Researchers Show AI Copilot Can Supercharge Email Fraud After Account Compromise
Cybersecurity firm Barracuda Networks published research on August 4, 2026, demonstrating how attackers can weaponize Microsoft 365 Copilot once they gain access to a regular employee's mailbox. In the lab simulation, the attacker used Copilot to rapidly map the organization, extract confidential email threads, and mimic the victim's writing style — all without deploying any malware. The attacker then lured the CEO into an adversary-in-the-middle phishing proxy, stole the authenticated session token, and accessed the CEO's mailbox to identify a live wire transfer of $247,500. Posing as the CEO, the attacker sent a convincing bank-account-change request to the finance team, with replies secretly forwarded to an external address and evidence deleted via Copilot. Because all emails originated from legitimate internal accounts, standard SPF, DKIM, and DMARC checks passed, though identity and mailbox audit logs could still detect the anomalous rule creation, bulk summarization, and deletion activity.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in