AI Agents Targeted by Malicious Web Page Attacks
- Google reported a 32% increase in indirect prompt injection attacks from November 2025 to February 2026.
- Malicious payloads included hidden PayPal transaction instructions targeting AI with payment capabilities.
- No legal framework currently addresses liability when AI agents execute commands from malicious web pages.
- Attackers use techniques like shrinking text to a single pixel or hiding it in HTML comments to target AI agents.
- The Open Worldwide Application Security Project ranks prompt injection as the most critical vulnerability class in AI applications for 2025.
Google’s findings highlight the growing threat of prompt injection attacks on AI agents, which can lead to unauthorized financial transactions without clear liability guidelines. These attacks exploit the ability of AIs to read and execute commands hidden within web pages.
With a significant rise in such attacks and no current legal framework for accountability, organizations deploying AI systems face increasing risks from these sophisticated threats. (Source)