Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Unihertz Titan 2 Elite Is A Great Looking Keyboard Phone

Unihertz Titan 2 Elite Is A Great Looking Keyboard Phone

7 June 2026
U.S. floats steering frozen Iran assets to Gulf allies for repairs

U.S. floats steering frozen Iran assets to Gulf allies for repairs

7 June 2026
The Clearest Sign That You’re In The Right Relationship, By A Psychologist

The Clearest Sign That You’re In The Right Relationship, By A Psychologist

7 June 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » New Warning — Microsoft Copilot AI Can Access Restricted Passwords
Innovation

New Warning — Microsoft Copilot AI Can Access Restricted Passwords

Press RoomBy Press Room14 May 20254 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
New Warning — Microsoft Copilot AI Can Access Restricted Passwords

As the name implies, Pen Test Partners is a company that specializes in security consulting, specifically penetration testing. These are professional hackers who can find the exact same routes to compromise your systems that the most advanced attackers would look to exploit. Those threat actors are increasingly using AI-powered attacks, so it makes sense for red team hackers to do likewise. And that, dear reader, is what happened when Pen Test Partners took a close look at how Microsoft’s Copilot AI for SharePoint could be exploited. The results were, to say the least, concerning. Not least considering an encrypted spreadsheet that the hackers were, quite rightly, rejected from opening by SharePoint, no matter what method was employed, was broken wide open when they asked the Copilot AI agent to go get it. “The agent then successfully printed the contents,” Jack Barradell-Johns, a red team security consultant with the security company, said, “including the passwords allowing us to access the encrypted spreadsheet.”

Red Team Penetration Testers Use Copilot AI To Hack Microsoft SharePoint

AI can be a force for good when it comes to security protections, but also, increasingly, a force for bad. The latter has recently been exemplified in a multi-stage AI-driven attack against Microsoft Teams users, for example.

I would strongly recommend reading the full report for all the details of how the red team hackers exploited Copilot AI for SharePoint during their engagement, but I want to focus on the access to passwords, as that’s what has really grabbed my attention, and should grab yours as well.

Barradell-Johns explained that during the engagement, the red teamers encountered a file named passwords.txt, located adjacent to an encrypted spreadsheet containing sensitive information. Naturally, they tried to access the file. Just as naturally, Microsoft SharePoint said nope, no way. “Notably,” Barradell-Johns said, “in this case, all methods of opening the file in the browser had been restricted.”

So, what did the red team hackers do? Use the read team hacking mindset and ask the Copilot AI for Sharepoint agent to go and get it instead. “The agent then successfully printed the contents,” Barradell-Johns reported, “including the passwords allowing us to access the encrypted spreadsheet.” The download restrictions that are part of the restricted view protections were circumvented, and the content of the Copilot chats could be freely copied.

Microsoft Responds To Red Team Copilot AI SharePoint Hacking Report

I reached out to Microsoft, and a spokesperson said:

“SharePoint information protection principles ensure that content is secured at the storage level through user-specific permissions and that access is audited. This means that if a user does not have permission to access specific content, they will not be able to view it through Copilot or any other agent. Additionally, any access to content through Copilot or an agent is logged and monitored for compliance and security.”

I then contacted Ken Munro, founder of Pen Test Partners, who issued the following statement addressing the points made in the one provided by Microsoft.

“Microsoft are technically correct about user permissions, but that’s not what we are exploiting here. They are also correct about logging, but again it comes down to configuration. In many cases, organisations aren’t typically logging the activities that we’re taking advantage of here. Having more granular user permissions would mitigate this, but in many organisations data on SharePoint isn’t as well managed as it could be. That’s exactly what we’re exploiting. These agents are enabled per user, based on licenses, and organisations we have spoken to do not always understand the implications of adding those licenses to their users.”

And, you’d better believe, if there are any configuration holes, then Copilot AI will find them.

Copilot For SharePoint Encrypted Password Hacking Encrypted Passwords With AI hacking passwords with AI Microsoft Copilot Security Warning Microsoft SharePoint Pen Test Partners SharePoint Hack SharePoint Password
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Unihertz Titan 2 Elite Is A Great Looking Keyboard Phone

Unihertz Titan 2 Elite Is A Great Looking Keyboard Phone

7 June 2026
The Clearest Sign That You’re In The Right Relationship, By A Psychologist

The Clearest Sign That You’re In The Right Relationship, By A Psychologist

7 June 2026
‘Strong’ Northern Lights Alert For 20 States On Monday As CME Strikes

‘Strong’ Northern Lights Alert For 20 States On Monday As CME Strikes

7 June 2026
Why Do Humans Get Dizzy? An Evolutionary Biologist Explains

Why Do Humans Get Dizzy? An Evolutionary Biologist Explains

7 June 2026
Rule-Followers Will Lose To AI While The Poor And Bold Win Big

Rule-Followers Will Lose To AI While The Poor And Bold Win Big

7 June 2026
‘Good Smile Fest 2026’ Shows Off ‘Dandivine’ And Reveals ‘Dancouga Liberation’

‘Good Smile Fest 2026’ Shows Off ‘Dandivine’ And Reveals ‘Dancouga Liberation’

7 June 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

22 October 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
‘Strong’ Northern Lights Alert For 20 States On Monday As CME Strikes

‘Strong’ Northern Lights Alert For 20 States On Monday As CME Strikes

7 June 20262 Views
Boomers are hoarding most of America’s wealth because they’re terrified of outliving their money

Boomers are hoarding most of America’s wealth because they’re terrified of outliving their money

7 June 20261 Views
Why Do Humans Get Dizzy? An Evolutionary Biologist Explains

Why Do Humans Get Dizzy? An Evolutionary Biologist Explains

7 June 20261 Views
America turns 250. Its greatest innovation was never a product — it was a system that let anyone build one

America turns 250. Its greatest innovation was never a product — it was a system that let anyone build one

7 June 20261 Views

Recent Posts

  • Unihertz Titan 2 Elite Is A Great Looking Keyboard Phone
  • U.S. floats steering frozen Iran assets to Gulf allies for repairs
  • The Clearest Sign That You’re In The Right Relationship, By A Psychologist
  • Consumers look resilient on the surface, but $4 gas was a tipping point
  • ‘Strong’ Northern Lights Alert For 20 States On Monday As CME Strikes

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Unihertz Titan 2 Elite Is A Great Looking Keyboard Phone

Unihertz Titan 2 Elite Is A Great Looking Keyboard Phone

7 June 2026
U.S. floats steering frozen Iran assets to Gulf allies for repairs

U.S. floats steering frozen Iran assets to Gulf allies for repairs

7 June 2026
The Clearest Sign That You’re In The Right Relationship, By A Psychologist

The Clearest Sign That You’re In The Right Relationship, By A Psychologist

7 June 2026
Most Popular
Consumers look resilient on the surface, but  gas was a tipping point

Consumers look resilient on the surface, but $4 gas was a tipping point

7 June 20260 Views
‘Strong’ Northern Lights Alert For 20 States On Monday As CME Strikes

‘Strong’ Northern Lights Alert For 20 States On Monday As CME Strikes

7 June 20262 Views
Boomers are hoarding most of America’s wealth because they’re terrified of outliving their money

Boomers are hoarding most of America’s wealth because they’re terrified of outliving their money

7 June 20261 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.