Security researchers disclosed attacks against Microsoft Copilot that use prompt injection and chained requests to extract sensitive data with minimal user interaction. Varonis Threat Labs described a single-click technique called Reprompt against Microsoft Copilot Personal that abuses legitimate Copilot links with a prefilled q parameter, then uses a double-request and chain-request flow to hide exfiltration instructions on an attacker-controlled server. The report said the attack could continue pulling data from an active session even after the Copilot tab was closed, while evading many client-side monitoring tools; Microsoft said the issue had been patched, and Varonis reported that Microsoft 365 Copilot enterprise customers were not affected.
A separate report from Rubrik Zero Labs said it had broken the Microsoft 365 Copilot sandbox in research published under the title ChatMate, indicating continued scrutiny of Copilot’s isolation and data-protection boundaries across Microsoft’s AI offerings. Together, the disclosures highlight how trusted Copilot workflows, prefilled prompts, and multi-step prompt handling can be abused to bypass intended safeguards and expose user data, reinforcing the need to treat AI prompt inputs and follow-on actions as untrusted.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft confirmed the Reprompt issue had been patched by the time Varonis published its report. The write-up also states that Microsoft 365 Copilot enterprise customers were not affected.
Varonis Threat Labs uncovered an attack flow dubbed "Reprompt" in Microsoft Copilot Personal that uses legitimate Copilot links with prefilled prompts to enable one-click, stealthy data exfiltration. The report says the technique abuses the URL q parameter and chained follow-on requests to bypass Copilot safeguards.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.