The SearchLeak exploit allowed attackers to steal two-factor authentication codes from users via Microsoft Copilot. This vulnerability stems from how LLMs handle sensitive data within search contexts. It exposes a recurring failure in current AI security architectures. Developers must now implement stricter data masking to prevent similar prompt-injection style leaks in production tools.