Copilot Facilitates Faster Wire Fraud Attacks with Stolen Employee Login
Researchers from Barracuda have demonstrated how Microsoft Copilot can be used to facilitate faster and more efficient wire fraud attacks. The proof of concept, described in an August 4 report by HackersRadar, shows that a stolen employee's login into Microsoft 365 can lead to a quicker chain of events, ultimately resulting in a stolen executive session.
The attack starts with a compromised employee's mailbox, where the attacker uses Copilot to create an inbox rule that hides sign-in notifications. This allows the attacker to go undetected as they read recent conversations and map the company structure.
Copilot is then used to draft a message from the employee to the CEO, using material from a real thread. The message carries a fake invoice confirmation link, which captures the CEO's session token when clicked.
The AI assistant helps the attacker find and delete messages tied to the scheme, making it easier for them to cover their tracks.