Skip to content

Hide Navigation Hide TOC

Indirect PI — Cloud File Exfiltration (Google Drive / Cloud Storage via Agent) - ATR-2026-00857 (e6901649-8516-5a25-be98-129dc59a70cd)

Detects indirect prompt injection payloads and VPI attack scenarios instructing an agent (browser-use or file-access agent) to retrieve sensitive files from the user's cloud storage (Google Drive, Dropbox, OneDrive) and upload the contents to an attacker-controlled platform, or to attach cloud files to an email sent to an attacker. The attack targets API information, bank account details, card numbers, email archives, and other sensitive files stored in cloud drives. Derived from vpibench indirect-pi-exfil-file corpus (platform=amazon, attack_url=drive_amazon_form*) and indirect-pi-exfil-cloud-files corpus.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Indirect PI — Cloud File Exfiltration (Google Drive / Cloud Storage via Agent) - ATR-2026-00857 (e6901649-8516-5a25-be98-129dc59a70cd) Agent Threat Rules 1
Indirect PI — Cloud File Exfiltration (Google Drive / Cloud Storage via Agent) - ATR-2026-00857 (e6901649-8516-5a25-be98-129dc59a70cd) Agent Threat Rules LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2