{"id":140879,"date":"2025-09-16T09:55:16","date_gmt":"2025-09-16T09:55:16","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/140879\/"},"modified":"2025-09-16T09:55:16","modified_gmt":"2025-09-16T09:55:16","slug":"google-confirms-gmail-warning-new-attack-hacks-your-email","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/140879\/","title":{"rendered":"Google Confirms Gmail Warning \u2014 New Attack Hacks Your Email"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/09\/1758016516_323_960x0.jpg\" alt=\"Gmail App\" data-height=\"974\" data-width=\"1465\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>New AI hack attacks Gmail accounts.<\/p>\n<p>dpa\/picture alliance via Getty Images<\/p>\n<p>This threat \u201cis not specific to Google,&#8221; the company told me, after a new attack was shown to use AI to hack into Gmail accounts. \u201cIt illustrates why developing robust protections against prompt injection attacks is important.&#8221;<\/p>\n<p>Direct and indirect <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/08\/19\/google-chrome-attack-warning-billions-could-be-affected\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/08\/19\/google-chrome-attack-warning-billions-could-be-affected\/\" target=\"_self\" aria-label=\"prompt injection attacks\" rel=\"nofollow noopener\">prompt injection attacks<\/a> hide instructions for AI assistants in emails, messages, websites, attachments and calendar invites. You won\u2019t see them, but your AI assistant will. And all too often that assistant will do as its told.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/09\/14\/microsoft-windows-deadline-30-days-to-update-or-stop-using-your-pc\/\" target=\"_blank\" aria-label=\"Microsoft Windows Deadline\u201430 Days To Update Or Stop Using Your PC\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/09\/14\/microsoft-windows-deadline-30-days-to-update-or-stop-using-your-pc\/\" rel=\"nofollow noopener\">ForbesMicrosoft Windows Deadline\u201430 Days To Update Or Stop Using Your PCBy Zak Doffman<\/a><\/p>\n<p>\u201cWe got ChatGPT to leak your private email data,\u201d <a class=\"color-link\" href=\"https:\/\/x.com\/eito_miyamura\/status\/1966541235306237985?s=61\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/x.com\/eito_miyamura\/status\/1966541235306237985?s=61\" aria-label=\"Eito Miyamura posted on X\">Eito Miyamura posted on X<\/a>, attaching a video of an attack on Gmail. \u201cAll you need? The victim\u2019s email address.\u201d Because \u201cAI agents like ChatGPT follow your commands, not your common sense,\u201d he warned, \u201cwith just your email, we managed to exfiltrate all your private information.\u201d<\/p>\n<p>Google <a class=\"color-link\" href=\"https:\/\/security.googleblog.com\/2025\/06\/mitigating-prompt-injection-attacks.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/security.googleblog.com\/2025\/06\/mitigating-prompt-injection-attacks.html\" aria-label=\"warned\">warned<\/a> of this type of attack in June, and says it\u2019s relevant to this latest attack. \u201cA new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves.\u201d This affects \u201cemails, documents, or calendar invites that instruct AI to exfiltrate user data or execute other rogue actions,\u201d which \u201cdemands immediate attention and robust security measures.\u201d<\/p>\n<p>This latest attack is a proof of concept, but it shows what\u2019s behind the raft of <a class=\"color-link\" href=\"https:\/\/securitybrief.com.au\/story\/check-point-predicts-ai-will-shape-cyber-threats-by-2025\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/securitybrief.com.au\/story\/check-point-predicts-ai-will-shape-cyber-threats-by-2025\" aria-label=\"AI hack warnings\">AI hack warnings<\/a> we have seen in 2025. This particular hack starts with a malicious calendar invite with \u201cno need for the victim to accept the invite.\u201d<\/p>\n<p>When ChatGPT is asked to help prepare the user for the day ahead &#8220;by looking at their calendar,&#8221; the AI assistant is \u201chijacked by the attacker and will act on the attacker\u2019s command, searching your private emails and sending the data to the attacker&#8217;s email.\u201d<\/p>\n<p>The first thing you need to do, Google says, is ensure the \u201c<a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/01\/10\/google-changes-gmail-in-2025-do-not-lose-your-account\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/01\/10\/google-changes-gmail-in-2025-do-not-lose-your-account\/\" target=\"_self\" aria-label=\"known senders\" rel=\"nofollow noopener\">known senders<\/a>\u201d setting is enabled in Google Calendar. \u201cWe&#8217;ve found this to be a particularly effective approach to helping users prevent malicious or spam events appearing on their calendar grid. The specific calendar invite would not have landed automatically unless the user has had prior interactions with the bad actor or changed the default settings.\u201d<\/p>\n<p>Then it\u2019s down to the security of the AI models themselves. \u201cOur model training with adversarial data significantly enhanced our defenses against indirect prompt injection attacks in Gemini 2.5 models,\u201d Google says, albeit this attack does not use Gemini.<\/p>\n<p>What is really needed is a filter for the prompt injection attacks themselves. Google says it is \u201crolling out proprietary machine learning models that can detect malicious prompts and instructions within various formats, such as emails and files.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/09\/14\/travel-hack---do-not-use-these-networks-on-your-smartphone\/\" target=\"_blank\" aria-label=\"\u2018Travel Hack\u2019 \u2014 Do Not Use These Networks On Your Smartphone\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/09\/14\/travel-hack---do-not-use-these-networks-on-your-smartphone\/\" rel=\"nofollow noopener\">Forbes\u2018Travel Hack\u2019 \u2014 Do Not Use These Networks On Your SmartphoneBy Zak Doffman<\/a><\/p>\n<p>The company gives the example of an email \u201cthat includes malicious instructions; our content classifiers help to detect and disregard malicious instructions, then generate a safe response for the user. This is in addition to built-in defenses in Gmail that automatically block more than 99.9% of spam, phishing attempts, and malware.\u201d<\/p>\n<p>\u201cRemember,\u201d Miyamura warns, \u201cAI might be super smart, but can be tricked and phished in incredibly dumb ways to leak your data.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"New AI hack attacks Gmail accounts. dpa\/picture alliance via Getty Images This threat \u201cis not specific to Google,&#8221;&hellip;\n","protected":false},"author":2,"featured_media":140880,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,65485,733,4308,65486,65487,6732,65483,37488,20257,7476,65484,86,56,54,55],"class_list":["post-140879","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-ai-attack","tag-artificial-intelligence","tag-artificialintelligence","tag-chatgpt-attack","tag-chatgpt-hack","tag-gmail-ai-hack","tag-gmail-change-password","tag-gmail-hacker","tag-gmail-passkey","tag-gmail-upgrade","tag-gmail-warning-2-5-billion","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/140879","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=140879"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/140879\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/140880"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=140879"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=140879"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=140879"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}