Email AI assistants could enable CEO account takeover
Barracuda researchers simulated attackers using a compromised mailbox’s AI assistant to hide activity, phish a CEO, capture session tokens and hijack the executive’s account.
Researchers at Barracuda Networks ran a laboratory simulation showing how an attacker with access to a compromised email account could use that account’s built-in AI assistant to escalate privileges and take over an executive’s mailbox.
The team began with a lower-level employee’s compromised account. Because many email platforms attach an AI assistant to each mailbox, gaining access to the email granted control of the assistant. The attacker first instructed the assistant to create an inbox rule that moved messages with sign-in in the subject into the deleted items folder to hide evidence of unauthorized access.
The attacker then used the assistant for reconnaissance, asking it to summarize organizational relationships and ongoing sensitive conversations. Those prompts revealed context and reasons why the CEO might expect a message from the compromised employee.
Using that context, the attacker had the assistant draft a reply in the employee’s usual style and add a link that appeared to be an invoice confirmation. The message came from a trusted internal address, matched the user’s tone and was likely to bypass standard filters.
In the simulation, the CEO clicked the link. The link routed through an adversary-in-the-middle proxy that captured the CEO’s session token and credentials. The report notes that possession of an authenticated session token can allow an attacker to bypass multifactor authentication and access the CEO’s mailbox. After taking over the CEO account, the attacker again used the assistant to remove traces of the new compromise.
The attacker then instructed the CEO’s AI assistant to summarize recent financial emails, invoices and upcoming transfers. With that information and the CEO’s writing style, the attacker drafted a message to the finance team instructing a wire transfer to a new bank account, saying the payee had changed their banking details. The simulated email passed authentication checks, referenced a real pending transaction and matched the executive’s normal communications. The researchers’ scenario redirected a hypothetical imminent pre-authorized payment of about $250,000.
The report emphasizes the experiment was a proof-of-concept carried out in a controlled environment and not a documented real-world incident. The researchers noted that compromising an email account remains the most difficult step, but historical patterns show attackers continue to pursue those access vectors. They also observed that mailbox-linked chatbots typically log activity, so an attacker seeking persistence must remove or alter those logs.
Researchers recommend organizations protect account credentials, monitor for unusual mailbox rules and AI-assistant activity, and consider controls on assistant capabilities that can modify mail rules, compose messages on behalf of users or access sensitive email content. The report also highlights that automated, context-aware message drafting combined with session-token theft can make internal phishing more convincing and can defeat some multifactor protections.








