Hidden Prompts in Word Files Can Hijack Microsoft 365 Copilot, Researcher Warns
A proof of concept shows Copilot copying attacker instructions into finished documents, then spreading them to the next draft.

Key points
- Researcher Håkon Måløy disclosed on July 28 a technique that uses hidden instructions inside a Word document to manipulate Microsoft 365 Copilot.
- The hidden prompts told Copilot to alter figures in a drafted report and to copy the same instructions into the finished file.
- Måløy waited 144 days after reporting the issue to Microsoft before going public.
- In his proof of concept, the poisoned output triggered the same behaviour when reused in a second Copilot drafting session, showing the attack can spread between documents.
A security researcher has shown that Microsoft 365 Copilot, the artificial intelligence assistant built into Word and other Office apps, can be tricked into changing the contents of a business report and then quietly passing the attacker's instructions along to the next document it helps write.
The technique was disclosed by Håkon Måløy on July 28, 144 days after he first told Microsoft about it. The Hacker News reported the findings.
Think of it like this. Someone slips a note into a folder of source material. The assistant reads the note, follows what it says, and then staples a copy of the note into the finished report so the next person who opens it gets the same treatment.
How does the attack actually work?
Hidden text inside a Word document tells Copilot what to do, and the user never sees it. Måløy placed instructions in a source file that Copilot was asked to summarise. Copilot obeyed the hidden prompts, rewrote figures in the drafted report, and embedded the same instructions in the new file it produced.
This is a form of what researchers call indirect prompt injection: the malicious commands do not come from the person using the assistant, they come from a document the assistant is reading on that person's behalf. Because Copilot treats the text in a source file as material to work with, it can also be steered by text hidden inside it.
The worrying twist is the copy step. Once the poisoned instructions land in the finished document, that document becomes a carrier. Feed it into a second Copilot session, and the same manipulation happens again.
What did Copilot actually change?
In the proof of concept, Copilot altered numerical figures in the report it was generating. Måløy chose figures because they are the sort of detail an executive skims and trusts, not something most reviewers cross-check line by line against the source.
A reader could easily approve a summary with quietly wrong numbers. Then send it on. Then use it as the basis for the next draft.
Timeline of the disclosure
| Date | Event |
|---|---|
| Reported | Måløy notifies Microsoft of the technique |
| +144 days | Måløy publishes the disclosure |
| July 28 | Public write-up released |
Should ordinary Copilot users be worried?
Not in the sense of a virus on your laptop, but yes in the sense that you cannot fully trust an AI-generated summary of a document you did not write yourself. If a colleague, supplier or external party sends you a file and you ask Copilot to summarise or rework it, the output could reflect instructions hidden by whoever authored the source.
Practical steps for everyday users:
- Treat AI-drafted figures, quotes and recommendations as claims to verify, not facts.
- Be cautious about running Copilot over documents from outside your organisation without a quick manual read first.
- If a Copilot output looks oddly worded, or contains instructions aimed at the AI itself, flag it to IT rather than reusing the file.
Common questions
Is this a bug in Word?
No. It is a weakness in how the Copilot assistant handles instructions it finds inside documents. The underlying Word file format behaves normally.
Has Microsoft fixed it?
Måløy went public 144 days after reporting the issue, which suggests he was not satisfied with the pace of a fix. Users should watch for Microsoft's own guidance on Copilot prompt-injection defences.



