AI assistants are incredibly smart and helpful — but they can also be naive, gullible, and sometimes stupid. A new one-click attack discovered by researchers at Varonis Threat Labs highlights this fact. ‘Reprompt’, as they’ve dubbed it, is a three-step attack chain that completely bypasses security checks after an initial LLM prompt, giving attackers invisible, undetectable, unrestricted access. Microsoft has already released a patch after being made aware of the flaw.
See also: UK police accuse Copilot of misreporting information

Reprompt uses three techniques to create a data extraction chain: Initial parameter to prompt (P2P injection), double request, and chained request. P2P embeds a prompt directly into a URL, taking advantage of the functionality of Copilot's default 'q' parameter, which is intended to simplify and improve the user experience.
The URL may include specific questions or instructions that automatically fill in the input field when the pages load. By exploiting this loophole, attackers then use the double request, which allows them to bypass protective measures.
Copilot only checks for malicious content in the Q variable for the first prompt, not for subsequent requests. For example, the researchers asked Copilot to retrieve a URL that contained the secret phrase “HELLOWORLD1234!“, repeating the request twice. Copilot stripped the secret phrase from the first URL, but the second attempt “worked flawlessly,”.
See also: Hackers exploit Copilot Studio's new Connected Agents feature

From here, attackers can initiate a chained request, in which the attacker’s server issues subsequent instructions to form an ongoing conversation. This tricks Copilot into extracting conversation histories and sensitive data. Threat actors can provide a series of prompts such as “Summarize all the files the user accessed today,” “Where does the user live?” or “What vacations are planned?” This method “makes data theft silent and scalable,” and there is no limit to what or how much the attackers can extract.
“Copilot leaks data bit by bit, allowing the threat to use each response to create the next malicious instruction.” The risk is that the reprompt does not require plugins, enabled links, or user interaction with Copilot beyond the initial click on a legitimate Microsoft Copilot link in a phishing message.
The attacker can remain in Copilot as long as they want, even after the user closes the conversation. All commands are delivered through the server after the initial prompt, so it is almost impossible to determine what is being output just by inspecting that prompt.
See also: LG installed Copilot on its TVs, but you can delete it

Be cautious of links, be on the lookout for unusual behavior, and always pause to check pre-filled prompts. This attack, like many others, starts with a phishing email or text message, so all the usual anti-phishing best practices apply, including 'don't click on suspicious links.'.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
