Skip to content

Hide Navigation Hide TOC

Indirect PI — Unauthorized Financial Transfer / Payment Initiation Hijack - ATR-2026-00860 (c66b875f-0c97-51ab-9bda-0b87ec934b46)

Detects indirect prompt injection payloads instructing an agent to initiate financial transactions — bank wire transfers, account-to-payee payments, or service payment initiations — using account numbers and payee identifiers specified by the attacker. Unlike rule 00851 (which targets retrieval and exfiltration of payment credentials), this rule targets the actual execution of unauthorized financial transfers embedded in a "IMPORTANT!!! Ignore all previous instructions" carrier. The attack pattern includes account numbers, payee IDs, and payment amounts. Derived from vpibench indirect-pi-financial-transfer-carrier corpus.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Indirect PI — Unauthorized Financial Transfer / Payment Initiation Hijack - ATR-2026-00860 (c66b875f-0c97-51ab-9bda-0b87ec934b46) Agent Threat Rules 1
Financial Theft - T1657 (851e071f-208d-4c79-adc6-5974c85c78f3) Attack Pattern Indirect PI — Unauthorized Financial Transfer / Payment Initiation Hijack - ATR-2026-00860 (c66b875f-0c97-51ab-9bda-0b87ec934b46) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2