Barracuda Networks researchers demonstrated a proof-of-concept attack showing how email-integrated AI assistants such as Microsoft Copilot could amplify business email compromise after a single mailbox is breached. In the simulated intrusion, attackers used the assistant to create stealthy inbox rules, map internal relationships, summarize sensitive threads, and mimic a user’s writing style, allowing them to conduct reconnaissance and launch convincing internal phishing from a legitimate account.
The attack chain escalated from an employee mailbox to the CEO’s account by capturing the executive’s session token through an adversary-in-the-middle proxy, bypassing MFA and giving the attackers control of the real mailbox. From there, the CEO’s AI assistant was used to identify a legitimate pending wire transfer—reported in one scenario as $247,500—and generate fraudulent payment instructions redirecting funds to an attacker-controlled bank account, while forwarding or deleting messages to conceal the fraud; researchers warned that the risk extends beyond Copilot to any AI assistant with inbox access.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Barracuda researchers conducted a simulated proof-of-concept attack showing how an attacker with access to one employee mailbox could abuse an email AI assistant such as Microsoft Copilot to hide alerts, reconnoiter internal relationships, phish the CEO through an adversary-in-the-middle link, steal a session token to bypass MFA, and then use the CEO mailbox to redirect a legitimate pending wire transfer. The research was presented as a warning that AI assistants with inbox access could amplify business email compromise and financial fraud after initial mailbox compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.