A single compromised email account, paired with an AI assistant, can be escalated into chief executive impersonation and a $250,000 wire transfer scam. A controlled attack by Barracuda's red team has shown how.
The proof-of-concept demonstrates how attackers can turn an AI assistant embedded in a business inbox into what Barracuda calls an "unwitting malicious insider". The test used Microsoft Copilot, but Barracuda says the technique applies equally to other widely available AI assistants.
The exercise matters because it uses legitimate access and existing business processes rather than malware. That gives traditional email security controls little reason to flag the activity. The attack succeeds using access the victim already holds.
How the attack unfolds
Working from a compromised employee account, the attackers first ask the AI assistant to establish persistence. It creates inbox rules that hide sign-in alerts and other suspicious notifications from the user.
They then use the assistant to map the organisation, identify high-value targets and surface conversations buried in months of emails, attachments and calendar activity. Armed with that context, they prompt the assistant to draft a convincing phishing message to the chief executive in the employee's own writing style.
Once the executive's account is compromised through a session-token theft attack, the attackers repeat the process. A simple prompt asking for recent financial activity surfaces active invoices, wire transfers and approval workflows, including a pending payment of $247,500.
The attackers then use the executive's mailbox and the assistant to draft a request to finance staff. It asks them to change the destination bank account before the transfer is approved. Because the message comes from a real mailbox, references a genuine transaction and matches the executive's style, it is unlikely to be flagged. Forwarding rules intercept confirmation messages, and the assistant is used to locate and remove evidence of the fraud.
Why it matters
Barracuda says the greatest risk from a compromised AI-enabled account is speed. An assistant can help attackers quickly uncover sensitive information, identify targets and craft communications.
"A user's email history is full of sensitive information and context that can be leveraged by attackers, including emails sent and received, documents shared, attachments, and calendar invites," said Daniel Avulov, senior cybersecurity researcher on Barracuda's red team. "The controlled attack shows how AI assistants can become unwitting malicious insiders and improve both the quality and speed of an attack."
Avulov said the most effective defence is to recognise that attack patterns remain the same. Defenders should use existing telemetry and keep mean time to detect as low as possible.
Barracuda argues that as AI assistants become embedded in business workflows, organisations should treat AI-enabled accounts as high-value assets. Protecting identities, monitoring for account compromise and securing AI-assisted access to corporate information will become a central part of email and identity security strategies.