Your Agents Can Get Phished Too: The New Microsoft 365 Attack Surface
Details
Session Description:
Microsoft 365 Copilot and AI agents are beginning to read the same email, documents, Teams messages, and other content that employees rely on every day. That creates a new security problem: an attacker may not need to convince a person to click a link if they can influence the information an AI system later retrieves and trusts.
The challenge for security teams is that the current choices are often unsatisfying. You can allow agents to consume broadly and accept the risk, block large classes of external or untrusted content and limit their usefulness, or push the burden back onto users by asking them to manually verify what an agent tells them. None of those approaches scales particularly well. In this session, we’ll walk through controlled examples of how malicious or misleading external content can enter the Microsoft 365 environment and later become context for Copilot. We’ll look at cases such as vendor impersonation, false business assertions, and agent-directed instructions, and examine why traditional email authentication and phishing controls do not always answer the more important question: should the AI trust what it is reading?
About the Speaker:
Armaan Chakrabarti is the Co-Founder and CEO of Cambrient AI, a cybersecurity company building AI-native communication security. His current work focuses on the emerging security challenges created when Microsoft 365 Copilot and other enterprise AI systems consume untrusted communications as context, as well as post-quantum cryptographic encryption for government and government-contractor organizations.
