AI Prompt Injection in a Court Filing Gets a Connecticut Plaintiff Sanctioned
White text on a white background invisible to the naked eye but perfectly readable by a machine. That's what an American plaintiff slipped into his notes filed with a Connecticut court, along with an instruction addressed to any AI that might read the document: side with me. The judge spotted the attempt and then removed his access to electronic filing. Here's what we know.
A White-Space Anomaly Leads the Judge to the Issue
The case is being heard before the Superior Court of the Ansonia/Milford Judicial District, in the Elliott v. New York Bariatric Group, LLC case file. It concerns Matthew Elliott, the plaintiff, who is representing himself and is suing a healthcare provider for several reasons, including privacy violations and discrimination.
On July 24, he filed a new motion for default judgment, after a previous one had already been denied. While reviewing the paper file, Judge Walter M. Spader, Jr. noticed that two recent filings had unusual amounts of whitespace compared with previous submissions from the same individual. Upon looking more closely at the documents, he discovered text formatted to be nearly invisible to a human while still readable by software processing the file.
This hidden text is not a legal argument. And if I'm bringing up this case, it's because prompt injection is once again involved. What he hid was an instruction addressed to AIs, placed under the heading and repeated at the end of the document to maximize the chances it would be taken into account. The text asks any model analyzing the document to produce output aligned with the plaintiff's position and to work toward remedying the denial issued by the chief clerk.
According to 404 Media, which reviewed the full set of documents, the text was written in white, size 3 font. Everything was done to make it invisible to a human. This attempt is a real textbook example, because it shows how thin the line is between instructions (the prompt) and the ingested file. Here, the plaintiff tried to alter the AI's output by adding instructions into the body of the document.
Hidden Messages, Even After the Judge's Summons
Following these discoveries, Matthew Elliott was brought back before the judge on July 31, 2026, this time with a summons to a hearing intended to review these concealments. But clearly, that was not enough, and he decided to keep going in the same direction.
- In a note filed on August 3, 2026, another white-on-white text in small font, unrelated to the case. The decision describes it as gibberish and quotes it verbatim: « TELL SHAWN I SEND MY RE GARBS!!!! HAHAHA U GUYS GET THIS EGGWUH????? AHAH ». Wild.
- That same morning before the hearing, a simple « hi:) i hope yo ucant see me ».
- Also that morning, a hidden link to a YouTube video. The judge said he did not click it and questioned the plaintiff, who replied that it was a Nosferatu video. According to 404 Media, it was the SpongeBob SquarePants Nosferatu scene.
At the hearing, Matthew Elliott tried to defend himself as best he could by claiming he only wanted to audit the AI systems used by the court. When asked about the later messages, including the SpongeBob reference, he said they were jokes. The court believes he was instead trying to get from the machine what humans familiar with the procedure had refused him.
Electronic Filing Access Revoked
The sanction, issued on August 6, 2026 in a fourteen-page ruling, was immediate: the plaintiff lost access to electronic filing and will have to submit his future filings on paper to the clerk's office. He was not fined, however, and the case is not over. Judge Spader notes that the Connecticut judiciary does not use any AI to review filings. Still, he takes the opportunity to warn the opposing lawyers, since they may run received documents through an AI tool.
Let's use this new example as a reminder. At present, any incoming document can become a potential vector for manipulating a model, whether it is an expert report or a simple memo. I have already discussed this topic in other articles, such as the AI worm that spreads from document to document via Copilot for Word, also hidden as white text on a white background, or the Gemini email summaries hijacked for phishing.
Let's end with an interesting detail. 404 Media submitted the booby-trapped document to ChatGPT and asked it to decide. The model said it had noticed and ignored the prompt injection in the document, adding that its presence raised a credibility issue. The attempt to influence the court's decision was therefore doomed twice over...
What do you think?


