A novel Microsoft Copilot attack that researchers dubbed "SearchLeak" would have enabled an attacker to silently exfiltrate user files, including emails, meeting notes, OneDrive files, SharePoint documents, and other business files the user has access to. Varonis Threat Labs today detailed the three-stage vulnerability, which works as a relatively unknown subset of indirect prompt-injection attacks called parameter-to-prompt injection (P2P), which needs to be on defender radar screens. The attack works like this: The threat actor sends the victim a Copilot link through any channel, such as email or Slack. The link itself opens Microsoft 365 Copilot Search, and it is structured so that whatever prompt is behind the "q" parameter, the search accepts (structured as " https://m365.cloud.microsoft/search/?auth=2&origindomain=microsoft365&q=<PROMPT>"). The attacker can use this link structure as an opening to craft a malicious prompt that the victim's Enterprise Copilot interprets and responds to. The attacker instructions tell the Copilot to perform a task like a search for a specific email received (such as a multifactor authentication code) and put requested information into a URL that sends the information to an attacker-controlled server. Varonis found that while guardrails would prevent certain versions of this attack, the attacker could put the attacker-controlled server link in an image tag that exists on the back of a Bing search-by-image link. An example prompt (per Varon...
Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
Dark Reading
·Alexander Culafi
·Published Jun 15, 2026
·Updated
Affected Software
2 affected components
Microsoft 365 Copilot Search
Microsoft Enterprise Copilot
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new attack targeting Microsoft Copilot's capabilities, known as the 'SearchLeak' attack.
2
What security implications are discussed in the article?
The article highlights the potential for silent data exfiltration of sensitive files such as emails and documents from Microsoft 365 Copilot.
3
What products or software are affected by the SearchLeak attack?
The affected products include Microsoft 365 Copilot Search and Microsoft Enterprise Copilot.
4
Who identified the SearchLeak attack and where can details be found?
Varonis Threat Labs identified the SearchLeak attack and provided detailed commentary on its implications.
5
When was the SearchLeak vulnerability first published?
The SearchLeak vulnerability was published on June 15, 2026.