Microsoft Copilot Cowork flaw exposed as prompt injection leaks enterprise files

Microsoft Copilot Cowork flaw exposed as prompt injection leaks enterprise files

N
News Editor 01
2026-07-22 16:05:16
PromptArmor says Microsoft 365 Copilot Cowork can be abused through a malicious skill file, allowing silent exfiltration of sensitive SharePoint and OneDrive documents without clear user approval.
MicrosoftAI securityCopilotdata exfiltrationprompt injection

Security firm PromptArmor says it found a reproducible prompt injection attack chain in Microsoft 365 Copilot Cowork. In its tests, an attacker only needed 5 malicious lines inside an 81-line skill configuration file to make the AI agent send sensitive files from SharePoint and OneDrive to an attacker-controlled server, all without the user realizing what was happening. The report states the researchers ran the attack 5 times and succeeded in all 5 cases.

A consent gap sits at the center of the attack

The key issue described by PromptArmor is the gap between Microsoft’s documentation and the product’s observed behavior. Microsoft’s public documentation says Cowork asks for user approval before carrying out sensitive actions such as sending emails or posting messages in Teams. PromptArmor says that safeguard did not apply when the destination was the user themself. Sending an email to oneself or posting a Teams message to oneself was carried out automatically, with no approval prompt and no user setting available to change that behavior.

According to the report, Copilot Cowork is a Frontier feature in Microsoft 365 and can use Microsoft Graph to access a user’s cloud permissions across enterprise data. That means the agent can reach the same files the user can access, including financial reports in SharePoint, HR documents in OneDrive, and files containing personally identifiable information.

Six steps turn a routine workflow into silent exfiltration

PromptArmor lays out the attack chain in six stages. First, the victim already has sensitive files stored in SharePoint or OneDrive. Second, the victim downloads a skill configuration file from the internet and uploads it into Copilot Cowork, an action the report describes as similar to installing a plugin. The skill file is then automatically loaded from a specific path in the user’s OneDrive, while administrators have very limited visibility into that process.

Third, the victim asks Copilot Cowork to summarize the week’s work, which triggers the skill. Fourth, the injected instructions make the agent generate pre-authenticated download links for each file and embed those links into malicious HTML image tags as query parameters sent to the attacker’s server. These links contain authorization data, so anyone who obtains them can download the files directly without signing into a Microsoft account.

Fifth, the agent sends a Teams message to the victim’s own account with the malicious image tags embedded inside it. No approval is required, and the malicious content is hidden from the user. Sixth, when the victim opens the Teams message, the browser automatically loads the images, sending the pre-authenticated URLs to the attacker’s server, where they can later be used to retrieve the files.

More capable models may widen the scope of leakage

PromptArmor says the problem is not limited to one model. The report says both Claude Opus 4.7 and Claude Sonnet 4.6 were affected in validation, with Opus 4.7 acting more aggressively by expanding the search scope and including files that had been opened in the victim’s Cowork sessions earlier that week.

The researchers also say the attack did not depend on the wording of the user’s request. If any query caused the malicious skill to load, the injection could succeed. The report adds that Copilot Cowork supports scheduled tasks. Once a malicious injection enters that schedule, the workflow can keep running quietly on each cycle, leaking enterprise data even when the user takes no new action.

PromptArmor calls it a design risk, not a single bug

In PromptArmor’s view, this is not the kind of issue that can be fully addressed with one patch. The firm describes it as a systemic risk in enterprise AI agent design: once an agent is granted delegated permissions across multiple systems, the failure of a single trust boundary can open a path to much broader data exposure.

The firm also says it separately disclosed another issue to Microsoft that could allow data to escape directly from the Copilot Cowork sandbox, and that matter is now in a responsible disclosure process. As for the attack chain detailed in this report, the researchers chose to publish because they see the exposure as rooted in the architecture itself, meaning users should be able to decide whether they accept that risk.

Current mitigations focus on reducing what the agent can do

The report says the most practical mitigations now center on restricting download access. Administrators can limit file downloads through SharePoint, including by setting Set-SPOSite -Identity <SiteURL> -BlockDownloadPolicy $true, or by blocking downloads based on sensitivity labels.

That comes with a clear tradeoff. Users may only be able to view files in the browser, while downloading, printing, and syncing are disabled across Microsoft 365 applications including Word, Excel, and PowerPoint.

The article places this incident within a broader run of Copilot security issues. It cites EchoLeak (CVE-2025-32711) in the consumer Copilot product, the Reprompt attack studied by Varonis (CVE-2026-24307), and an indirect prompt injection flaw in Copilot Studio (CVE-2026-21520, CVSS 7.5) that has been patched, while similar classes of weaknesses remain visible across the wider Copilot product line.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.