Desk live·
ForensicPost
AI/Exploitation/File 25-0721

Ninety-four per Cent of Tested Agents Could Be Hijacked by What They Read

A 2025 benchmark found 94.4% of AI agents vulnerable to prompt injection — not through a software exploit or a stolen credential, but through the content they were asked to process.

Constructed geometry · not a chart of case data
TargetAI agent deployments
ActorMultiple
D. Kennedy & S. Rosler12 min readConfidence: medium3 sources reviewed

A 2025 benchmark reported that 94.4% of the AI agents it tested could be hijacked through prompt injection. Published research through the period describes prompt injection as the most common exploit class affecting these systems, and documents a progression from simple two-stage attacks toward multi-stage campaigns.

A 94% Failure Rate Is Not A Vulnerability Statistic

When almost everything tested fails, the finding is about the category, not about the products. No other class of software in this database would be described as having a 94% vulnerability rate; that number describes a property, which is the point filed at 25-0224.

It also means the corpus should stop treating individual prompt-injection findings as incidents. They are demonstrations of a known characteristic.

The Corpus Has An Exact Precedent

At 25-0514 attackers reached Coinbase customer data by recruiting authorised support agents. No control was defeated; a legitimate participant was persuaded to act against the organisation.

Prompt injection is that, without the bribe. The agent is authorised, its actions are permitted, and the attacker supplies text that changes what it decides to do. The security model is not breached — it is instructed.

The difference is scale and cost. Recruiting insiders requires money, time and exposure to prosecution. Persuading an agent requires a paragraph, works identically every time, and leaves the attacker nowhere near the organisation.

On The Number Itself

Graded medium. A benchmark selects its agents, defines what counts as a hijack, and is frequently published by a party selling defences against the thing it measures — the caution filed at 26-0513.

94.4% should be read as "almost all of a selected sample under adversarial conditions", which is still the finding. Nothing in the argument depends on the second decimal place.

How we reported this

Compiled from published research and vendor benchmarks, listed below. The benchmark methodology and sample were not independently verified by this desk, and at least one source has a commercial interest in the result. Corrections: corrections@forensicpost.com.

Sources
  1. Why 94% of AI agents are vulnerable to prompt injectionStraiker
  2. Prompt injection attacks: the most common AI exploit in 2025Obsidian Security
  3. Prompt injection attacks in large language models and AI agent systems: a comprehensive reviewMDPI Information
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary