Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Varonis: SearchLeak: How Hackers Exploit Copilot to Steal Data

Varonis
07/04/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


it's a chain reaction designed to steal data. Firm's Threat Labs recently uncovered a new AI attack called Search Leak. Search Leak is like ordering something simple, like a nice little cookie. The bag shows up completely normal, but there's a hidden label on the bag, and the moment it appears, it automatically sends an order to go somewhere else. That's basically what's happening with Search Leak. It starts with a link you get at work, through Teams, email, Slack, anything. You click it, and it just opens Copilot, but that link contains hidden instructions, so instead of just searching, the Copilot that's plugged into your workplace starts digging through your mailbox. It then hides what it finds in an image tag waiting to be opened. That image request gets routed through Bing, which then hands it off to the attacker. In Copilot, Bing is trusted, and kind of unassuming, making it the perfect middleman for this attack. Search Leak comes off the heels of Varonis Threat Labs' discovery of Reprompt. The danger of this attack comes from a chain of older issues, like injection, race conditions, and server-side requests, now stitched together by AI and enabled by a single click. Microsoft patched this, but there's a lesson to be learned. AI attacks aren't always about brand new tricks. AI might just be connecting older weaknesses in ways we haven't seen before. So please, keep an eye on your AI.

TL;DR

  • Varonis Threat Labs discovered SearchLeak, an attack that hijacks Microsoft Copilot Enterprise via prompt injection to silently search and exfiltrate data from corporate mailboxes.
  • The attack is triggered by a single malicious link sent through Teams, email, or Slack, requiring no additional user interaction beyond clicking.
  • Stolen data is smuggled out through Bing image requests, exploiting Bing's trusted status within the Copilot environment as a covert exfiltration channel.

Summary

Varonis Threat Labs has uncovered SearchLeak, a novel AI-enabled attack chain that weaponizes Microsoft Copilot Enterprise to silently exfiltrate sensitive data from corporate mailboxes. The attack begins with a seemingly harmless link delivered through common workplace channels — Teams, email, or Slack. When clicked, the link opens Copilot but embeds hidden prompt injection instructions that direct the AI to search through the victim's mailbox without their knowledge. Exfiltrated data is concealed inside an image tag, which routes an outbound request through Bing — a trusted, low-suspicion domain within the Copilot ecosystem — ultimately delivering the stolen information to the attacker. What makes SearchLeak particularly dangerous is that it doesn't rely on a single zero-day vulnerability. Instead, it chains together well-known weaknesses — prompt injection, race conditions, and server-side request forgery — and uses AI as the connective tissue to execute them with a single click. Microsoft has since patched the vulnerability, but the broader lesson is significant: AI systems can amplify the impact of legacy attack techniques in ways defenders haven't yet anticipated. SearchLeak follows Varonis Threat Labs' earlier discovery of Reprompt, signaling an emerging pattern of AI-native attack research from the firm.

Chapters

0:00 - Introducing SearchLeak
0:09 - How the Attack Works
0:38 - Bing as the Exfiltration Channel
0:59 - Patch & Key Takeaway

Key Quotes

0:00 "The latest AI attack isn't a single flaw, it's a chain reaction designed to steal data."
0:42 "In Copilot, Bing is trusted, and kind of unassuming, making it the perfect middleman for this attack."
1:02 "AI attacks aren't always about brand new tricks. AI might just be connecting older weaknesses in ways we haven't seen before."

FAQ

Has Microsoft fixed the SearchLeak vulnerability?

Yes. According to Varonis, Microsoft has patched the SearchLeak vulnerability. However, the attack illustrates a broader risk: AI can chain legacy weaknesses in new ways, so ongoing vigilance around AI-connected tools remains essential.

How does SearchLeak exfiltrate data without the victim noticing?

The attack hides stolen data inside an image tag embedded in a Copilot response. When that image loads, it sends an outbound request routed through Bing — a trusted domain — which then passes the data to the attacker, all without visible user interaction.


Categories:
  • » Webinar Library » Varonis
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Threat Intelligence
  • Security Operations
  • Short Form
  • Data Protection
  • AI security vulnerabilities
  • Prompt injection attacks
  • Microsoft Copilot Enterprise
  • Data exfiltration techniques
  • Threat research
  • Legacy vulnerability chaining
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Varonis: SearchLeak: How Hackers Exploit Copilot to Steal Data

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Ensuring Compliance Through Audit Evidence: From CJIS to FERPA

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Ensuring Compliance Through Audit Evidence: From CJIS to FERPA
                      https://www.truthinit.com/index.php/channel/2159/ensuring-compliance-through-audit-evidence-from-cjis-to-ferpa/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version