A new proof-of-concept exposes how hackers can leverage Microsoft Copilot in their business email compromise (BEC) and large-scale wire fraud attacks. The demonstration reveals that a single compromised employee account can rapidly escalate into full CEO takeover within minutes of gaining access to the inbox, resulting in the theft of up to $250,000 with minimal technical effort from the attacker. Instead of using traditional "living off the land" techniques like PowerShell scripts or remote access tools, Barracuda researchers showed attackers abusing Copilot itself to speed up every stage of the intrusion.

Their first move is establishing persistence: a simple Copilot prompt creates an inbox rule that silently redirects sign-in notifications to the Deleted Items folder, preventing the victim from noticing suspicious login alerts.

Upon entering the CEO's mailbox, the attackers request Copilot for a "refresh on recent financial emails, including invoices, monetary values, and upcoming transfers." Within moments, Copilot surfaces a pending $247,500 wire transfer awaiting final approval. For cybersecurity teams, the key takeaway is clear: AI-enabled accounts can pose a significant threat once an account has been compromised, necessitating increased vigilance regarding monitoring of these accounts, abuse of inbox rules, and unusual session activities as part of identity and email security strategies.

Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations -> Integrate ANY.RUN With Your SOC Now.