Hidden text in Word documents makes Copilot alter figures and spread the attack

Security researcher Håkon Måløy disclosed an attack on Copilot for Word on 28 July 2026. Hidden instructions in an attached document make the assistant alter the content of the document it is writing, and copy those instructions into the result. The new document then becomes a carrier of the attack itself. The findings are part of a coordinated disclosure with the Microsoft Security Response Center, where an agreed period of 90 days was extended twice to 144 days. Måløy states that the attack could still be reproduced with every mitigation Microsoft has deployed, and that at the time of publication no customer side measure closes the issue completely.

What happens technically

The attack is an indirect prompt injection, described in the report as cross domain prompt injection. The malicious document contains a hidden prompt formatted as JSON, and the text can be written as white text on a white background in a small font size. Copilot for Word strips all text formatting, including colour and font size, before the text is passed to the language model. The text is therefore invisible to the human reader and fully readable to the model. The attacker needs no access to the organisation's Microsoft 365 tenant, only a way to share a document, and the report names SharePoint, Teams and Outlook as examples. The document has to enter Copilot's context, either because the user attaches it, or because Copilot finds it in the user's OneDrive through the «Edit with Copilot» function in work mode.

The attack runs in two stages. In the first stage Copilot carries out the instructions in the attached document as if they were the user's own. In the demonstration the assistant halved every figure in a quarterly report without mentioning the change, and then pasted the entire attack text at the bottom of the new document in white text at font size 8. In the second stage the new document is the attack vector. If it is later used as source material in another Copilot session, the instructions trigger again, and the original document no longer needs to be present. The timeline in the report shows that Microsoft deployed a first mitigation on 3 April 2026, that the original wording was closed on 9 April, and that the attack was reproduced the same day with a new prompt. A second mitigation on 14 July consisted of upgrading the underlying model to GPT-5.5, and the following day the attack was reproduced with GPT-5.6. Måløy states that he is disclosing at the class level and withholding the wording of the prompt itself. Self propagating prompts have been described in research before, among them the Morris II work against email assistants, but Måløy considers this among the first public demonstrations of propagation through documents in a mainstream office suite.

Shared documenthidden white textCopilot for Wordreads the attachmentNew documentfigures quietly alteredShared onwardsand reusedthe document becomes the new attack vector
Figure: The malicious document influences Copilot in the first session, and the result carries the instructions into the next session without the original document being present.

What this means for you if you use Copilot in Word

If you use Copilot to write in Word, this is a question of integrity before it is a question of confidentiality. Berigo's assessment is that the most serious effect is not that a document leaks, but that figures and wording are changed quietly in material you later use to make decisions. A document written by an assistant looks normal. The change is often small enough to slip past you even when you read attentively. Måløy writes that during his experiments he had to ask Copilot to highlight the changes in order to spot them himself. Norwegian organisations share documents with customers, auditors and partners every day, and so do you. A document you pass on is therefore also a possible route into the recipient's workflow.

The other side of the case is that the controls that work today are organisational. There is no update for you to install, and the vendor has spent 144 days on two mitigations without closing the class. Your way of working therefore has to carry the risk. We believe you should look particularly closely at the work mode in which Copilot searches OneDrive on its own, because there you do not choose which documents end up in the context. If your organisation falls under NIS2, this belongs in the risk assessment under Article 21, both as a risk in the tool chain and as a training question. A management system for artificial intelligence under ISO/IEC 42001 gives you a place to put the requirement, but the requirement has to be written as a rule people can actually follow on a busy day.

Berigo recommends

  • Treat documents from external sources as untrusted when they are used with Copilot. The advice is the researcher's own, and it is what works today.
  • Read the attachment before a Copilot session starts, and review the result before the document is saved, shared or reused.
  • Consider whether Copilot should search OneDrive freely while drafting, since the document then enters the context without the user choosing it.
  • Check figures in decision material against the original source, not against a document written by an assistant.
  • Bring the vulnerability class into the risk assessment for AI tools, and describe it as a risk that content is altered, not only that content leaks.

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch