5 min read By Excello Mail Team

One Compromised Inbox Plus Microsoft Copilot Equaled a $247,500 Wire Fraud. DMARC Was Never in the Room.

Barracuda's Red Team disclosed a Black Hat USA 2026 proof-of-concept showing how a single compromised Microsoft 365 mailbox, paired with the account's own Copilot license, can escalate to full CEO impersonation and a redirected wire transfer in minutes. Every message the assistant sent was fully SPF, DKIM, and DMARC authenticated, because the account itself was real.

Barracuda’s Red Team published research on August 4, 2026, ahead of Black Hat USA 2026, that should reframe how security teams think about the AI assistants now built into every major mailbox. Their controlled proof-of-concept started with a single already-compromised Microsoft 365 account, the kind of foothold attackers get every day through ordinary credential theft. What came next did not require malware, a second phishing email, or any exploit at all. It required prompting the account’s own Microsoft Copilot license. Within minutes, the researchers had impersonated the company’s CEO and redirected a real wire transfer worth $247,500.

Nothing about this attack touches DMARC’s job. The mailbox was real. The domain was real. Every message Copilot drafted and sent left from infrastructure that had already cleared SPF, DKIM, and DMARC long before the human owner lost control of it.

The AI Assistant as an Instant Insider

The Barracuda researchers described a three-step escalation. First, the attacker prompted Copilot to create an inbox rule moving any message with “sign-in” in the subject line straight to Deleted Items, a single instruction that quietly suppressed the account-recovery alerts that would otherwise have tipped off the real owner. Second, the attacker asked Copilot to mine the mailbox, calendar, and message history for organizational structure: who approved payments, who reported to whom, which threads discussed budgets and invoices. Third, the attacker prompted Copilot to draft a reply to a live Q3 budget approval thread, written in the compromised employee’s own established voice, with a link framed as an invoice confirmation. The victim on the other end was dealing with a colleague they already trusted, in a conversation that was already underway, phrased exactly the way that colleague always phrased things. The wire transfer followed.

What used to take an attacker hours of manual reconnaissance and careful mimicry, reading through months of email, learning a target’s phrasing, mapping the org chart by hand, took Copilot minutes, because that is precisely the job an AI assistant is built to do well.

Why Authentication Was Never Part of the Equation

DMARC exists to answer one question: did the domain claimed in the From header authorize the infrastructure that sent this message. In Barracuda’s scenario, that question has an easy, correct, and completely unhelpful answer. Yes. The domain authorized the infrastructure, because the infrastructure was Microsoft’s own Exchange Online service sending on behalf of an account that genuinely belonged to that domain. There was no lookalike domain, no external relay, no spoofed header for any authentication layer to catch. This is the same “genuinely compromised mailbox” failure mode that has shown up repeatedly this year, but with a new accelerant: the mailbox’s own AI assistant doing the attacker’s targeting and writing for them, at a speed no human red team operator could match.

Not a Copilot Bug. A Feature, Used Exactly as Designed.

Barracuda was careful to note that nothing in this chain exploited a flaw in Copilot. Inbox rule creation, conversation search, and writing-style-matched drafting are ordinary features, present because they make legitimate employees faster at their jobs. The problem is that those same features inherit the full access and trust level of whatever account invokes them, with no concept of whether the hands on the keyboard belong to the account’s owner or to someone who stole their session. Barracuda’s own conclusion was blunt: this technique is not unique to Copilot, and the same escalation path is available through any enterprise AI assistant wired into a compromised mailbox.

What This Means for Your Program

Treat AI assistant access as inheriting full account privilege, because it does. A Copilot, Gemini, or similar assistant tied to a mailbox can read everything that mailbox can read and draft anything that mailbox can send. Review what those integrations can act on, not just what they can see.

Monitor for inbox rule abuse as a specific, high-value signal. Rules that silently hide messages containing “sign-in,” “security alert,” or similar keywords are a known evasion pattern. Alert on new hidden-folder or auto-delete rules touching those terms, and treat them as a compromise indicator worth immediate review.

Prioritize phishing-resistant authentication for the accounts that matter most. This attack’s root enabler was not the AI assistant. It was the initial account compromise. FIDO2 security keys and platform passkeys close the door this entire chain walked through.

Keep DMARC enforced regardless. This incident does not weaken the case for DMARC at reject. It demonstrates a separate risk category entirely, one that lives inside an account your domain already, correctly, trusts.

Add AI assistant activity to your detection surface. Session-level monitoring that only watches for suspicious logins will miss this attack completely, because the login already succeeded before the AI assistant was ever prompted. Unusual assistant queries against financial threads or executive conversations deserve the same scrutiny as unusual login geography.

The Takeaway

Attackers no longer need to write a convincing phishing email themselves. Once they hold a live, compromised account, they can ask that account’s own AI assistant to find the right target, learn the right voice, and draft the right message, all in minutes, and every downstream message it sends is fully DMARC compliant, because it genuinely comes from the domain it claims to. Authentication was built to verify that a message came from where it says it came from. It was never built to ask whether the person operating that account, human or AI-assisted, is the one the domain owner intended.


Excello Mail gives you continuous visibility into your DMARC enforcement and every source authorized to send under your domain, so account compromise stands out fast instead of blending into normal traffic. Sign up for free to Excello Mail and keep your authentication posture airtight while your team builds defenses for what happens after a real account gets taken over.