SQL injection attacks involve inserting malicious SQL code into a legitimate query to manipulate database behavior.