Twitter/X

In 2025 attackers exfiltrated corporate data from Microsoft 365 Copilot without…

Brief

OrcaRouter warns that the 2026 threat model is a 'haunted PDF' scenario where attackers in 2025 stole corporate data from Microsoft 365 Copilot by sending an email the AI read and obeyed. They argue agents, not just humans, are being socially engineered and announce free 'Firewall + Guardrails' protections on OrcaRouter.ai (same API key/gateway, one-switch enablement) with an AI Threat Report 2026 explaining the risks.

Why it matters

In 2025 attackers exfiltrated corporate data from Microsoft 365 Copilot without the victim clicking anything — an email was read and obeyed by the AI.

Key details

  • OrcaRouter says 2026 threat model shifts from human social engineering to agent social engineering, where AIs themselves are manipulated.
  • OrcaRouter released free 'Firewall + Guardrails' on OrcaRouter.ai that work with the same API key and gateway, enabled by one console switch with no code changes; details in their AI Threat Report 2026.
Source evidence

2026 threat model: a haunted PDF

OrcaRouter 🐳 (@OrcaRouter)

In 2025, attackers stole corporate data from Microsoft 365 Copilot.

The victim clicked nothing. They got an email. The AI read it. The AI obeyed it.

In the past, humans got socially engineered. In 2026, agents are getting socially engineered.

So we built Firewall + Guardrails to protect agents — and made them FREE on OrcaRouter.ai. Same API key, same gateway, one switch in your console. No code to change.

The AI Threat Report 2026 from our security research team explains why. 🧵🐋

— https://nitter.net/OrcaRouter/status/2067615849075343783#m