AI Assistants Are Making Business Email Compromise Faster, Not Louder
Primary Guard Newsroom · August 12, 2026 · 5 min read
New research shows an AI assistant can compress days of attacker reconnaissance into seconds. Primary Guard explains what changes, and what does not.
Research published on 4 August 2026 by Barracuda demonstrates something Primary Guard has been expecting for a while. Once an attacker is inside a mailbox, an AI assistant does not open a new door. It simply makes the attacker very much faster at walking through the ones already open.
The demonstration ends with a fraudulent wire transfer of $247,500. The number is the least interesting part.
What the researchers actually did
The scenario begins after a routine account compromise, with an ordinary employee's Microsoft 365 mailbox already in the attacker's hands. No privilege escalation, no new exploit, nothing exotic. From that starting point, every subsequent step used Copilot rather than the scripting and remote access tooling attackers have traditionally relied on.
First, persistence. A single instruction to Copilot created an inbox rule quietly moving sign-in notifications into Deleted Items, removing the alerts that usually give an account takeover away.
Then reconnaissance. Rather than the bulk searching and mass downloading that security tooling is specifically built to detect, Copilot was simply asked questions. It mapped the organisation's reporting lines, identified who mattered, and surfaced a genuine pending transaction awaiting approval. Work that once meant hours of careful manual reading took seconds and produced no unusual data access pattern.
Next, the fraud itself. Copilot drafted a bank account change request in the CEO's authentic writing style, referencing the real transaction by name and amount. Because the message came from the genuine mailbox and passed every authentication check, the finance team had no reason to doubt it. The payment was redirected.
Finally, cover. A forwarding rule intercepted the finance team's replies to an external address so the CEO never saw the follow-up questions, and Copilot was used to locate and delete the messages that would have exposed the scheme.
Why this is different from ordinary BEC
Business email compromise is not new, and Malaysian and Indonesian organisations have been losing money to it for years. What changes here is timing.
The traditional protection against BEC was never really technical. It was that a convincing impersonation took work. An attacker had to read enough correspondence to learn how the CEO writes, understand who approves what, and find a transaction plausible enough to hijack. That took days, and days gave defenders a window in which unusual searching, unusual downloads, or an unusual login might be noticed.
That window is what has collapsed. The reconnaissance now looks like an employee asking their assistant a normal question, because that is precisely what it is.
What this is not
Primary Guard thinks the framing here matters, because a good deal of the coverage has got it wrong.
This is not a Copilot vulnerability. The researchers exploited no flaw and Copilot was granted no permission it did not already have. Everything demonstrated was available to whoever controlled that user account, which is exactly how the product is designed to work. Reporting it as a Microsoft security hole misdirects attention towards a patch that is never going to arrive.
It is also not specific to Copilot. Barracuda notes the same technique applies to any AI assistant with comparable reach into mail and documents. Organisations running other assistants should not read this as somebody else's problem.
And it is a proof of concept, not a reported theft. No organisation lost $247,500 here. The figure illustrates a plausible outcome rather than a confirmed incident.
The honest conclusion is narrower than the headlines, and more uncomfortable. The AI assistant is not the vulnerability. The compromised account is the vulnerability, exactly as it always was. The assistant simply removes the delay that used to give you a chance.
What to do about it
Three controls address this directly, and none of them require new technology for most organisations.
Stop the account takeover. Everything above depends on the attacker already holding valid credentials. Phishing-resistant multi-factor authentication and conditional access remain the highest-value control available, and our guidance on Zero Trust identity and device management covers how to get there. Related, our guide to phishing in Malaysia addresses the delivery route most of these compromises still take.
Watch for the rules. Mailbox rule creation is the single most reliable signal in this entire chain. A rule that moves sign-in notifications to Deleted Items, or forwards internal correspondence to an external address, has almost no legitimate explanation. These events are logged in Microsoft 365 and can be alerted on today. Most organisations simply are not looking, which is one of the functions a managed security operations centre performs continuously.
Verify payment changes out of band. No email should ever be sufficient authority to change bank details, regardless of who appears to have sent it or how convincingly it is written. A phone call to a previously known number, not one supplied in the message, defeats this entire attack chain at the final step. It is the cheapest control described here and the one most often skipped.
The regulatory dimension
For Malaysian organisations there is a second consequence. A mailbox compromise of this kind almost always involves personal data, which places it within the breach notification obligations that took full effect under the amended Personal Data Protection Act in June 2025. Notification is required to the Commissioner within 72 hours. An attacker who has used an AI assistant to delete the evidence makes that deadline considerably harder to meet, because you must still describe what was accessed.
Financial institutions carry parallel obligations to Bank Negara Malaysia under RMiT.
How Primary Guard can help
Primary Guard works with organisations across Malaysia, Indonesia and Thailand on identity security, email protection and managed detection. If you are rolling out AI assistants across Microsoft 365 or Google Workspace and want to understand what that changes in your threat model, or you want mailbox rule creation monitored properly, talk to our team.