CIO Brief: Your AI Assistant Can Be Tricked Into Leaking Data
Retrospective: this article looks back at events from June 2025, written in 2026 with the benefit of hindsight.
The short version: In 2025, researchers found a way to trick Microsoft 365 Copilot into leaking data simply by sending an email with hidden instructions — the user didn't need to click anything. Microsoft fixed it. But the underlying risk — AI assistants being manipulated by content they read — is here to stay.
Why AI assistants can be tricked
Copilot reads your emails, documents and chats to answer questions. Some of that content comes from outsiders. If an attacker hides instructions inside an email, the AI might follow them — for example, retrieving sensitive information and sending it somewhere. This is called prompt injection.
The business impact
- Data leakage without user action.
- New attack surface that traditional security tools don't cover.
- Regulatory questions about AI handling of sensitive data.
Questions to ask your team
- What sensitive information can Copilot access in our organization?
- Have we limited Copilot's access to highly confidential documents?
- Do we monitor how Copilot is used with sensitive data?
- Do we track security advisories for our AI tools?
What good looks like
Copilot access limited by permissions cleanup, sensitivity labels and data loss prevention; monitoring of AI interactions; and AI vulnerabilities tracked like any other software flaw.
The decision
Treat Copilot and other AI assistants as part of your security program — with their own risk assessment, controls and monitoring — not just as productivity tools.
- EchoLeak (June 2025): The First Zero-Click Attack on Microsoft 365 Copilot Incident Teardowns
- How to Reduce Copilot Prompt-Injection Exposure With Labels and DLP How-To & Hardening
- Detecting Copilot Prompt Injection: Defender XDR and Sentinel Hunting Queries Detection & Response