Barracuda researchers showed how Microsoft Copilot can turn a stolen Microsoft 365 login into a faster wire fraud chain, but the dangerous step is the one the old draft blurred: the attacker still has to take over the CEO's account.
You don't need custom malware to make this kind of attack move quickly. You need one ordinary employee's Microsoft 365 account, a convincing message, and an AI assistant that can search the inbox faster than any fraudster working by hand.
That is the point in Barracuda's proof of concept, described in an August 4 report from HackersRadar. The attack starts with a standard employee's mailbox, not the CEO's. From there, researchers showed how Microsoft Copilot could help an attacker hide login alerts, read recent conversations, map the company structure and find the person worth targeting next.
That distinction matters. The first login doesn't magically give the attacker the CEO's authority. It gives them context. In a business email compromise scheme, context is money.
The researchers used Copilot to create an inbox rule that sent sign-in notifications to Deleted Items, keeping the compromised employee from seeing the warning. Then they asked Copilot to summarize active threads and identify the CEO. Instead of spending hours reading stale email, the attacker gets a clean view of who talks to whom and what kind of message might be believed.
Perplexity launched Personal Computer for Windows on July 28, 2026, a $200-per-month AI desktop agent that reads local files, routes tasks across 20-plus frontier models, and works inside File Explorer, Word, Excel, and Outlook. It's the most direct challenge yet to Microsoft Copilot, on Microsoft's own operating system, and it costs six times as... - perplexity AI agent Windows pricing - beating Microsoft Copilot with alternatives Copilot then helped draft a message from the employee to the CEO, using material from a real thread. The message carried a fake invoice confirmation link. When the CEO clicked it, the attack moved through an adversary-in-the-middle proxy that captured the CEO's session token. MFA didn't save the account at that point, because the attacker wasn't guessing a password. They were stealing a live session.
The AI didn't break in by itself #
Once inside the CEO's mailbox, the proof of concept got sharper. The attackers asked Copilot for recent financial emails, including invoices, dollar amounts and upcoming transfers. It surfaced a pending $247,500 wire transfer awaiting final approval. That's the kind of detail a human attacker would normally have to dig for line by line.
Then Copilot helped draft the finance-team message in the CEO's own style. It asked for a change to the receiving bank details. Because the message came from the real CEO mailbox, it passed the checks that usually catch spoofed email. That is why this works.
After the fraudulent instruction went out, the attackers set up a forwarding rule to catch replies from finance before the CEO saw them. Copilot was also used to find and delete messages tied to the scheme. None of that required a new Copilot vulnerability. It used the permissions of accounts the attacker had already compromised.
Here's the thing. Calling this only a Copilot problem lets companies look in the wrong place. Copilot made the fraud faster, cleaner and easier to aim, but the root failure was still identity. A stolen employee session led to a stolen executive session. The AI just removed the slow parts.
That is still a serious shift. In the old version of business email compromise, an attacker had to read the mailbox, learn the tone, spot the payment and write the message. With Copilot sitting inside Microsoft 365, those jobs can be handed to the assistant in plain English. The work gets compressed from patient reconnaissance into a short series of prompts.
Security teams need to watch the assistant #
A normal security stack is not built to treat a user's AI assistant as a suspect. It sees mailbox searches, summaries, draft messages and inbox rules. Those are everyday actions inside Microsoft 365. No malware lands on disk. No strange executable runs. No exploit chain announces itself.
Signal's Meredith Whittaker says AI agents are surveillance infrastructure and she's right
Signal president Meredith Whittaker issued a blunt warning on June 20 that AI agents like Microsoft Copilot are surveillance infrastructure in disguise, arguing their sweeping access to contacts, messages, and credentials effectively nullifies end-to-end encryption. Her critique lands at a pivotal moment for startups building agentic workflows on... - AI agents privacy surveillance concerns - how to protect data from AI
That is why the cleanest defenses are boring ones. Require phishing-resistant MFA where possible. Watch for new inbox rules that hide security alerts or forward finance replies - that's the tell. Flag sudden Copilot searches across invoices, payment language and executive correspondence after a risky login, and treat one compromised Microsoft 365 session as a bigger event than it used to be.
Microsoft doesn't need to be uniquely broken for this to matter. Any AI assistant with access to email, files and workflow history can become a knowledgeable insider once the wrong person is logged in. Your company may have bought Copilot to save employees time. Attackers want the same thing.
Also read: A Single Video Call Can Root Millions of Unisoc-Powered Android Phones • Unitree Says Its New Superman Robot Just Outran Usain Bolt • Micron Launches a $250 Million Fund to Bankroll the AI Startups Buying Its Chips