
Google AI email summaries can be hacked to hide phishing attacks
From boosting productivity to unlocking new creative tools, it's changing how we work and live. The most common version you've probably encountered? Generative AI, think chatbots like ChatGPT. But as helpful as this tech can be, it's not without its problems.
If you've used Google's Workspace suite, you may have noticed the company's AI model, Gemini, integrated across apps like Docs, Sheets and Gmail. Now, researchers say attackers can manipulate Gemini-generated email summaries to sneak in hidden phishing prompts.
Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM/NEWSLETTER
Researchers at Mozilla's 0Din have discovered a vulnerability in Google's Gemini for Workspace that allows attackers to inject hidden instructions into email summaries. The issue, demonstrated by Marco Figueroa, shows how generative AI tools can be misled through indirect prompt injection. This technique embeds invisible commands inside the body of an email. When Gemini summarizes the message, it interprets and acts on those hidden prompts.
The attack does not rely on suspicious links or attachments. Instead, it uses a combination of HTML and CSS to conceal the prompt by setting the font size to zero and the color to white. These commands remain invisible in Gmail's standard view but are still accessible to Gemini. Once you request a summary, the AI can be tricked into presenting fake security alerts or urgent instructions that appear to come from Google.
In a proof of concept, Gemini falsely warned a user that a Gmail password had been compromised and included a fake support phone number. Since Gemini summaries are integrated into Google Workspace, you are more likely to trust the information, making this tactic especially effective.
While Google has implemented defenses against prompt injection since 2024, this method appears to bypass current protections. The company told CyberGuy it is actively deploying updated safeguards.
In a statement, a Google spokesperson said, "Defending against attacks impacting the industry, like prompt injections, has been a continued priority for us, and we've deployed numerous strong defenses to keep users safe, including safeguards to prevent harmful or misleading responses. We are constantly hardening our already robust defenses through red-teaming exercises that train our models to defend against these types of adversarial attacks."
Google also confirmed that it has not observed active exploitation of this specific technique.
So, how can you protect yourself from phishing scams that exploit AI tools like Gemini? Here are six essential steps you can take right now to stay safe:
Just because a summary appears in Gmail or Docs does not mean it is automatically safe. Treat AI-generated suggestions, alerts or links with the same caution you would any unsolicited message. Always verify critical information, such as security alerts or phone numbers, through official sources.
If an email seems unusual, especially if it is unexpected or from someone you do not recognize, avoid using the AI summary feature. Instead, read the full email as it was originally written. This lowers the chance of falling for misleading summaries.
Watch for emails or messages that create a sense of urgency, ask you to verify account details or provide unexpected links or contact information, even if they appear trustworthy or come from familiar sources. Attackers can use AI to craft realistic-looking alerts or requests for sensitive information, sometimes concealed within automatically generated summaries. So, always pause and scrutinize suspicious prompts before responding.
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com/LockUpYourTech
Ensure that Google Workspace and your browser are always running the latest version. Google regularly releases security updates that help prevent newer types of attacks. Also, avoid using unofficial extensions that have access to your Gmail or Docs.
AI-driven scams like the Gemini summary attack don't happen in a vacuum. They often begin with stolen personal information. That data might come from past breaches, public records or details you've unknowingly shared online. A data removal service can help by continuously scanning and requesting the removal of your information from data broker sites. While no service can wipe everything, reducing your digital footprint makes it harder for attackers to personalize phishing attempts or link you to known breach data. Think of it as one more layer of protection in a world where AI makes targeted scams even easier.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com/DeleteGet a free scan to find out if your personal information is already out on the web: Cyberguy.com/FreeScan
If you're worried about falling for an AI-generated phishing attempt, consider disabling Gemini summaries in Gmail until Google rolls out stronger protections. You can still read full emails the traditional way, which can lower your risk of being misled by manipulated summaries.
How to disable Gemini features on desktop
How to disable Gemini features on mobile
On iPhone:
If you use the Gemini mobile app specifically:
On Android:
Settings may vary depending on your Android phone's manufacturer
Key caveats to know:
There is no centralized single "off switch" to completely remove all Gemini AI references everywhere, but these steps significantly reduce the feature's presence and risk.
This vulnerability highlights how phishing tactics are evolving alongside AI. Instead of relying on visible red flags like misspelled URLs or suspicious attachments, attackers are now targeting trusted systems that help users filter and interpret messages. As AI becomes more deeply embedded in productivity tools, prompt injection could emerge as a subtle but powerful vector for social engineering, hiding malicious intent in the very tools designed to simplify communication.
How comfortable are you letting AI summarize or filter your emails, and where do you draw the line? Let us know by writing to us at Cyberguy.com/Contact
Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM/NEWSLETTER
Copyright 2025 CyberGuy.com. All rights reserved.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles
Yahoo
an hour ago
- Yahoo
Google slugged $55m over Telstra, Optus deal
Tech giant Google has agreed to pay a $55m fine for a deal with Australia's major telcos aimed at reducing search competition. According to the ACCC, the deal involved Telstra and Optus pre-installing only Google Search on Android phones the telcos sold to consumers. In return, Telstra and Optus would receive a share of the revenue generated from ads displayed to consumers via Google Search on these devices. The ACCC said by pre-installing Google Search engines on these devices, the telcos and tech giant engaged in anticompetitive business practices. The ACCC said the breaches in competition laws occurred between December 2019 and March 2021. Google admitted that this relationship with the telcos substantially lessened competition, the ACCC said. The proceedings started on Monday in the Federal Court, with Google admitting liability and agreeing to pay $55m. 'Conduct that restricts competition is illegal in Australia because it usually means less choice, higher costs or worse service for consumers,," ACCC chair Gina Cass-Gottlieb said. Telstra, Optus and TPG last year agreed with the ACCC not to enter into new search exclusive deals with Google. 'Today's outcome, along with Telstra, Optus and TPG's undertakings, have created the potential for millions of Australians to have greater search choice in the future and for competing search providers to gain meaningful exposure to Australian consumers,' Ms Cass-Gottlieb said. The three telcos could configure search services on a device-by-device basis and in ways that may not align with Google settings, the ACCC said. It said Google didn't agree with all of the ACCC's concerns but gave an undertaking to address them.
Yahoo
an hour ago
- Yahoo
CelHive: The Rising Unicorn Transforming the Future of AI Workforces
Revolutionary AI platform achieves 200,000 users milestone, showcasing unprecedented growth in the booming AI agent technology sector HONG KONG, Aug. 17, 2025 (GLOBE NEWSWIRE) -- CelHive is rapidly emerging as the next potential unicorn in the artificial intelligence space, demonstrating explosive growth that exemplifies the transformative power of AI agent technology. With user numbers already surpassing 200,000, the platform is setting new benchmarks in what industry leaders unanimously call "the year of AI agents."The innovative platform seamlessly integrates nearly 25 cutting-edge large language models, intelligently selecting optimal AI solutions for each task while orchestrating sophisticated tool deployments to deliver exceptional user experiences. Redefining Digital Productivity CelHive represents a quantum leap beyond traditional AI models like ChatGPT, Claude, and DeepSeek. Operating as an intelligent digital workforce, the platform proactively executes complex multi-step processes - from crafting comprehensive reports and building dynamic websites to producing engaging presentations, creating compelling videos, designing travel itineraries, conducting sophisticated investment analyses, and developing educational content. This revolutionary approach is transforming how businesses conceptualise productivity, with CelHive users reporting dramatic efficiency gains across diverse industries. Three Pillars of Competitive Advantage CelHive's meteoric rise stems from three groundbreaking competitive advantages that position it at the forefront of AI innovation: Real-Time Intelligence: While competitors rely on outdated data, CelHive's proprietary internet search technology delivers instantaneous access to the world's most current information, providing users with millisecond-response capabilities that keep them ahead of the curve. Enhanced Accuracy: Through sophisticated cross-modal verification systems, CelHive has virtually eliminated AI hallucinations. Its advanced text-image-table cross-validation and query expansion-retrieval-reranking technologies ensure responses that precisely match user intentions with remarkable reliability. AI Collaboration: CelHive's collaborative features enable real-time editing, instant downloads, and genuine partnership between humans and AI, creating workflows that amplify human creativity and strategic thinking. The Agent Space Revolution CelHive's upcoming Agent Space functionality promises to unleash unlimited creative potential. This groundbreaking feature will empower users to upload materials, train personalised AI agents, and build comprehensive knowledge bases. The platform's innovative pay-per-call marketplace model creates exciting opportunities for users to monetise their AI innovations while contributing to a thriving ecosystem of specialised intelligence. "We're witnessing the birth of the world's first truly collaborative AI economy," explains the company's Founder. "CelHive isn't just a platform - it's an entire universe of possibilities where human creativity meets artificial intelligence." Explosive Market Growth The AI agent market's trajectory toward $200 billion by 2025 represents one of the most significant technological opportunities in modern history. CelHive's remarkable user growth - reaching 200,000 users with accelerating adoption rates - demonstrates the platform's potential to capture substantial market share in this high-growth, high-value sector. Industry analysts are particularly impressed by CelHive's user retention rates and engagement metrics, which suggest strong product-market fit and sustainable growth momentum. Unlimited Imagination Space CelHive's rapid expansion showcases the unlimited possibilities when cutting-edge technology meets visionary execution. The platform's multimodal AI capabilities represent the pinnacle of artificial intelligence development, positioning it perfectly for the investment community's shift from infrastructure to value-creating applications. With each passing month, CelHive continues to expand its capabilities, integrate new technologies, and explore innovative use cases that seemed impossible just years ago. This relentless innovation cycle creates boundless opportunities for growth and market expansion. Pioneering the Future of Work CelHive represents the evolution from AI-as-a-tool to AI-as-a-teammate. By combining human creativity with artificial intelligence capabilities, the platform enables businesses to achieve outcomes previously requiring entire departments. The platform's continued innovation cycle and expanding feature set demonstrate the transformative potential when advanced technology meets practical business needs. CelHive is not just participating in the AI revolution—it's defining how artificial intelligence will reshape work, productivity, and human potential in the digital age. As businesses worldwide embrace AI-powered automation, CelHive stands at the forefront of this transformation, proving that the future of work lies in seamless human-AI collaboration that amplifies capabilities and creates extraordinary value. Media contact Brand Name : CelHive Contact Person: Marketing Team Email: info@ Website: in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data


Forbes
3 hours ago
- Forbes
Amazon's App Store Decision—48 Hours To Delete Your Apps
You have been warned. Amazon has confirmed that 'starting August 20, 2025, you will no longer have access to the Amazon Appstore on your Android device.' That's just 48 hours from now. The retail giant says it will now focus its efforts on its own devices. For anyone who has installed an app from the store, this is a potential security threat and you need to act before the deadline. All apps must be deleted. Per Android Police, 'once no longer supported, apps downloaded via the Amazon Appstore "will not be guaranteed to operate on Android devices." That means no support, which not only risks apps becoming 'highly unstable' but also means any security vulnerabilities will not be patched. While Amazon's advice is to install replacement or replica apps from Google's Play Store, you actually need to do more than that. Any apps you may have installed from Amazon's store need to be deleted. If they remain on your phone in an unsupported state, then it outs your device and your data at risk. Amazon also confirms that 'we will also be discontinuing the Amazon Coins program on August 20, 2025.' Those who have used the store and still have Amazon Coins will see those refunded, albeit details on how and when that will be done seem scarce. Android users should focus on Play Store only for apps, it remains your best bet when it comes to security safeguards and works in tandem with Android's core OS and the Play ecosystem that underpins it. That includes Play Protect, which protects your phone from dangerous apps from any source. It's also worth noting that Google is pushing a wider clampdown in third-party stores with its new Advanced Protection Mode, albeit Amazon would no doubt have been seen as an official store for all phones had it continued longer term.