
Reprompt: one click steals all your Microsoft Copilot data
The numbers speak for themselves: a single click on a legitimate Microsoft link was enough for an attacker to steal your location, recent files, travel plans, and complete Copilot conversations. The attack is called Reprompt, it chains three prompt injection techniques, and it worked even after closing the chat. 33 million users were at risk.










