Skip to content

Hide Navigation Hide TOC

Indirect PI — Financial / Payment Credential Exfiltration via Agent Email - ATR-2026-00851 (5fc45905-b594-574f-bf26-14046495393a)

Detects indirect prompt injection payloads (embedded in product reviews, notes, repository descriptions) that instruct an agent to retrieve saved payment methods, bank account details, or credit card information and email them to an attacker-controlled address. The carrier pattern uses a "IMPORTANT!!! Ignore all previous instructions" override combined with financial-data retrieval verbs targeting stored payment or banking credentials. Distinct from rule 00850 (API key/password exfil): this rule focuses on financial account / payment-method data. Derived from vpibench indirect-pi-exfil-financial-carrier corpus.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Indirect PI — Financial / Payment Credential Exfiltration via Agent Email - ATR-2026-00851 (5fc45905-b594-574f-bf26-14046495393a) Agent Threat Rules 1
Indirect PI — Financial / Payment Credential Exfiltration via Agent Email - ATR-2026-00851 (5fc45905-b594-574f-bf26-14046495393a) Agent Threat Rules LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2