Zero-click email attack pulled data out of Microsoft 365 Copilot
A single email was enough to make Copilot hand over tenant data, researchers found. Microsoft fixed it before anyone had to act.
12 Jun 2025
Researchers at Aim Security found that a crafted email could make Microsoft 365 Copilot exfiltrate data from a user's tenant with no clicks, tracked as CVE-2025-32711.
Occurred 15 January 2025 · Disclosed 11 June 2025 · Record updated 13 September 2026
Sensitive data reachable by Copilot (emails, files, chats) could be exfiltrated by any external sender. Microsoft patched server-side before disclosure; no customer action was required.
A single email was enough to make Copilot hand over tenant data, researchers found. Microsoft fixed it before anyone had to act.
12 Jun 2025