Hackers Exploit Copilot AI in SharePoint to Steal Passwords and Sensitive Data

Hackers Exploit Copilot AI in SharePoint to Steal Passwords and Sensitive Data

AI Assistants in SharePoint Open New Doors for Data Breaches

Emerging flaws in Microsoft’s Copilot AI integration within SharePoint are exposing critical security blind spots, allowing unauthorized actors to retrieve highly sensitive assets such as internal credentials, API tokens, and private files.

As enterprises accelerate their use of AI-driven tools to streamline workflows, they may be inadvertently widening their attack surface. These tools, intended to enhance productivity, are now becoming attractive vectors for exploitation.

Cybersecurity researchers at Pen Test Partners have identified that SharePoint’s built-in AI agents—referred to as SharePoint Agents—can be manipulated to bypass conventional security detection. Once compromised, these agents can quietly extract sensitive business data without triggering alerts.

Behind the Breach: Intelligent Agents with Dual Entry Points

These SharePoint Agents fall into two categories: Microsoft’s Default Agents, embedded out of the box, and Custom Agents, built by organizations for tailored use. Both types, if improperly secured, can be exploited through advanced techniques that abuse the AI’s underlying access privileges.

Copilot AI in SharePoint Becomes a Gateway to Hidden Corporate Secrets

SharePoint remains a prime target for cyber adversaries—not because of any inherent flaw, but because it’s become a digital vault for an organization’s most sensitive data. Security analysts consistently encounter high-risk content during red team operations, ranging from password-laden spreadsheets to full email archives and unencrypted private keys—all quietly stored in SharePoint libraries.

A particularly troubling vulnerability highlights how Microsoft’s Copilot AI can be manipulated to override access restrictions. Despite protections like “Restricted View” — intended to block users from downloading certain documents — researchers found a simple prompt to Copilot could extract forbidden content.

In one test, the AI agent was asked to locate a file labeled “Passwords.txt,” which was otherwise hidden behind security controls. Without hesitation, the agent displayed the entire contents, including login credentials that granted access to an encrypted file.

Silent Access: How AI Agents in SharePoint Are Being Turned into Insider Threat Tools

A newly uncovered exploit, informally named “HackerBot,” illustrates how Microsoft Copilot can be subverted to access highly restricted SharePoint content—without requiring authentication. Despite Microsoft’s official guidance indicating such behavior should be impossible, researchers found multiple paths that sidestep these controls with alarming ease.

In one case, security firm Knostic revealed a time-based permission gap: if a user’s access to a file is revoked, Copilot may still retrieve it due to lag in its sync process. That delay creates a fleeting—but critical—window where confidential data remains vulnerable, even after it should be locked down.

Invisible Intrusions, No Audit Trail

The true danger lies not just in what Copilot can access, but in how quietly it operates. Unlike typical file access through SharePoint, actions performed by Copilot don’t generate traceable activity in user logs. This leaves security teams blind to data being pulled out of restricted zones. No “recent file” flags. No “accessed by” records. Just silence.

Deceptively Simple Prompts, Surprisingly Effective Results

Researchers also demonstrated that Copilot’s safeguards can be manipulated using social engineering tactics. One example involved posing as a security team member and prompting the AI to search for files containing sensitive data. The agent complied—combing through content and returning filenames without any authentication verification.

What Can Be Done? Immediate Defenses for Enterprise AI

To reduce the risk of exploitation, experts strongly recommend the following steps for organizations deploying Copilot in SharePoint environments:

  • Enforce strict content governance: Ensure that sensitive materials are never uploaded to SharePoint unless properly encrypted and access-controlled.
  • Limit AI agent creation: Require formal approval workflows for new or custom agents.
  • Enhance visibility: Tune monitoring tools to track AI interactions and access behaviors—not just traditional file logs.
  • Segment sensitive sites: Consider disabling Copilot entirely on SharePoint locations housing regulated or classified data.

While Microsoft has issued fixes for some of the reported issues, researchers caution that this is only the beginning. As AI becomes more deeply embedded across enterprise systems, its potential as both a productivity tool and an attack vector will only grow.

Enterprises must rethink their assumptions: AI doesn’t just assist users—it can be weaponized by them too.

More Articles & Posts