Open cardosec

Case D6E9D3 · AI security · L3 Applied

Copilot Forwards the Inbox

Practise as: Incident drill · Interview

Live alertMail logs show the AI email assistant forwarded 42 messages from the CFO's mailbox to an external Gmail address at 14:07, seconds after summarizing an inbound vendor invoice email.

Interview questionYour AI email assistant forwarded executive mail to an outside address. Walk me through your response.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Contain: disable the assistant's send/forward tool or revoke its OAuth grant; block the recipient address.
  2. Preserve evidence: the triggering email (raw MIME), model prompt/response and tool-call logs, mail trace logs.
  3. Likely indirect prompt injection hidden in the vendor email (white text or HTML comment) plus excessive agency.
  4. Scope impact: which messages left, their sensitivity, other mailboxes that processed the same sender's mail.
  5. Fix: human approval for external sends, allowlisted recipients, and strip tools after reading untrusted content.

If the interviewer pushes back

  • Is this a model vulnerability or an application design flaw? Who owns the fix, the vendor or you?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.