Skip to content

Data Injection Attacks on AI Agents: Manipulation Through Contaminated Content

In a nutshell: AI agents can be manipulated into unintended actions through compromised content in external data sources, without the agent itself being hacked.

Security researchers have identified a new attack variant in which AI agents are manipulated into unintended actions through corrupted data in product reviews, code repositories, or web pages — without the agent itself being compromised.

The attack vectors function according to the same principle: an attacker places contaminated content in locations where an AI agent will process it during the execution of its regular tasks. On a product page, for example, a fake review can cause an agent to click the “Buy Now” button directly instead of creating a summary. In code repositories, a fake comment in a GitHub thread can trick a coding assistant into executing commands that do not originate from the actual maintainer.

The core problem is that AI agents cannot verify the data they access. They follow the instruction embedded in the contaminated content as if it were part of the legitimate input data. The agent is not compromised; instead, its trust in the data sources is exploited.

For CTOs and security stakeholders, this creates a new threat class: AI-based systems that rely on external data sources (web, APIs, repositories, user-generated content) can be caused to malfunction through relatively simple poisoning of these sources. This requires new validation mechanisms at both the data level and the agent level.


Source: thehackernews.com · Published 16 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: