An Employee Opens a Webpage. That Is All It Takes.
An employee at a mid-sized firm is logged into Microsoft Copilot Personal, as most staff now are for at least part of the working day. She opens a webpage someone sent her, or a shared document sitting in her inbox like any other file. She reads a paragraph, closes the tab, and moves on. Nothing about the page looks wrong. She never clicks a link inside it, never downloads anything, and never types a password anywhere.
That single act of opening the page is the entire attack. Security research firm Varonis found that a hidden prompt embedded in ordinary-looking content is enough to make Copilot act on an attacker's instructions the moment it reads that content, inside the session she already has open. Varonis named the flaw SearchLeak and disclosed it alongside two related vulnerabilities in Copilot Personal.
Two Flaws, Chained, Equal Full Data Access
The SearchLeak chain works by combining two separate weaknesses. First, an attacker crafts a webpage or document that carries a hidden malicious prompt, written to look like ordinary text or metadata rather than an instruction. Second, when a victim who is already logged into Copilot visits that page or opens that document, the hidden prompt executes automatically inside her authenticated session. No further click, no approval dialog and no second warning stands between the page loading and the prompt running.
Once the prompt is running with her authority, it tells Copilot to query whatever the victim has already authorized it to reach: her email, her files, and any third-party apps connected to her account. Copilot does not ask her to confirm this, because from its own perspective it is simply carrying out an instruction inside a legitimate, already-authenticated session.
The final step is exfiltration, and Copilot supplies the tool for that too. Using its own built-in capability to fetch URLs, the compromised assistant sends the data it has gathered out to a webhook controlled by the attacker. The victim's session, her authorizations and Copilot's own features are all working exactly as designed. Nothing in that chain requires her to make a mistake.
A Second Door: Poisoning Copilot's Memory
Varonis disclosed a third, separate flaw alongside the SearchLeak chain, this one reached through Copilot's web-page summarization feature. Rather than exfiltrating data in one pass, this path lets an attacker plant false or manipulated information into what Copilot remembers about a user, poisoning its memory through content the assistant is asked to summarize.
That matters because it turns a single bad webpage into a lingering problem rather than a one-time event. An assistant's memory is meant to make it more useful over time, carrying context between sessions. A poisoned memory carries an attacker's influence between sessions in exactly the same way, long after the page that planted it has been closed.
Why This Is Not Phishing
Traditional phishing depends on tricking a person: click this link, enter your password here, approve this login. Security training exists to catch that moment of human decision. SearchLeak has no such moment. The victim did not click a malicious link, did not enter a credential, and was not shown anything resembling a warning to override.
The exploit fires when the AI assistant reads content, not when the human clicks anything. That is a different trigger entirely, and it sits outside everything that standard 'do not click suspicious links' training was built to prevent. An employee who did everything right by every existing standard could still trigger this chain simply by opening a file that had been sent to her.
This is the core of the new risk. An AI copilot that carries standing, already-authorized access to a person's email, files and connected apps becomes a single point of compromise the moment it can be tricked into acting on instructions hidden inside content it merely reads. The assistant's usefulness, that it can act on your behalf without you re-authorizing every step, is the same property that makes this attack possible.
What EU and UK Businesses Should Actually Check
Microsoft rated SearchLeak critical and has already patched it, so the specific flaw described here is closed. That is good news, and not the reason to keep reading. The pattern it belongs to, prompt injection through content an AI assistant passively consumes rather than content a human actively clicks, is not going away, and it will recur in some other connected assistant with some other trigger.
For any business now rolling out Microsoft 365 Copilot or a similarly connected AI assistant, the useful exercise is not just training staff to spot suspicious links. It is asking what that assistant can be tricked into doing with the standing access it already holds, and treating 'prompt injection via passively-consumed content' as its own line item in vendor risk assessments. Because that standing access typically touches personal data, this belongs in GDPR data-processing risk assessments too, not only in the IT security backlog.
Read next: France's Tax Agency Is Exempt From Its Own GDPR Fines | Hidden AI Reasoning Leaked Via Cheaper Sibling Models



