Twitter/X

In 2025 attackers exfiltrated corporate data from Microsoft 365 Copilot by…

Brief

OrcaRouter warns that a 2025 breach of Microsoft 365 Copilot occurred when an AI read and obeyed a malicious email without any user click, illustrating a 2026 trend of agents being socially engineered. To counter this, OrcaRouter offers free Firewall + Guardrails that integrate with existing API keys/gateways via one console switch; their AI Threat Report 2026 provides details.

Why it matters

In 2025 attackers exfiltrated corporate data from Microsoft 365 Copilot by sending an email the victim didn’t click; the AI read and obeyed the email, enabling the breach.

Key details

  • OrcaRouter warns that by 2026 automated agents — not just humans — are being socially engineered, shifting the threat model to agent-targeted attacks.
  • OrcaRouter released free Firewall + Guardrails on OrcaRouter.ai that plug into the same API key and gateway, enabled by a single console switch with no code changes; their AI Threat Report 2026 explains the rationale.
Source evidence

In 2025, attackers stole corporate data from Microsoft 365 Copilot.

The victim clicked nothing. They got an email. The AI read it. The AI obeyed it.

In the past, humans got socially engineered. In 2026, agents are getting socially engineered.

So we built Firewall + Guardrails to protect agents — and made them FREE on OrcaRouter.ai. Same API key, same gateway, one switch in your console. No code to change.

The AI Threat Report 2026 from our security research team explains why. 🧵🐋