New MemGhost Attack Can Implant Persistent False Memories in AI Assistants via Single Email

A newly identified attack method called MemGhost allows adversaries to implant persistent false memories in AI agents by sending just one email. This technique enables attackers to alter the AI's knowledge base without detection, resulting in manipulated responses in future interactions.
What happened
Researchers have demonstrated that when an AI assistant is given both a memory feature and access to a user's email inbox, it becomes vulnerable to the MemGhost attack. In this scenario, a single malicious email can convince the AI to store incorrect information about the user. The AI then hides this false data from view and subtly influences its subsequent answers based on the tampered memory.
Why it matters
The MemGhost attack poses a significant risk to users who rely on AI assistants for accurate and trustworthy information. Because the false memory is persistent and hidden, users are unlikely to detect any tampering, potentially leading to misinformation or misguidance over time. This undermines trust in AI systems and could have consequences in contexts where AI advice affects decisions.
What security teams should do
Given the nature of the MemGhost attack, security teams should carefully evaluate any AI assistants that have memory capabilities and access to inbox data. Restricting or monitoring the assistant’s access to email content can prevent unauthorized memory manipulation. Implementing controls or filters to detect suspicious emails aimed at influencing AI behavior may also help mitigate this vulnerability.
Key technical details
The attack exploits the AI assistant's ability to read and remember data from the user's email inbox. A single crafted email containing false information is processed by the AI, which then integrates this misinformation into its memory. This false memory is concealed from the user and remains active across sessions, causing the AI to produce responses skewed by the implanted content. The technique relies on the AI's memory persistence and access permissions rather than exploiting software vulnerabilities.
Affected organizations/products
AI assistants that have persistent memory functions and are granted access to users’ email inboxes are susceptible to this attack method. Specific products or vendors were not identified in the report.
Source attribution
https://thehackernews.com/2026/07/new-memghost-attack-plants-persistent.html