Prompt injection

OpenAI documents prompt injections that spread on their own between agents


The report describes malicious instructions that copy themselves from one email to another with no human intervention. They were detected in June and published in September.

September 27, 2026 · Translated from the Spanish original

What happened

Why it matters

The number

3 scenarios described (email, file system and multi-hop Slack), with no associated prevalence figure.

Context

The combination of access to private data, untrusted content and the ability to communicate externally had already been described as the weak point of assistants connected to work. This report adds the missing mechanism for the problem to scale without an attacker present at every step.

What’s next

Bottom line

The pattern repeats: a behavior is detected in June, published in September and reaches the real world as generic hygiene advice. The distance between the two dates is, for now, the margin anyone who already has an agent reading email is working with.

Sources

Edited by Rodrigo Cornejo. How we select and verify: who writes these notes.

Related notes

← All notes