Microsoft Copilot Vulnerability Exposed Sensitive Data

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Microsoft's Copilot faced vulnerabilities allowing attackers to steal sensitive data through prompt injection and ASCII smuggling. Researchers, including Johann Rehberger, identified these flaws, which could lead to privacy violations. Microsoft has since patched these issues, but details of the fix remain undisclosed, raising concerns about data protection.[AI generated]

Why's our monitor labelling this an incident or hazard?

The report describes a realized data‐exfiltration attack against Microsoft Copilot—an AI system—using novel ASCII smuggling and prompt‐injection techniques to steal user data. Because the AI system’s exploitation directly led to unauthorized data theft, it constitutes an AI Incident.[AI generated]
AI principles
Privacy & data governanceRobustness & digital securityTransparency & explainabilityAccountabilityRespect of human rights

Industries
Digital securityIT infrastructure and hostingConsumer services

Affected stakeholders
ConsumersBusiness

Harm types
Human or fundamental rightsReputationalEconomic/Property

Business function:
ICT management and information security

AI system task:
Interaction support/chatbotsContent generationReasoning with knowledge structures/planning


Articles about this incident or hazard