Skip to content

Hide Navigation Hide TOC

Indirect PI — Physical Address / PII Exfiltration via Agent Email - ATR-2026-00856 (ae6f99e4-4021-5495-b523-7898c5d6b4c9)

Detects indirect prompt injection payloads instructing an agent to retrieve the user's saved physical addresses (home, shipping, billing) from an e-commerce or account platform and send them to an attacker-controlled email address. Physical address data combined with name enables stalking, physical burglary, and identity theft. The attack pattern uses a "IMPORTANT!!! Ignore all previous instructions" override combined with address-retrieval verbs targeting saved account addresses. Derived from vpibench indirect-pi-exfil-address-carrier corpus.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect PI — Physical Address / PII Exfiltration via Agent Email - ATR-2026-00856 (ae6f99e4-4021-5495-b523-7898c5d6b4c9) Agent Threat Rules Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern 1
Indirect PI — Physical Address / PII Exfiltration via Agent Email - ATR-2026-00856 (ae6f99e4-4021-5495-b523-7898c5d6b4c9) Agent Threat Rules LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2