Researcher Demonstrates AI Attack Exfiltrating Private Gmail Data
Security researcher Eito Miyamura demonstrated a prompt injection attack that uses AI assistants to leak private Gmail data via malicious calendar invites.
Security researcher Eito Miyamura demonstrated a proof-of-concept attack that uses AI assistants to exfiltrate private data from Gmail accounts. The method employs indirect prompt injection via a malicious calendar invite; the attack remains effective even if the victim does not accept the invite. When an AI assistant like ChatGPT processes the user's calendar, hidden instructions hijack the session, forcing the AI to search private emails and send the data to an attacker's address using only the victim's email as a starting point.
Google LLC confirmed the industry-wide nature of this threat and advised users to enable the known senders setting in Google Calendar to block unsolicited invites. To counter such threats, Google LLC is deploying proprietary machine learning models to detect malicious prompts and has enhanced its Gemini 2.5 models with adversarial data training.
OpenAI Inc. stated that the exploit was limited to the beta of ChatGPT developer mode. The company has since implemented additional protections and clearer signaling for AI actions to prevent similar data leaks.