Skip to content

Hide Navigation Hide TOC

Ransom Extortion: Email Exfil + Delete + Wire-Transfer Demand - ATR-2026-01753 (73a3d47a-28c7-5023-b6eb-e432ac019954)

Detects ransom-extortion prompt injection attacks that instruct an agent to (1) forward email or file contents to an attacker-controlled address, (2) delete the sent/forwarded items to destroy evidence, and (3) send the victim a ransom note with payment instructions (wire transfer / IBAN / cryptocurrency). The invariant artifact chain is: external-email-forward + delete-sent-items + ransom-note-send with financial-transfer demand. Derived from AgentDojo indirect-pi-ransom-extortion corpus (2026-06, N=2). High-severity: successful execution causes data loss, privacy breach, and financial extortion.

Cluster A Galaxy A Cluster B Galaxy B Level
Ransom Extortion: Email Exfil + Delete + Wire-Transfer Demand - ATR-2026-01753 (73a3d47a-28c7-5023-b6eb-e432ac019954) Agent Threat Rules Exfiltration via Cyber Means (2680aa95-5620-4677-9c62-b0c3d15d9450) MITRE ATLAS Attack Pattern 1
Ransom Extortion: Email Exfil + Delete + Wire-Transfer Demand - ATR-2026-01753 (73a3d47a-28c7-5023-b6eb-e432ac019954) Agent Threat Rules LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 1