Twitter/X

OrcaRouter (via @AIFrontliner, 2026-06-18) reports that attackers in 2025…

Brief

OrcaRouter (via @AIFrontliner, 2026-06-18) reports that attackers in 2025 exfiltrated corporate data from Microsoft 365 Copilot because an AI read and obeyed a malicious email without user interaction. They argue agents are now targets of social engineering and have published a free 'Firewall + Guardrails' on OrcaRouter.ai—one-switch, same API key/gateway, no code changes—backed by an AI Threat Report 2026.

Source evidence

POV: you gave your agent MCP access "just for testing" and it's now in a committed relationship with an attacker's server

OrcaRouter 🐳 (@OrcaRouter)

In 2025, attackers stole corporate data from Microsoft 365 Copilot.

The victim clicked nothing. They got an email. The AI read it. The AI obeyed it.

In the past, humans got socially engineered. In 2026, agents are getting socially engineered.

So we built Firewall + Guardrails to protect agents — and made them FREE on OrcaRouter.ai. Same API key, same gateway, one switch in your console. No code to change.

The AI Threat Report 2026 from our security research team explains why. 🧵🐋

— https://nitter.net/OrcaRouter/status/2067615849075343783#m