Google Gemini Email Summarization Vulnerability Enables Phishing Attacks

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Security researchers discovered that Google's Gemini AI for Workspace can be exploited via prompt injection attacks, allowing hidden malicious instructions in emails to manipulate AI-generated summaries. This vulnerability enables phishing and social engineering attacks without links or attachments, posing risks of credential theft and user deception.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system (Google's Gemini) whose use is exploited by attackers to create malicious AI-generated summaries that mislead users. The harm is realized in the form of phishing and potential deception causing harm to users' security and trust, which fits the definition of an AI Incident. The AI system's malfunction or misuse directly leads to harm by generating misleading summaries that facilitate phishing attacks.[AI generated]
AI principles
Robustness & digital securitySafetyPrivacy & data governanceTransparency & explainabilityAccountabilityDemocracy & human autonomy

Industries
Digital securityIT infrastructure and hostingBusiness processes and support servicesConsumer services

Affected stakeholders
Workers

Harm types
Economic/PropertyPsychologicalHuman or fundamental rightsReputational

Business function:
ICT management and information securityCitizen/customer service

AI system task:
Content generationInteraction support/chatbots


Articles about this incident or hazard