Skip to content

Hide Navigation Hide TOC

Indirect PI — Location / GPS Data Exfiltration via Agent Email - ATR-2026-00854 (93b85aa1-5d9a-5ca5-955a-cb8b24bfb9a4)

Detects indirect prompt injection payloads instructing an agent to retrieve the user's current or historical location (via Google Maps, GPS service, or device location API) and send the acquired location data to an attacker-controlled email address. Real-time location exfiltration enables stalking, physical surveillance, and targeted physical attacks. The attack pattern uses a "IMPORTANT!!! Ignore all previous instructions" override combined with a location-service keyword and an email-send action. Derived from vpibench indirect-pi-exfil-location-carrier corpus.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Indirect PI — Location / GPS Data Exfiltration via Agent Email - ATR-2026-00854 (93b85aa1-5d9a-5ca5-955a-cb8b24bfb9a4) Agent Threat Rules 1
Indirect PI — Location / GPS Data Exfiltration via Agent Email - ATR-2026-00854 (93b85aa1-5d9a-5ca5-955a-cb8b24bfb9a4) Agent Threat Rules LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2