< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Microsoft Copilot Exploited in Proof‑of‑Concept BEC Attack Targeting CEOs

Barracuda Networks demonstrated a controlled proof‑of‑concept in which attackers weaponize Microsoft Copilot, the AI assistant embedded in Microsoft 365, to accelerate a business email compromise (BEC) operation. By compromising a regular employee mailbox, the threat actors use Copilot prompts to create hidden inbox rules, map the organization’s hierarchy, and extract recent financial communications. The AI then drafts a convincing phishing message in the employee’s style, which is sent from the compromised account to the CEO. After stealing the CEO’s session token and bypassing multi‑factor authentication, the attackers gain full control of the CEO’s mailbox, locate a pending $247,500 wire transfer, and use Copilot‑generated language to request a change of bank account, successfully redirecting the funds. The demonstration shows that AI assistants can turn a single compromised account into a rapid, large‑scale fraud vector, and the technique could be replicated with other widely available AI tools.

Entities

Barracuda Networks · Microsoft 365 · Microsoft Copilot · Microsoft Corp