A security researcher has disclosed a vulnerability in Microsoft Copilot for Word that could allow hidden malicious instructions to replicate through documents used in everyday collaboration. The technique uses prompt injection rather than conventional malware, creating a risk for organizations using Copilot to draft, edit, or summarize Word files.
The issue was reported to Microsoft by security researcher Håkon Måløy in March 2026 and followed a 144-day coordinated disclosure process. Microsoft has implemented partial mitigations, although the broader attack class remained effective as of late July 2026.
The disclosure matters because Word documents routinely travel through email, SharePoint, Teams, and OneDrive. A document that appears legitimate to an employee could potentially influence Copilot's behavior when it is used as reference material, allowing the threat to move through normal workflows.
How the Hidden-Prompt Technique Works
The attack begins with a Word document containing text formatted in white on a white background. The content is effectively invisible during a normal read-through, allowing an attacker to conceal instructions without changing the document's apparent purpose or presentation.
Those instructions can be structured as a prompt intended for Copilot rather than as content for the user to read. When someone asks Copilot for Word to create, revise, or summarize content based on the document, the AI can process the concealed text alongside the visible material. Copilot may then interpret the hidden content as an instruction.
But it doesn't end there. As Radoslav Krehlik, owner at NORAM spol., explains,
"the processcreates a self-propagating AI worm that spreads through normal collaboration in SharePoint, Teams, OneDrive, and email."
Once the new document is shared and used by another employee as Copilot source material, the process can happen again, creating further carrier files without relying on macros, executable code, or a traditional malware payload. This can make the activity difficult to trace.
As the disclosure summary states: "No special access is required. Simply opening or referencing the poisoned document is enough." That makes the threat relevant to organizations where employees regularly reuse documents, templates, and externally supplied material.
What Organizations Can Do to Reduce Exposure
The most immediate defensive measure is to treat externally sourced documents as untrusted before using them with Copilot for Word. That includes files received by email, downloaded from websites, shared by partners, or supplied during procurement, legal, and customer service processes.
Security teams should ensure that users understand the distinction between opening a document and asking an AI assistant to act on its contents. Copilot's ability to use a document as context can introduce a separate layer of risk, particularly if the file has not been reviewed through established security controls.
Organizations should also ask users to verify documents generated or edited by Copilot before sharing them. The risk is not limited to the original malicious file. An apparently legitimate document produced by an employee may have become a carrier for hidden instructions.
For businesses that do not need Copilot in Word for all users, reducing its availability may be appropriate while internal risk assessments are carried out. Individual users can disable Copilot through Word settings, while Microsoft 365 administrators can control how prominently Copilot Chat is surfaced across Microsoft 365 apps.
Disabling optional connected experiences can also limit certain cloud-enabled functionality. These settings do not eliminate prompt injection risks, but they can reduce the likelihood that an unvetted document will be processed by Copilot as part of a routine workflow.




