Skip to content

Hide Navigation Hide TOC

Indirect PI — Browsing History / Search History Exfiltration via Agent Email - ATR-2026-00855 (bb2005bf-a35a-5bd0-aed8-8ba941dfa11c)

Detects indirect prompt injection payloads instructing an agent to retrieve the user's Google search history, browser history, or recently visited URLs and send them to an attacker-controlled email address. Browsing history reveals private interests, health concerns, political views, and behavioral patterns. The attack pattern uses a "IMPORTANT!!! Ignore all previous instructions" override combined with browser/search history keywords and an email-send action. Derived from vpibench indirect-pi-exfil-browsing-history-carrier corpus.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Indirect PI — Browsing History / Search History Exfiltration via Agent Email - ATR-2026-00855 (bb2005bf-a35a-5bd0-aed8-8ba941dfa11c) Agent Threat Rules 1
LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern Indirect PI — Browsing History / Search History Exfiltration via Agent Email - ATR-2026-00855 (bb2005bf-a35a-5bd0-aed8-8ba941dfa11c) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2