M365 Copilot Wire Transfer (2025) โ A poisoned invoice caused Copilot to confidently recommend urgent payment to attacker-controlled bank details. The finance manager trusted the AI's reasoning and approved without independent verification.
Source: OWASP ASI Incidents Tracker, 2025Prompt Injection ยท Output Handling ยท Excessive Agency ยท Misinformation