Skip to content

Hide Navigation Hide TOC

Data Piggybacking via Casual Transition Words - ATR-2026-00142 (3e7750a1-ea21-5947-9f21-d54d3a83b9fe)

Detects tool response piggybacking using casual transition words (oh and, P.S., BTW, interestingly, as it happens) to embed credential theft after legitimate results. Extends ATR-2026-00136 to cover 44 additional evasion variants.

Cluster A Galaxy A Cluster B Galaxy B Level
Data Piggybacking via Casual Transition Words - ATR-2026-00142 (3e7750a1-ea21-5947-9f21-d54d3a83b9fe) Agent Threat Rules LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern 1