EchoLeak (June 2025): The First Zero-Click Attack on Microsoft 365 Copilot
Facts in this article were checked against the sources listed below as of Oct 5, 2026.
Retrospective: this article looks back at events from June 2025, written in 2026 with the benefit of hindsight.
In June 2025, researchers at Aim Security (Aim Labs) disclosed EchoLeak, tracked as CVE-2025-32711 — described as the first "zero-click" exploit against an AI agent in a production system. It affected Microsoft 365 Copilot. Microsoft rated it critical (CVSS 9.3), fixed it on the service side, found no evidence of exploitation in the wild, and required no customer action.
- Crafted emailAn attacker sends an email containing hidden instructions written to look like normal content.
- No click neededThe recipient doesn't open or interact with it.
- RetrievalLater, when the user asks Copilot a question, Copilot's retrieval pulls the malicious email in as context.
- Scope violationThe injected instructions cause Copilot to include sensitive internal data in output that can reach an attacker-controlled destination.
- Fixed server-sideMicrosoft rates the issue critical (CVSS 9.3) and fixes it in June 2025; no in-the-wild exploitation is reported.
EchoLeak is worth studying not because it's still exploitable — it isn't — but because it demonstrates a durable class of risk that every organization deploying AI assistants now carries.
What happened, at a high level
EchoLeak was a form of indirect prompt injection:
- An attacker sent an email to a target. The email contained instructions written so that, to a human, it read like ordinary content.
- The target didn't need to open the email or click anything.
- Later, when the target asked Copilot a question, Copilot's retrieval process — which pulls relevant emails, files and chats into context — included the attacker's email.
- The hidden instructions caused Copilot to include sensitive information from the user's context in a response, in a way that could send that data to a destination the attacker controlled, bypassing some of Microsoft's protections.
Aim Labs called the underlying problem an "LLM scope violation": untrusted external content influencing the model to access and leak privileged internal data. Researchers noted that data reachable this way could include chat history, OneDrive files, SharePoint content and Teams messages within the user's access.
Why it mattered
AI assistants mix trusted and untrusted content. Copilot reasons over everything a user can access — including emails from strangers. Any of that content can contain instructions aimed at the model rather than the person.
Zero-click removes the human defense. Security awareness training can't help when the user never interacts with the malicious content.
Traditional controls weren't designed for this. Antivirus and URL filtering look for malware and malicious links; a block of persuasive text is neither.
Fixes are server-side — and opaque. Customers couldn't patch anything themselves. Their protection depended on Microsoft's fix and on how much sensitive data Copilot could reach in the first place.
What to do now
You can't eliminate prompt injection, but you can shrink what a manipulated assistant can reach and leak.
- Fix oversharing first. If Copilot can't access sensitive content, a manipulated Copilot can't leak it. Use SharePoint Advanced Management data access governance reports, site access reviews and Restricted Content Discovery for the most sensitive sites.
- Label sensitive content. Publish sensitivity labels with default and auto-labeling, and apply encryption to highly confidential labels so only authorized users can use that content.
- Use DLP for Microsoft 365 Copilot. In Microsoft Purview, create policies for the Microsoft 365 Copilot location to exclude content with highly confidential labels from Copilot processing, and — where available — to restrict responses to prompts containing specific sensitive information types.
- Strengthen email filtering. Messages quarantined before reaching mailboxes can't be retrieved as context. Review Defender for Office 365 policies.
- Govern agents and connectors. Each agent, plugin or connector adds data sources and possible actions. Review them in the Microsoft 365 admin center.
- Monitor AI interactions. Confirm Copilot interaction events are audited and review Purview DSPM for AI reports.
- Track AI advisories. Include Copilot and other AI service CVEs in vulnerability management — even when the fix is server-side — so you can assess exposure and document decisions.
- Apply the same thinking to your own AI apps. If you build agents with Azure AI Foundry, Amazon Bedrock or other platforms, treat retrieved content as untrusted, restrict tool permissions and require human approval for high-impact actions.
How to monitor for prompt-injection risk
Direct detection is difficult, but you can watch the conditions that make it dangerous:
- Copilot interactions referencing highly confidential content, visible through Purview audit and DSPM for AI.
- DLP alerts for the Copilot location.
- External emails with hidden or unusual formatting, such as large blocks of instructions addressed to an "assistant," flagged through mail flow inspection or custom detections.
- Unexpected external links in AI-generated output.
Common mistakes
- Treating Copilot as a productivity tool only, outside the security program.
- Relying on the vendor fix alone without reducing data exposure.
- Giving AI agents write or send permissions without human approval steps.
- Assuming prompt injection is a one-time bug. It's a category of risk that will recur.
Applying the lessons to your own AI applications
If you build AI applications or agents — on Azure AI Foundry, Amazon Bedrock or other platforms — EchoLeak is a useful design checklist. The OWASP Top 10 for LLM applications lists prompt injection as the leading risk, alongside sensitive information disclosure and excessive agency.
Design defensively: treat every retrieved document, email and web page as untrusted input; separate system instructions from user and retrieved content; restrict the tools and data each agent can access; filter or block outputs that include external links or encoded data where they aren't expected; require human approval before high-impact actions; and log prompts, retrieved sources and tool calls so you can investigate when something goes wrong. Platform guardrails such as Amazon Bedrock Guardrails and Azure AI Content Safety help, but they work best as one layer among several.
Questions for leadership
- What sensitive information can Copilot access in our organization today?
- Have we limited Copilot's access to highly confidential content with labels and DLP?
- Who tracks security advisories for the AI tools we use?
Key takeaways
- EchoLeak showed a crafted email could make Copilot leak data with zero user interaction.
- Microsoft fixed it server-side; no in-the-wild exploitation was reported.
- Prompt injection is a lasting risk class for any AI that reads untrusted content.
- Reduce what AI can reach — permissions, labels, DLP — and monitor AI interactions.
Sources
- How to Reduce Copilot Prompt-Injection Exposure With Labels and DLP How-To & Hardening
- Detecting Copilot Prompt Injection: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: Your AI Assistant Can Be Tricked Into Leaking Data CIO Briefings