Slide 1 of 28
Part 1 — What Is It?Slide 1
PART 1
What Is It?
Slides 1–8 · Understanding the risk before we name it
Slide 1 · The Setup
You didn't do anything wrong. Someone else did.
A real attack. No password stolen. No link clicked. No warning.
What happened

It's a Tuesday morning. You have a meeting in an hour and about 200 unread emails. You open your AI assistant and type: "Summarize what I missed while I was out."

The assistant starts working — reading your inbox, pulling context, building a summary. Normal. You've done this a hundred times.

But one of those emails wasn't just an email. Buried in it — invisible to you, invisible in any preview — were instructions written for the AI, not for you. The assistant read them. And followed them.

While it was summarizing your inbox, it was also reading your password reset emails. Your HR documents. Your draft messages. It packaged that data and quietly sent it to an address you've never heard of.

You got your summary. You went to your meeting. You never knew.

The damage

This isn't a hypothetical. In June 2025, researchers demonstrated exactly this attack against Microsoft 365 Copilot. A single crafted email. Zero clicks required from the victim. The AI did the rest.

The attacker never touched your account. They touched your AI.

The question this module answers

How does an AI that's supposed to help you end up working for someone else — without you ever knowing it switched sides?

I want to understand how → What do we call this?