Practical guides to protect yourself, your family, and your business from AI-driven scams, deepfakes, and emerging cyber threats.
Barracuda's red team started where most real intrusions start: with access to one unremarkable employee mailbox. Not an executive, not an administrator. A few conversational prompts later they held the chief executive's authenticated session, a list of every payment awaiting approval, and a wire transfer of $247,500 rerouted to an account they controlled.
Not one step in that chain required a new exploit, or a privilege the attacker had not already stolen. What the AI assistant added was speed, and a kind of institutional knowledge that used to cost an intruder days of patient reading. That is the shift worth understanding, because it changes which part of the attack your defenses can realistically catch.
The proof of concept was published on 4 August 2026 by the Barracuda Red Team as part of the company's Black Hat USA 2026 research, and reported two days later by eSecurity Planet. It ran on Microsoft Copilot, the assistant built into Microsoft 365, though Barracuda notes the same steps apply to the chatbots now embedded in most major mail clients. The scenario was a business email compromise, or BEC: fraud that redirects a legitimate payment by impersonating somebody inside the company.
The sequence is worth following closely. Holding the employee's account, the attacker first asked Copilot to create an inbox rule sending sign-in notifications straight to Deleted Items, so the victim never saw the alerts that would have exposed the intrusion. Inbox rules sit buried in settings and are rarely reviewed, and the assistant removed any need to know where they live. Reconnaissance came next. One prompt turned months of accumulated email into a summary of the org chart, the live threads, and the people worth pivoting to. The attacker picked the CEO, then had Copilot draft a message to them in the employee's own writing style, referencing a conversation already in progress. The CEO opened the invoice link. It routed through an adversary-in-the-middle proxy, a relay that sits between the victim and the real login page and captures the authenticated session token, which is the credential your browser holds after you have already cleared multi-factor authentication (MFA, the second login step such as a code or an app prompt). Stealing that token put the attacker inside the CEO's mailbox without ever having to defeat MFA head on.
BEC is not an emerging threat. It is the second most costly category of internet crime the FBI tracks, responsible for just over $3 billion in verified losses across 24,768 complaints in 2025, an average above $122,000 per victim, according to the bureau's 2025 Internet Crime Report. What Barracuda demonstrated is that the two things which used to slow these attacks down, learning the organization and writing convincingly as a specific person, have collapsed into prompts. Consider what that means for your own finance function. The fraudulent request came from the chief executive's genuine mailbox, passed every authentication check, referenced a payment that really existed, and read exactly like the CEO. Every signal an email gateway inspects was legitimate, which is precisely why nothing flagged it. The staff in this scenario were not careless. They were correct on every check they had been trained to run. The systemic point underneath is that once an account is taken over, the AI assistant behaves like a knowledgeable insider working for the intruder. It grants no new privileges, as Barracuda is careful to state. It applies the stolen ones faster and more competently than the attacker could alone, which pushes your detection surface away from message content and toward account behavior: rule creation, session anomalies, and assistant queries that look nothing like how the human uses their own inbox.
Nobody lost money here. Barracuda ran the attack in a controlled environment and published the prompts and screenshots so defenders could see the shape of it. Bring that shape to your next security meeting, because the lesson is simple and uncomfortable. Your organization is rolling out AI assistants so employees can read their own mail faster, find the right document, and draft in their own voice. The controls you decided were good enough for one compromised account were designed for an intruder who had to do all of that by hand.


