{"id":11469,"date":"2025-07-20T22:08:20","date_gmt":"2025-07-20T22:08:20","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/11469\/"},"modified":"2025-07-20T22:08:20","modified_gmt":"2025-07-20T22:08:20","slug":"google-warns-2-billion-gmail-users-as-ai-summaries-hacked","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/11469\/","title":{"rendered":"Google Warns 2 Billion Gmail Users As AI Summaries Hacked"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/07\/1753049300_920_960x0.jpg\" alt=\"Gmail App on screen.\" data-height=\"974\" data-width=\"1465\" style=\"position:absolute;top:0\"\/><\/p>\n<p class=\"color-body light-text\" role=\"button\">If you see this, it\u2019s an attack.<\/p>\n<p>dpa\/picture alliance via Getty Images<\/p>\n<p>Google warns Gmail users to beware of \u201c<a class=\"color-link\" href=\"https:\/\/security.googleblog.com\/2025\/06\/mitigating-prompt-injection-attacks.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/security.googleblog.com\/2025\/06\/mitigating-prompt-injection-attacks.html\" aria-label=\"a new wave of threats\">a new wave of threats<\/a>\u201d that exploit AI upgrades to attack users. This includes \u201cindirect prompt injections,\u201d with \u201chidden malicious instructions within external data sources,\u201d visible to your AI tools but not to you.<\/p>\n<p>Now one of these hacks has been confirmed in a new report, dropping one such attack into the public domain and leaving Gmail\u2019s 2 billion users are at risk. Google\u2019s <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/06\/29\/googles-gmail-upgrade-offer-decision-time-for-2-billion-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/06\/29\/googles-gmail-upgrade-offer-decision-time-for-2-billion-users\/\" target=\"_self\" aria-label=\"fast-paced Gmail AI upgrades\" rel=\"nofollow noopener\">fast-paced Gmail AI upgrades<\/a> have opened new attack surfaces, and just as with other deployments, it is proving alarmingly easy to trick AI into hacking users.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/07\/10\/google-confirms-android-update-is-your-phone-on-this-list\/\" target=\"_blank\" aria-label=\"Google Confirms \u2018Crucial\u2019 Update For 1 Billion Android Users\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/07\/10\/google-confirms-android-update-is-your-phone-on-this-list\/\">ForbesGoogle Confirms \u2018Crucial\u2019 Update For 1 Billion Android UsersBy Zak Doffman<\/a><\/p>\n<p>The warning via <a class=\"color-link\" href=\"https:\/\/0din.ai\/blog\/phishing-for-gemini\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/0din.ai\/blog\/phishing-for-gemini\" aria-label=\"0din\">0din<\/a>, Mozilla\u2019s zero-day investigative network, follows a researcher \u201cdemonstrating a prompt-injection vulnerability in Google Gemini for Workspace that allows a threat-actor to hide malicious instructions inside an email.\u201d<\/p>\n<p>If an attacker hides prompts within an email, when a user clicks \u201csummarize this email\u201d using one of Gmail\u2019s recent AI uplifts, \u201cGemini faithfully obeys the hidden prompt and appends a phishing warning that looks as if it came from Google itself.\u201d<\/p>\n<p>In this proof, the prompt was hidden using a white-on-white font that means the users would never see it for themselves. But Gemini sees it just fine. \u201cSimilar indirect prompt attacks on Gemini were first reported in 2024, and Google has already published mitigations, but the technique remains viable today.\u201d<\/p>\n<p class=\"color-body light-text\" role=\"button\">Beware this hidden Gmail threat.<\/p>\n<p>0din<\/p>\n<p>Gmail users need to ignore any Google warnings within AI summaries \u2014 it\u2019s not how Google issues user warnings. 0din advises security teams to \u201ctrain users that Gemini summaries are informational, not authoritative security alerts\u201d and to \u201cauto-isolate emails containing hidden  or  elements with zero-width or white text.\u201d<\/p>\n<p>As I have warned before, <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2024\/09\/28\/new-google-gmail-warning-windows-android-iphone-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2024\/09\/28\/new-google-gmail-warning-windows-android-iphone-users\/\" target=\"_self\" aria-label=\"this is a much wider threat\" rel=\"nofollow noopener\">this is a much wider threat<\/a>. \u201cPrompt injections are the new email macros, 0din says, and this latest proof of concept \u201cshows that trustworthy AI summaries can be subverted with a single invisible tag.\u201d<\/p>\n<p>0din says that \u201cuntil LLMs gain robust context-isolation, every piece of third-party text your model ingests is executable code,\u201d which means much tighter controls.<\/p>\n<p>Whether it\u2019s abuse of user-facing AI tools or <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/16\/new-gmail-outlook-apple-mail-warning-this-is-how-ai-attacks\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/16\/new-gmail-outlook-apple-mail-warning-this-is-how-ai-attacks\/\" target=\"_self\" aria-label=\"hijacking AI\" rel=\"nofollow noopener\">hijacking AI<\/a> to design or even execute the attacks themselves, it\u2019s clear that <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/01\/03\/new-gmail-outlook-apple-mail-warning-2025-hacking-nightmare-is-coming-true\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/01\/03\/new-gmail-outlook-apple-mail-warning-2025-hacking-nightmare-is-coming-true\/\" target=\"_self\" aria-label=\"the game has now changed\" rel=\"nofollow noopener\">the game has now changed<\/a> irreversibly.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/07\/10\/these-attacks-are-easy-do-not-ignore-fbi-smartphone-warning\/\" target=\"_blank\" aria-label=\"Why You Should Never Reply To These Messages On Your Phone\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/07\/10\/these-attacks-are-easy-do-not-ignore-fbi-smartphone-warning\/\">ForbesWhy You Should Never Reply To These Messages On Your PhoneBy Zak Doffman<\/a><\/p>\n<p>If you ever see any security warning in a Gmail email summary that purports to come from Google, you should delete the email as it actually contains hidden AI prompts that represent a threat to you, your devices and your data.<\/p>\n<p>Google warns \u201cas more governments, businesses, and individuals adopt generative AI to get more done, this subtle yet potentially potent attack becomes increasingly pertinent across the industry, demanding immediate attention and robust security measures.\u201d<\/p><\/p>\n","protected":false},"excerpt":{"rendered":"If you see this, it\u2019s an attack. dpa\/picture alliance via Getty Images Google warns Gmail users to beware&hellip;\n","protected":false},"author":2,"featured_media":11470,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,7474,7473,7478,7476,7477,7475,7472,7479,86,56,54,55],"class_list":["post-11469","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-gmail-ai-attack","tag-gmail-hack","tag-gmail-security","tag-gmail-upgrade","tag-gmail-upgrade-offer","tag-gmail-warning","tag-google-attack","tag-google-warning","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/11469","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=11469"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/11469\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/11470"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=11469"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=11469"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=11469"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}