Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Varonis: SearchLeak: How Hackers Exploit Copilot to Steal Data

Varonis
07/04/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


it's a chain reaction designed to steal data. Firm's Threat Labs recently uncovered a new AI attack called Search Leak. Search Leak is like ordering something simple, like a nice little cookie. The bag shows up completely normal, but there's a hidden label on the bag, and the moment it appears, it automatically sends an order to go somewhere else. That's basically what's happening with Search Leak. It starts with a link you get at work, through Teams, email, Slack, anything. You click it, and it just opens Copilot, but that link contains hidden instructions, so instead of just searching, the Copilot that's plugged into your workplace starts digging through your mailbox. It then hides what it finds in an image tag waiting to be opened. That image request gets routed through Bing, which then hands it off to the attacker. In Copilot, Bing is trusted, and kind of unassuming, making it the perfect middleman for this attack. Search Leak comes off the heels of Varonis Threat Labs' discovery of Reprompt. The danger of this attack comes from a chain of older issues, like injection, race conditions, and server-side requests, now stitched together by AI and enabled by a single click. Microsoft patched this, but there's a lesson to be learned. AI attacks aren't always about brand new tricks. AI might just be connecting older weaknesses in ways we haven't seen before. So please, keep an eye on your AI.

TL;DR

  • Varonis Threat Labs discovered SearchLeak, an attack that hijacks Microsoft Copilot Enterprise via prompt injection to silently search and exfiltrate data from corporate mailboxes.
  • The attack is triggered by a single malicious link sent through Teams, email, or Slack, requiring no additional user interaction beyond clicking.
  • Stolen data is smuggled out through Bing image requests, exploiting Bing's trusted status within the Copilot environment as a covert exfiltration channel.

Summary

Varonis Threat Labs has uncovered SearchLeak, a novel AI-enabled attack chain that weaponizes Microsoft Copilot Enterprise to silently exfiltrate sensitive data from corporate mailboxes. The attack begins with a seemingly harmless link delivered through common workplace channels — Teams, email, or Slack. When clicked, the link opens Copilot but embeds hidden prompt injection instructions that direct the AI to search through the victim's mailbox without their knowledge. Exfiltrated data is concealed inside an image tag, which routes an outbound request through Bing — a trusted, low-suspicion domain within the Copilot ecosystem — ultimately delivering the stolen information to the attacker. What makes SearchLeak particularly dangerous is that it doesn't rely on a single zero-day vulnerability. Instead, it chains together well-known weaknesses — prompt injection, race conditions, and server-side request forgery — and uses AI as the connective tissue to execute them with a single click. Microsoft has since patched the vulnerability, but the broader lesson is significant: AI systems can amplify the impact of legacy attack techniques in ways defenders haven't yet anticipated. SearchLeak follows Varonis Threat Labs' earlier discovery of Reprompt, signaling an emerging pattern of AI-native attack research from the firm.

Chapters

0:00 - Introducing SearchLeak
0:09 - How the Attack Works
0:38 - Bing as the Exfiltration Channel
0:59 - Patch & Key Takeaway

Key Quotes

0:00 "The latest AI attack isn't a single flaw, it's a chain reaction designed to steal data."
0:42 "In Copilot, Bing is trusted, and kind of unassuming, making it the perfect middleman for this attack."
1:02 "AI attacks aren't always about brand new tricks. AI might just be connecting older weaknesses in ways we haven't seen before."

FAQ

Has Microsoft fixed the SearchLeak vulnerability?

Yes. According to Varonis, Microsoft has patched the SearchLeak vulnerability. However, the attack illustrates a broader risk: AI can chain legacy weaknesses in new ways, so ongoing vigilance around AI-connected tools remains essential.

How does SearchLeak exfiltrate data without the victim noticing?

The attack hides stolen data inside an image tag embedded in a Copilot response. When that image loads, it sends an outbound request routed through Bing — a trusted domain — which then passes the data to the attacker, all without visible user interaction.


Categories:
  • » Webinar Library » Varonis
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Threat Intelligence
  • Security Operations
  • Short Form
  • Data Protection
  • AI security vulnerabilities
  • Prompt injection attacks
  • Microsoft Copilot Enterprise
  • Data exfiltration techniques
  • Threat research
  • Legacy vulnerability chaining
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Varonis: SearchLeak: How Hackers Exploit Copilot to Steal Data

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/27/2026
                      01:00 PM
                      08/27/2026
                      Becoming Agent Ready with Cyera: Essential Strategies and Insights
                      https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                    • 08/27/2026
                      01:00 PM
                      08/27/2026
                      Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                      https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/03/2026
                      01:00 PM
                      09/03/2026
                      Verge.io: Can You Afford Your Next Storage Refresh?
                      https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version