Microsoft Copilot security flaw may expose your private data, here is how to stay safe

HIGHLIGHTS

A flaw in Microsoft Copilot could have exposed emails, files, and other private Microsoft 365 data.

Microsoft has fixed the issue and said there is no sign that any users were affected.

Avoid unknown links, keep software updated, and limit data access to stay protected.

Microsoft Copilot security flaw may expose your private data, here is how to stay safe

Microsoft’s AI assistant Copilot was affected by a security issue that could have allowed attackers to access private information from Microsoft 365 accounts. The flaw, called SearchLeak, was discovered by cybersecurity researchers who warned that attackers could steal data with limited action from users. Copilot is used by many organisations to search files, summarise emails, and find information across Microsoft services. Microsoft has fixed the issue and said it found no evidence that customers were affected. Users should still stay careful, keep their accounts protected, and follow security practices to reduce the risk of data exposure.

Digit.in Survey
✅ Thank you for completing the survey!

Researcher Dolev Taler from Varonis Threat Labs discovered the issue and explained that SearchLeak involved multiple weaknesses in Copilot’s search feature. According to the researcher, an attacker could send a user a normal-looking link with hidden instructions. If the user opened the link, Copilot could misunderstand those instructions and treat them as a search request.

Researchers found that Copilot could then search information available to the user, including emails, meeting notes, documents, and files stored across Microsoft services. This data could then be encoded into an image link and then sent out of the system using the Bing search engine, making it difficult to detect data movement.

Also read: Apple iPhone 18 Pro and iPhone Ultra design leaked again: Check expected specs, launch timeline and price

This made emails, information about meetings, files on SharePoint, data on OneDrive, and any other business information associated with Copilot vulnerable. Given how widely Microsoft 365 is used to store sensitive company information, the potential impact was significant.

The good news is that no attacks exploiting this flaw have been reported yet. Microsoft fixed the bug upon notification from the researchers and classified it as an important security issue.

Also read: This new Samsung AI feature can spot signs of illness in your dog or cat

How to stay safe

It’s easy to stay safe from any such AI vulnerabilities. Here are some of the tips you can follow as an individual or an organisation to ensure that your data is safe:

  • Don’t click on links you weren’t expecting, even if they look real. Double-check who sent a link before opening it in an email or chat message. 
  • Make sure that your Microsoft 365 account, as well as all your working software, are updated.
  • Do not provide your employees access to information that is not required for their work.
  • Always monitor what your AI tool can access.

Bhaskar is a Senior Copy Editor at Digit India who keeps a close watch on everything shaping the world of technology from smartphones and home appliances to AI, government tech initiatives, digital safety, and the latest industry developments. Whether it's breaking news, in-depth features, hands-on reviews, practical how-to guides, or exclusive scoops, he translates complex tech into stories that are easy to understand and worth reading. His work has been featured in iGeeksBlog, GuidingTech, and other leading publications. Before joining Digit India, he served as an assistant editor at TechBloat. A B.Tech graduate and full-time tech journalist, he is driven by just one goal, which is to help readers stay informed, stay secure, and stay ahead in an ever-changing digital world. View Full Profile