HomeSecurityOne click is enough: 'Reprompt' turns Microsoft Copilot into an export tool...

One click is enough: 'Reprompt' turns Microsoft Copilot into a data extraction tool

AI assistants are incredibly smart and helpful — but they can also be naive, gullible, and sometimes stupid. A new one-click attack discovered by researchers at Varonis Threat Labs highlights this fact. ‘Reprompt’, as they’ve dubbed it, is a three-step attack chain that completely bypasses security checks after an initial LLM prompt, giving attackers invisible, undetectable, unrestricted access. Microsoft has already released a patch after being made aware of the flaw.

See also: UK police accuse Copilot of misreporting information

Reprompt
'Reprompt' turns Microsoft Copilot into a data extraction tool

Reprompt uses three techniques to create a data extraction chain: Initial parameter to prompt (P2P injection), double request, and chained request. P2P embeds a prompt directly into a URL, taking advantage of the functionality of Copilot's default 'q' parameter, which is intended to simplify and improve the user experience.

The URL may include specific questions or instructions that automatically fill in the input field when the pages load. By exploiting this loophole, attackers then use the double request, which allows them to bypass protective measures.

Copilot only checks for malicious content in the Q variable for the first prompt, not for subsequent requests. For example, the researchers asked Copilot to retrieve a URL that contained the secret phrase “HELLOWORLD1234!“, repeating the request twice. Copilot stripped the secret phrase from the first URL, but the second attempt “worked flawlessly,”.

See also: Hackers exploit Copilot Studio's new Connected Agents feature

One click is enough: 'Reprompt' turns Microsoft Copilot into a data extraction tool

From here, attackers can initiate a chained request, in which the attacker’s server issues subsequent instructions to form an ongoing conversation. This tricks Copilot into extracting conversation histories and sensitive data. Threat actors can provide a series of prompts such as “Summarize all the files the user accessed today,” “Where does the user live?” or “What vacations are planned?” This method “makes data theft silent and scalable,” and there is no limit to what or how much the attackers can extract.

“Copilot leaks data bit by bit, allowing the threat to use each response to create the next malicious instruction.” The risk is that the reprompt does not require plugins, enabled links, or user interaction with Copilot beyond the initial click on a legitimate Microsoft Copilot link in a phishing message.

The attacker can remain in Copilot as long as they want, even after the user closes the conversation. All commands are delivered through the server after the initial prompt, so it is almost impossible to determine what is being output just by inspecting that prompt.

See also: LG installed Copilot on its TVs, but you can delete it

One click is enough: 'Reprompt' turns Microsoft Copilot into a data extraction tool

Be cautious of links, be on the lookout for unusual behavior, and always pause to check pre-filled prompts. This attack, like many others, starts with a phishing email or text message, so all the usual anti-phishing best practices apply, including 'don't click on suspicious links.'.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS