**Attackers Use Email AI Assistants to Hijack Accounts, Researchers Warn**
In a disturbing demonstration of the potential for email account compromise, researchers at Barracuda Networks have shown how attackers can use built-in AI assistants to hijack high-level accounts and execute sophisticated attacks. By exploiting the trust placed in these chatbots by their users, hackers can create a stealthy and versatile alternative to traditional Living off the Land (LotL) tactics.
The attack begins with compromising an email account, which is often the most challenging part of this type of attack. However, once inside, an attacker gains automatic access to any built-in AI Assistant attached to the account. Researchers used a simulated attack within their laboratory environment to explore the potential for bad actors to abuse these chatbots.
In their proof of concept, the researchers successfully elevated privileges from a lower-level compromised user to that of the CEO using only the AI and without being detected. They chose this route because directly phishing the CEO would likely set off alarms and be difficult to execute undetected. With a compromised email account, an attacker has access to the chatbot’s capabilities, which can be used to establish persistence and stealth.
The researchers started by instructing the chatbot to remove any evidence of its use in the logs, creating basic stealth. Next, they used the AI to conduct reconnaissance, asking it to remind them about the organization structure and ongoing email conversations involving the CEO. The responses to these prompts revealed relationships between the compromised user and the CEO, providing a valid reason for contact.
The attackers then crafted an internal phishing email in the style of the compromised user, using the chatbot to construct the message and link. This “trusted” phish was designed to bypass filters and convince the CEO to click on the malicious link, which would route through an adversary-in-the-middle proxy to steal their credentials and session token.
The attackers’ next step was to use the stolen CEO account to execute a session token takeover, bypassing multifactor authentication (MFA) and logging into the highly privileged CEO’s account. The researchers then used the chatbot to provide a refresher on recent financial emails, revealing an imminent pre-authorized payment of $250,000.
The attacker’s final step was to use the chatbot to send a message to finance, instructing them to redirect the payment to a new account due to changes in the payee’s banking details. Since the message came from the CEO’s real mailbox and passed every authentication check, traditional email security systems failed to flag it as suspicious.
While this simulation was intentionally designed to demonstrate the potential for abuse, it highlights the risks of using built-in AI assistants without proper security measures in place. As these tools become increasingly accessible and user-friendly, attackers may find new ways to exploit them. To mitigate this risk, organizations must ensure that their email security systems are equipped to detect and prevent such attacks.
**Practical Takeaway**
This research serves as a reminder of the importance of implementing robust email security measures, including multifactor authentication and regular vulnerability scanning. Additionally, users should be aware of the potential risks associated with built-in AI assistants and take steps to secure their accounts by regularly reviewing their chatbot logs and ensuring that these tools are not being used in unauthorized ways. By staying informed and vigilant, organizations can reduce the risk of falling victim to such attacks.
Source: SecurityWeek — 2026-08-04