Published on August 6, 2026

Compromised Microsoft Copilot Accounts Could Enable Business Email Compromise


Severity

Medium

Detail

Barracuda’s Red Team has demonstrated how a compromised Microsoft 365 account with Microsoft Copilot access could be abused to facilitate business email compromise (BEC) attacks. In a controlled proof-of-concept, the researchers showed that attackers could use Copilot to gather organizational information, impersonate a company CEO, and redirect a USD 247,500 wire transfer. The findings highlight how AI assistants can assist attackers in accelerating post-compromise activities without exploiting vulnerabilities in Copilot itself.

How?

The proof-of-concept did not rely on vulnerabilities in Microsoft Copilot. Instead, it demonstrated how attackers could misuse Copilot’s legitimate capabilities after obtaining access to a Microsoft 365 account.

Following the compromise of an employee’s account, the attackers used Copilot to create an inbox rule that automatically deleted Microsoft sign-in notifications. This helped conceal unauthorized access by preventing the legitimate user from seeing security alerts or suspicious login activity.

The attackers then instructed Copilot to review the employee’s mailbox, including email conversations, shared files, calendar invitations, and communication history. By analyzing this information, Copilot identified key personnel, mapped reporting relationships, and revealed ongoing business activities. Using these insights, the attackers selected the company’s CEO as their next target and generated a phishing email that closely matched the employee’s normal writing style.

The phishing email directed the CEO to a malicious invoice page hosted behind an adversary-in-the-middle (AiTM) proxy. When the CEO accessed the page, the attackers captured the authenticated session token, allowing them to access the CEO’s Microsoft 365 account without needing to bypass multifactor authentication (MFA). Additional inbox rules were then configured to suppress security notifications and hide evidence of the compromise.

With access to the CEO’s mailbox, the attackers used Copilot to rapidly identify recent financial discussions, invoices, payment amounts, and pending transactions. This enabled them to locate a legitimate wire transfer valued at USD 247,500 that was awaiting approval without manually searching through large volumes of email.

The attackers then instructed Copilot to draft a fraudulent request to change the beneficiary bank account. Because the email was sent from the CEO’s legitimate mailbox, referenced an actual pending transaction, and matched the CEO’s communication style, the finance team accepted the request and transferred the funds to an attacker-controlled account.

To avoid detection, the attackers configured another inbox rule that forwarded replies from the finance team to an external email address while preventing those messages from appearing in the CEO’s mailbox. After the fraudulent transaction was completed, Copilot was used to locate and remove emails associated with the attack in an attempt to erase evidence.

Barracuda’s research demonstrates that AI assistants do not require additional privileges to increase security risks. Once a Microsoft 365 account is compromised, Microsoft Copilot can quickly process emails, documents, and organizational data using the same permissions as the legitimate user. This enables attackers to perform reconnaissance, craft convincing phishing emails, and conduct business email compromise attacks far more efficiently, highlighting the importance of strong identity protection, monitoring of inbox rules, and timely detection of compromised accounts.

Conclusion

Barracuda’s research shows that AI assistants do not require additional privileges to increase security risks. Once a Microsoft 365 account is compromised, Microsoft Copilot can process emails, documents, and organizational data using the same permissions as the compromised user, enabling attackers to accelerate reconnaissance and business email compromise activities.

Source

Compromised Microsoft Copilot Accounts Let Hackers Impersonate CEOs and Steal $247,500