Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > How a Rogue Prompt Could Turn Microsoft Copilot Into a $250,000 Wire Fraud Accomplice
How a Rogue Prompt Could Turn Microsoft Copilot Into a $250,000 Wire Fraud Accomplice
Read Time:3 Minute, 30 Second

Business email compromise has always relied on patience: attackers spend days or weeks quietly reading a mailbox, learning who talks to whom, and waiting for the right invoice to hijack. A new proof-of-concept from Barracuda’s research team shows how that timeline can collapse dramatically when the attacker enlists an unwitting accomplice already embedded in the target’s inbox, Microsoft Copilot.

From One Compromised Inbox to CEO Takeover

The demonstrated attack starts the way many BEC campaigns do, with access to a single, ordinary employee’s mailbox. But instead of relying on classic “living off the land” tradecraft, PowerShell scripts, remote access tools, and hours of manual digging, the researchers showed attackers turning to Copilot itself to do the heavy lifting.

The first move is persistence. A simple prompt to Copilot creates an inbox rule that quietly redirects sign-in notification emails into the Deleted Items folder, so the real account owner never sees the alerts that would normally flag suspicious activity.

Reconnaissance at Machine Speed

From there, the attacker asks Copilot to summarize the organization’s structure and surface active email threads, a task that would traditionally take a human hours of sifting through months of correspondence. Within moments, the assistant identifies the company’s CEO as the highest-value target and surfaces a real email exchange between the compromised employee and that executive.

Using that authentic thread as raw material, the attacker prompts Copilot to draft a convincing message written in the victim’s own voice and tone, complete with a link disguised as an invoice confirmation. When the CEO clicks it, the link routes through an adversary-in-the-middle proxy that intercepts the session token, letting the attacker bypass multi-factor authentication entirely and take over the CEO’s account outright. The same Copilot-generated inbox rule trick is reused here too, hiding sign-in alerts on the newly hijacked mailbox.

Finding the Money

Once inside the CEO’s inbox, the attacker doesn’t manually search for financial records. Instead, they ask Copilot for a “refresher on recent financial emails, including invoices, monetary values, and upcoming transfers.” In seconds, Copilot surfaces a pending $247,500 wire transfer awaiting final approval, a detail that could have taken a human attacker hours to locate on their own.

Copilot is then asked to draft an urgent message to the finance team, written in the CEO’s authentic style, requesting a last-minute change to the destination bank account. Because the email genuinely originates from the real CEO mailbox and sails through every standard authentication check, SPF, DKIM, DMARC, it slips past traditional email security filters that are built to catch spoofed senders rather than a fully compromised, legitimate one. The finance team redirects the payment, and the money is gone.

Covering Tracks, Also With AI

To buy time before discovery, the attackers set up a forwarding rule that silently reroutes the finance team’s replies to an external address, intercepting any confirmation messages before the real CEO ever sees them. Finally, Copilot is used once more, this time to locate and delete evidence of the entire scheme across the mailbox, a cleanup job that would take a human attacker far longer to execute manually.

Why This Matters

Barracuda’s researchers stress that none of the individual techniques here are new; inbox rule abuse, adversary-in-the-middle phishing, and BEC-style wire fraud have all been documented for years. What’s changed is the speed and low technical bar. An attacker no longer needs deep scripting skill or hours of manual reconnaissance. A capable AI assistant that already has trusted access to the mailbox can be repurposed, prompt by prompt, to perform reconnaissance, drafting, and cleanup that used to require real operator expertise.

For defenders, the takeaway is that AI copilots embedded in productivity suites need to be treated as part of the attack surface, not just a productivity feature. Recommended mitigations include tightly scoping what mailbox rules can be created without review, monitoring for AI-assistant activity that touches financial correspondence, enforcing phishing-resistant MFA that can’t be relayed through a proxy, and requiring out-of-band verification for any last-minute changes to payment or banking details, no matter how legitimate the request looks in the inbox.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on How a Rogue Prompt Could Turn Microsoft Copilot Into a $250,000 Wire Fraud Accomplice, use the discussion on Forum.

>> forum community

Comments

Leave a Reply