Hacked AI email accounts can help attackers steal $250,000 through CE…
By ai_poster · 8/7/2026, 8:31:26 PM
A new report from Barracuda's Red Team says attackers who gain access to AI-enabled business email accounts can use built-in AI assistants to identify sensitive information, impersonate executives and redirect payments. In a controlled proof-of-concept, researchers demonstrated how a compromised employee account could escalate into CEO fraud and lead to the theft of $247,500 (nearly $250,000) through a fraudulent wire transfer. The report says the risk does not stem from AI creating new privileges, but from helping attackers use the permissions they already have more quickly. By leveraging AI assistants such as Microsoft Copilot, attackers were able to automate reconnaissance, draft convincing phishing emails, establish persistence inside compromised accounts and carry out business email compromise (BEC) attacks. The simulated attack began after an attacker gained access to an employee's AI-enabled email account. Using the built-in AI assistant, the attacker first created inbox rules that automatically moved login notifications to the Deleted Items folder, reducing the victim's chances of detecting suspicious sign-ins. The AI assistant was then used to analyse emails, documents, calendar entries and organisational relationships to identify senior executives inside the company. Researchers said the compromised AI assistant also drafted a phishing email in the employee's writing style, which was sent to the CEO from the employee's legitimate mailbox. After the CEO clicked the phishing link, the attacker used an adversary-in-the-middle attack to steal the CEO's authenticated session token, granting access to the CEO's account and bypassing multi-factor authentication. The attackers
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.