Threat · curated 7 Sep 2026
This Word Document Steals Your Password From Microsoft Copilot (+ LIVE DEMO)
First reported youtube.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Microsoft Copilot's cross-surface memory poisoning and zero-click exfiltration path shows how a single crafted document can turn a company-deployed AI assistant into a persistent, silent data-theft channel with no logging or auditing.
Researcher Johann Rehberger (wunderwuzzi) demonstrated an exploit chain that steals data, including passwords, from Microsoft 365 Copilot using only a Word document that the victim summarizes — no link, macro, or download required. The attack uses an indirect prompt injection, bypasses Microsoft's image-based exfiltration block via remote font loading in a CSS stylesheet, and poisons Copilot's persistent memory so it triggers across Word, Excel, Outlook, SharePoint, and the desktop app in every future conversation.