A proof-of-concept attack demonstrates how a single compromised employee's inbox can escalate to a full CEO account takeover and business email compromise (BEC), leading to a $247,500 wire transfer heist facilitated by Microsoft Copilot’s AI assistant capabilities. The attack chain starts with routine account compromises but introduces a novel aspect: leveraging Copilot itself to quickly deduce organizational hierarchies and identify high-value targets within seconds. Microsoft Copilot Flaw The Red Team initially used Copilot to create an inbox rule that silently redirected sign-in notifications to the Deleted Items folder, effectively neutralizing alerts that typically expose account takeovers.

With persistence secured, a single prompt from Copilot revealed the company’s org chart and flagged an active email thread with the CEO, turning a full-time employee's cluttered inbox into a targeting map that would normally require hours of manual parsing. The Copilot responded with an impersonal “Lackawanna County Contract Wire for $247,500 Awaiting Final Approval,” effectively circumventing traditional security tools that flag bulk-search and download patterns. Barracuda suggests layered defenses: Email Gateway Defense to block malicious links before delivery, and Managed XDR to detect post-compromise indicators like inbox rule abuse and anomalous forwarding, treating AI-enabled accounts as a critical security concern moving forward.