Researchers at Varonis forced Microsoft 365 Copilot to exfiltrate user passwords via a simple link click. The team discovered the vulnerability by asking the AI itself for the exploit method. This bypasses required user consent for sensitive data access. Enterprise admins must now audit prompt permissions to prevent similar unauthorized data exfiltration.