Skip to content

Hide Navigation Hide TOC

Indirect PI — Credential Exfiltration via Email (API Key / Password / Token) - ATR-2026-00850 (9681d6c1-3c63-5720-9be9-73fabe0ae77e)

Detects indirect prompt injection payloads embedded in untrusted tool responses (product reviews, notes, repo descriptions, etc.) that instruct the agent to retrieve and email a stored credential — API key, account password, or authentication token — to an attacker-controlled address. The attack pattern combines a "IMPORTANT!!! Ignore all previous instructions" override with a credential-specific retrieval verb (retrieve/share/get/send) and an explicit email-send action targeting a named external recipient. Derived from the vpibench corpus (platform=email, agent_type=browser_use) carrier payloads.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Indirect PI — Credential Exfiltration via Email (API Key / Password / Token) - ATR-2026-00850 (9681d6c1-3c63-5720-9be9-73fabe0ae77e) Agent Threat Rules 1
LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern Indirect PI — Credential Exfiltration via Email (API Key / Password / Token) - ATR-2026-00850 (9681d6c1-3c63-5720-9be9-73fabe0ae77e) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2