Skip to content
ThreatCluster

Microsoft 365 Copilot Vulnerability Allows Data Theft via Indirect Prompt Injection

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Microsoft has patched a vulnerability in Microsoft 365 Copilot that allowed attackers to exploit indirect prompt injection to access sensitive corporate emails. The flaw was identified by security researcher Adam Logue, who reported that attackers could embed malicious instructions in Office documents, leading the AI assistant to retrieve and leak sensitive data. Microsoft determined that the Copilot tool is not eligible for their bug bounty program.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)