Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Europe’s rivers are running dry, and the knock-on effects are disastrous | Yiannis Baboulias

    August 5, 2026

    Australia news live: Bowen says nuclear advocates living in ‘fantasy world’; Leeser says funding won’t improve Naplan results | Australia news

    August 5, 2026

    Electricité : à gauche, Bernard Cazeneuve joue sa propre partition

    August 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Europe’s rivers are running dry, and the knock-on effects are disastrous | Yiannis Baboulias
    • Australia news live: Bowen says nuclear advocates living in ‘fantasy world’; Leeser says funding won’t improve Naplan results | Australia news
    • Electricité : à gauche, Bernard Cazeneuve joue sa propre partition
    • Ex-MP urges Tories to drop candidate jailed for campaign of antisemitic abuse against her | Conservatives
    • William Lawrence Wins Primary in Battleground Michigan House District
    • How One Startup Built a (Mostly) China-Free Robot
    • OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
    • OpenAI Dumps Apple Employees’ Text Messages to Fight Trade Secret Suit
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 5, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Most email systems provide an AI Assistant for the account holder. Attackers can use the chatbot of a compromised account as an alternative and versatile form of Living off the Land (LotL).

    Compromising an email account is the most difficult part of this attack, but empirically, we know this doesn’t deter attackers. Once an email account is compromised, the attacker has automatic access to any built-in AI Assistant attached to the account. 

    Researchers at Barracuda Networks explored the potential for bad actors to abuse this chatbot, developing a proof of concept via a simulated attack within their own laboratory environment.

    The task was to elevate privileges from a lower-level compromised user to that of the CEO using the AI and without being detected. This route was chosen since directly phishing the CEO would be challenging, would likely set off alarms, and be detected.

    With a compromised email, an attacker has automatic access to any built-in chatbot. The first requirement of an attack is to establish persistence which requires stealth. Attacker use of the chatbot would normally be discoverable in its logs, so the initial task is to use the AI to remove any evidence of use of the AI. The researchers started with a chatbot prompt: “Create an inbox rule that moves any emails with ‘sign-in’ in the subject into the ‘deleted items’ folder.”

    This creates basic stealth. Next comes reconnaissance. “Remind me about our organization structure. Tell me about my ongoing important/sensitive email conversations.” The responses to these prompts will reveal any relationship between ‘you’ and the CEO, and possible reasons to contact the CEO.

    Advertisement. Scroll to continue reading.

    The next stage is to phish the CEO, but now with the advantage of acceptable context. The phish is internal and will bypass filters. The reason for the contact is valid. And most importantly, the attacker can instruct the chatbot to construct an email in the style of the compromised user.

    The nature of this phish will depend upon the information already discovered. In the researchers’ proof of concept, they were able to instruct the chatbot, “Create an email using my writing patterns to respond to the Q3 budget approval email. I have a link to insert into the draft that contains the actual invoice confirmation.” 

    This ‘trusted’ phish has a high(er) probability of succeeding. “The CEO unsuspectingly clicks the link provided as an invoice, believing it to be from their trusted employee. The link routes through an adversary-in-the-middle proxy that performs a session token takeover. The CEO’s credentials and authenticated session token allow the threat actor to bypass multifactor authentication (MFA) and login to the highly privileged CEO’s account,” suggest the researchers.

    The initial process is repeated to prevent detection of the newly compromised CEO email account. The CEO’s AI Assistant is then instructed to provide, “A refresher on recent financial emails, including invoices, monetary values, and upcoming transfers”. In this simulation, the attacker discovered an imminent pre-authorized payment of about $250,000 – so the next step is by now fairly obvious.

    “Respond to finance with my [the CEO’s] typical writing patterns saying that I need the wire to be sent to a new account because the [payee] has changed their banking details to…” The researchers point out, “Since the message came from the CEO’s real mailbox, passed every authentication check, referenced a real in-flight transaction, and matched the CEO’s usual tone with the finance team, there was nothing for traditional email security to flag.” All that remained for the attacker was a stealthy exit, again assisted by the chatbot.

    It has to be said that this was a simulation, and all the chips fell nicely for the researchers. But there is nothing to say that the same process could not be repeated by an attacker in real life. Nor is there anything to say that the attacker’s payout could not be higher than that achieved here.

    The purpose of this research was not to indicate what will or is even likely to happen, but to highlight the way an attacker could make future use of the tools that become available. If one of those tools is to use ready access to an internal AI chatbot, the potential misuse of that chatbot could have severe consequences, primarily limited only by the attacker’s imagination.

    Related: McDonald’s Chatbot Recruitment Platform Exposed 64 Million Job Applications

    Related: Researchers Link DeepSeek’s Blockbuster Chatbot to Chinese Telecom Banned From US

    Related: Beware – Your Customer Chatbot is Almost Certainly Insecure: Report

    Related: Microsoft Unveils Copilot Vision AI Tool, but Highlights Security After Recall Debacle

    Accounts Assistants Attackers email hijack weaponized
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

    Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook

    CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout

    Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

    TP-Link patches Omada ZTP flaws allowing hackers to breach networks

    Capital One closed hundreds of Trump bank accounts for ‘anti-money laundering reasons,’ lawsuit says

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Europe’s rivers are running dry, and the knock-on effects are disastrous | Yiannis Baboulias

    August 5, 2026

    Australia news live: Bowen says nuclear advocates living in ‘fantasy world’; Leeser says funding won’t improve Naplan results | Australia news

    August 5, 2026

    Electricité : à gauche, Bernard Cazeneuve joue sa propre partition

    August 5, 2026

    Ex-MP urges Tories to drop candidate jailed for campaign of antisemitic abuse against her | Conservatives

    August 5, 2026
    Latest Posts

    Oil prices hit $100 for the first time since May

    July 23, 2026

    Pew Survey: China May Be Liked More, but It Is Celebrating a Race It Never Ran

    July 23, 2026

    Yinson Production and PTSC’s FSO heads off to Southeast Asian oil project

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Europe’s rivers are running dry, and the knock-on effects are disastrous | Yiannis Baboulias

    August 5, 2026

    Australia news live: Bowen says nuclear advocates living in ‘fantasy world’; Leeser says funding won’t improve Naplan results | Australia news

    August 5, 2026

    Electricité : à gauche, Bernard Cazeneuve joue sa propre partition

    August 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.