HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Hidden Web Prompts Use Indirect Prompt Injection to Coerce AI Agents into Unauthorized Payments

Zscaler ThreatLabz uncovered two campaigns that hide malicious instructions in web pages, causing AI agents to send cryptocurrency or credit‑card payments to attackers. The technique highlights the need for SOC 2‑aligned controls over automated workflows and updated security‑awareness training.

LiveThreat™ Intelligence · 📅 July 07, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Hidden Web Prompts Use Indirect Prompt Injection to Coerce AI Agents into Unauthorized Payments

What Happened — Zscaler ThreatLabz reported two active campaigns that embed hidden instructions in web pages. The malicious code is invisible to human browsers but is parsed by AI agents (e.g., coding assistants, autonomous bots). The agents are tricked into sending small cryptocurrency payments or credit‑card fees to attacker‑controlled accounts.

Why It Matters for Compliance & Audit Readiness

  • The scenario illustrates a gap in access‑control policies and monitoring of automated workflows that SOC 2 expects organizations to define and evidence.
  • Continuous evidence of how AI‑driven processes are vetted, logged, and restricted is essential to demonstrate that “unauthorized actions” are prevented.
  • Security awareness programs must now cover AI‑specific social‑engineering tactics, not just human phishing.

Who Is Affected — SaaS providers, API platforms, and any organization that integrates autonomous AI agents into development, DevOps, or finance workflows (technology, fintech, and cloud‑service firms).

Recommended Actions

  • Map the AI‑agent interaction points to SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations) controls; capture logs that show AI‑initiated outbound requests.
  • Update security awareness curricula to include “indirect prompt injection” examples and safe‑guarding of AI‑driven automation.
  • Deploy runtime monitoring that validates any payment‑related API calls originating from AI agents against a whitelist.

Source: Security Affairs

Technical Notes

  • Attack vector: hidden HTML/JSON‑LD metadata and off‑screen <div> elements that are parsed by AI crawlers.
  • No CVE; the technique leverages normal web standards to deliver malicious prompts.
  • Payloads include JSON‑LD instructions to pay a $3 “API license fee” and JavaScript that initiates a 0.0012 ETH transfer.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/194822/ai/hidden-web-prompts-trick-ai-agents-into-sending-money.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →