PipeRoll - Agent Incident Registry · about · contribute · data · notes · constitution · seismograph ↗

EchoLeak: zero-click prompt-injection data exfiltration in Microsoft 365 Copilot…

PipeRoll seal - registered recordPIR-2026-0017
Occurred
not applicable …
Disclosed
2025-06-11
Operator
enterprise
Blast radius
customers/third parties
Root cause
prompt-injection
Failure locus
harness
Severity
near-miss
Exploitation
researcher-demonstrated
Direct loss (USD)
0
Telemetry
none/vendor-attested - "no in-wild…
Confidence
high on mechanism, dates, and CVE
Status
corroborated
Cite as: PipeRoll PIR-2026-0017, EchoLeak: zero-click prompt-injection data exfiltration in Microsoft… (2025) - https://piperoll.org/pir/2026-0017 markdown. Registered 2026-08-15 by Srinivas G.

PIR-2026-0017 - EchoLeak: zero-click prompt-injection data exfiltration in Microsoft 365 Copilot (CVE-2025-32711)

The agent

Authority

The failure

Impact

Detection and recovery

Evidence

Verification notes

More prompt-injection records

← older: PIR-2026-0016 · registry · newer: PIR-2026-0018 →