Sev0AI security incidents, tracked

All incidents / Manipulated AI

EchoLeak: zero-click prompt injection could make Microsoft 365 Copilot leak data

Microsoft, disclosed Jun 2025. Manipulated AI Data exposed Low

Researchers showed that an email with hidden instructions could make Microsoft 365 Copilot pull data from a user's mail, files and chats and send it out, with no clicks from the victim. It was the first publicly documented zero-click attack on a production AI assistant. Microsoft fixed it server-side.

Disclosed
Jun 2025
Organization
Microsoft
Vendor
Microsoft
Product
Microsoft 365 Copilot
Type of AI
Work assistant
How it happened
Manipulated AI: Prompt injection
Harm
Data exposed
Data involved
Internal documents
Reach
No known access
Severity
Low
Model at fault
Yes
Status
Confirmed (research, no known victims)
Vulnerability IDs
CVE-2025-32711

Sources

  1. https://guardion.ai/ai-incidents/echoleak-m365-copilot-zero-click

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "EchoLeak: zero-click prompt injection could make Microsoft 365 Copilot leak data", https://sev0.fyi/incidents/2025-06-01-echoleak-m365-copilot/