started · updated
Microsoft Copilot Exploited in Proof‑of‑Concept BEC Attack Targeting CEOs
Barracuda Networks demonstrated a controlled proof‑of‑concept in which attackers weaponize Microsoft Copilot, the AI assistant embedded in Microsoft 365, to accelerate a business email compromise (BEC) operation. By compromising a regular employee mailbox, the threat actors use Copilot prompts to create hidden inbox rules, map the organization’s hierarchy, and extract recent financial communications. The AI then drafts a convincing phishing message in the employee’s style, which is sent from the compromised account to the CEO. After stealing the CEO’s session token and bypassing multi‑factor authentication, the attackers gain full control of the CEO’s mailbox, locate a pending $247,500 wire transfer, and use Copilot‑generated language to request a change of bank account, successfully redirecting the funds. The demonstration shows that AI assistants can turn a single compromised account into a rapid, large‑scale fraud vector, and the technique could be replicated with other widely available AI tools.
Entities
Barracuda Networks · Microsoft 365 · Microsoft Copilot · Microsoft Corp