The Register Home Page

back to article Sneaky Mermaid attack in Microsoft 365 Copilot steals data

Microsoft fixed a security hole in Microsoft 365 Copilot that allowed attackers to trick the AI assistant into stealing sensitive tenant data – like emails – via indirect prompt injection attacks. But the researcher who found and reported the bug to Redmond won't get a bug bounty payout, as Microsoft determined that M365 …

  1. elsergiovolador Silver badge

    Prompt

    Obviously Microsoft forgot to add to the prompt: "Be aware of scammers and don't let them easily trick you into handing over the data."

    1. Like a badger Silver badge

      Re: Prompt

      What, like the scammers at Microsoft who trick people into hand over bug reports, take and use the data and then go "Not paying you, hahahahahhahaaa! Looooser! Loooser!"

      1. RolandM

        Re: Prompt

        Smart people then sell the infos elsewhere ?

    2. Steve Davies 3 Silver badge

      You forgot to add

      "We, Microsoft are the ONLY ones allowed to slurp your data. It is in the small (1pt, white on white) print on page 1001 of your EULA which you agreed to."

  2. Richard 12 Silver badge
    Alert

    As Copilot is out of scope

    One assumes it's insecure by design, with more holes than a colander that's been snapped in half.

    1. Doctor Syntax Silver badge

      Re: As Copilot is out of scope

      They wouldn't be able to afford all the payouts.

    2. Pascal Monett Silver badge
      Holmes

      Re: As Copilot is out of scope

      Bugzilla doesn't trust it.

      What does that tell you ?

    3. Ropewash

      Re: As Copilot is out of scope

      The singularity as seen by Microsoft. So many holes that it is now only a hole, devouring all the surrounding data.

  3. Fuzzy Fitzpatrick
    Gimp

    Not a bug, a feature

    But the researcher who found and reported the bug to Redmond won't get a bug bounty payout, as Microsoft determined that M365 Copilot isn't in-scope for the vulnerability reward program. Or, it’s working just as intended and this isn’t a bug, just a pain in the arse Joe Public found the feature.

    1. matjaggard

      Re: Not a bug, a feature

      Either way the message is clear - it's better to exploit or sell the vulnerability than tell Microsoft.

    2. Brian Scott

      Re: Not a bug, a feature

      If Microsoft doesn't consider their AI worthy of a bug bounty, it can only mean they think it isn't finished yet and nobody in their right mind should trust it for anything beyond beta testing.

      They expect the product to have so many security holes that they'd just be handing over money to everybody that asks.

  4. Fruit and Nutcase Silver badge
    Big Brother

    Web Search

    The default settings of the Search feature in Windows is to search the web, via Bing if it can't find anything locally. All those proprietary terms are being eagerly harvested by Microsoft

    Icon: Big Brother Satya

  5. Anonymous Coward
    Anonymous Coward

    Graphic

    The graphic with the emetic tinting is a pretty evil looking bint https://regmedia.co.uk/2025/10/24/sneaky_mermaid.jpg and uncropped you can see the legs so not actually a mermaid. Reminds me of Jadis in '80s Narnia TV series.

    The image is the high point of the article as the rest is MS being MS. Same old, same old...

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon