Security researchers have revealed a vulnerability chain dubbed SearchLeak that could have enabled attackers to extract sensitive enterprise information from Microsoft 365 Copilot with just a single user click.
The flaw reportedly exposed data ranging from emails and meeting notes to SharePoint documents and OneDrive files, all without requiring additional permissions, malware installation, or follow-up actions from the victim.
The issue has since been addressed by Microsoft through server-side mitigations, and researchers say there is no evidence that the vulnerability was exploited in the wild before being patched.
A trusted link becomes a security threat
Unlike conventional phishing attacks that rely on suspicious websites, SearchLeak leveraged a legitimate Microsoft-hosted URL. Because the link originated from a trusted domain, it was more likely to bypass security filters and appear safe to users.
Researchers demonstrated that a victim only needed to click the specially crafted link once. From there, Microsoft 365 Copilot Enterprise Search could be manipulated into retrieving information already accessible under the victim’s account and transmitting it outside the organisation.
The attack reportedly targeted data stored across Microsoft’s productivity ecosystem, including Outlook, SharePoint, OneDrive, calendars, and meeting records.
Exploiting the AI layer
What makes SearchLeak significant is that it did not attack a traditional application directly. Instead, it targeted the AI layer connecting users to corporate information.
Microsoft 365 Copilot is designed to search across multiple business data sources and provide users with relevant information through natural language interactions.
Researchers found a way to abuse this functionality by injecting instructions that Copilot interpreted as legitimate requests. In effect, the AI assistant became an unwilling participant in the attack.
This approach reflects a growing category of cybersecurity threats where attackers manipulate AI systems rather than compromise operating systems or endpoints.
Researchers describe SearchLeak as a chain of multiple weaknesses working together.
While each vulnerability on its own posed limited risk, combining them created a powerful attack path capable of bypassing traditional security assumptions.
Why security teams are paying attention
Enterprise AI assistants are increasingly becoming central hubs for organisational knowledge.
Unlike individual applications, they often have visibility into emails, documents, chats, calendars, and collaboration platforms simultaneously. As a result, compromising the AI layer can potentially provide access to a much broader range of information than compromising a single application.
Security experts have repeatedly warned that prompt injection attacks, retrieval abuse, and AI trust-boundary failures could emerge as some of the most serious challenges facing organisations adopting generative AI technologies. SearchLeak provides a practical example of how those concerns can translate into real-world security risks.
The disclosure follows a series of AI-related security findings over the past year, suggesting that attackers and researchers alike are increasingly focused on enterprise AI systems.
While Microsoft’s fix appears to have eliminated the immediate threat, the incident reinforces an important lesson for organisations: AI assistants should be treated as critical infrastructure rather than simple productivity tools.
As businesses continue integrating AI into daily workflows, security teams may need to rethink traditional defences and develop protections specifically designed for AI-driven environments.
The SearchLeak discovery serves as a reminder that in the age of enterprise AI, a single click can have consequences far beyond opening a malicious webpage.