Updated
Updated · startupfortune.com · Aug 17
Barracuda Shows Copilot Aided $247,500 Wire Fraud After 1 Microsoft 365 Login Theft
Updated
Updated · startupfortune.com · Aug 17

Barracuda Shows Copilot Aided $247,500 Wire Fraud After 1 Microsoft 365 Login Theft

1 articles · Updated · startupfortune.com · Aug 17

Summary

  • $247,500 in pending payments was exposed in Barracuda’s proof of concept after attackers used Microsoft Copilot inside a compromised CEO mailbox to identify a wire transfer and draft altered bank instructions.
  • 1 stolen Microsoft 365 employee login started the chain: Copilot hid sign-in alerts, summarized inbox threads, identified the CEO and helped craft a phishing message that captured the executive’s live session token through an adversary-in-the-middle link.
  • MFA did not stop the takeover because the attack stole an active session rather than guessing a password, and the fraud email came from the real CEO account, bypassing typical spoofing checks.
  • Barracuda said Copilot was not exploited through a new vulnerability; the AI simply accelerated reconnaissance, message drafting, inbox-rule creation and cleanup using permissions from already compromised accounts.
  • The broader warning is that AI assistants with access to email and workflow history can turn one account breach into a faster business-email-compromise attack, pushing defenders to watch for hidden inbox rules, finance-message forwarding and unusual Copilot searches after risky logins.

Insights

If hackers steal your session token, can hardware-backed MFA truly stop an AI from draining your company's bank accounts?
How does an AI productivity tool become the ultimate weapon for corporate hackers without any actual software vulnerability?
When AI perfectly mimics a CEO's writing style to authorize wire transfers, how can finance teams distinguish friend from foe?