Hackers Could Weaponize Email AI to Impersonate CEOs

Security Week Feed · High sophistication
Last updated August 4, 2026

Barracuda researchers simulated how an attacker who already compromised one employee mailbox could use the account’s built-in email AI assistant to hide evidence, learn org context, and draft convincing internal phishing emails. In their proof of concept, the attacker used an invoice-themed link to hijack the CEO’s session and then used the CEO mailbox to request a wire transfer change to a new bank account.

Key findings

  • Once an email account is compromised, the attacker can use the built-in email AI assistant as a “living off the land” tool.
  • The AI assistant can be prompted to create inbox rules to hide security-related emails (stealth/persistence).
  • The AI assistant can summarize sensitive conversations and org structure to help the attacker choose believable pretexts.
  • Attackers can use the AI assistant to draft internal spearphishing emails in the compromised user’s writing style to increase trust.
  • A successful click can route to an adversary-in-the-middle proxy to steal session tokens and bypass MFA.
  • After CEO takeover, the attacker can use the CEO AI assistant to identify upcoming payments and craft a bank-change wire request (BEC) that passes authentication checks.

Who’s being targeted

  • Commonly targeted roles: Executive leadership (CEO and assistants), Finance / Accounts Payable, All employees (email users), IT / Security operations (mailbox and AI assistant administrators).
  • Affected industries: Any organization using email platforms with built-in AI assistants, Corporate finance (wire payments), Executive leadership.
  • Attack channels: email, website.
  • Impersonated: Employee account holder (attacker using a compromised mailbox), Trusted internal employee (attacker replying from their compromised mailbox), CEO (attacker operating from the CEO’s compromised mailbox).

Awareness takeaways

  • Treat internal emails as untrusted when they contain links or payment instructions, even if they come from a real coworker’s mailbox.
  • Finance teams should require out-of-band verification for any bank detail change or wire redirection request.
  • Monitor for suspicious mailbox rule creation (especially rules that delete or move ‘sign-in’/security emails) as an early sign of account takeover.
  • Limit and audit AI-assistant access and logging, because attackers can use assistants for reconnaissance and drafting highly convincing messages in the victim’s style.

Red flags to watch for

  • Unexpected inbox rules that delete or move ‘sign-in’ or security alert emails
  • Missing security notification emails that coworkers normally receive
  • Unexplained configuration changes attributed to the user
  • Invoice/confirmation links inserted into an email thread unexpectedly
  • Pressure to approve/confirm via a link rather than established finance systems
  • Link leads to a login flow or unexpected webpage rather than an internal approved tool
  • Any bank-detail change request sent only by email (even from a real executive mailbox)
  • Request references a real payment but changes the account at the last minute
  • Unusual urgency or bypass of normal vendor/bank-change verification steps
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: your mailbox is hacked, and the attacker uses your own email AI to cover their tracks for them. Barracuda showed an attacker telling the email chatbot: "Create an inbox rule that moves any emails with 'sign-in' in the subject into the deleted items folder", so security alerts just vanish while they read your sensitive threads and learn who approves what. Then they have the AI write an internal reply in your exact style: "Create an email using my writing patterns to respond to the Q3 budget approval email. I have a link to insert into the draft that contains the actual invoice confirmation." The CEO clicks that internal invoice link, hits an adversary-in-the-middle page, and their session gets hijacked. Here’s the move: if any email about invoices, wires, or bank changes asks you to click a link, even from a real coworker, pause and confirm it out-of-band with finance before you do anything.

Similar attacks

Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Mirage2FA Phishing Kit Steals Microsoft 365 Sessions

Mirage2FA Phishing Kit Steals Microsoft 365 Sessions

A phishing-as-a-service toolkit called Mirage2FA has been targeting organizations by abusing real Microsoft 365 login pages through a man-in-the-middle proxy. The attackers capture usernames, passwords, and live two-factor authentication codes, then take over the user’s session using stolen session…

August 31, 2026
Phish Adds Passkey That Survives Reset

Phish Adds Passkey That Survives Reset

Researchers described iAuthFlow v2, a phishing toolkit that steals a live Google login session and then uses that access to enroll an attacker-controlled passkey. Because passkeys are separate login methods, the attacker can often get back into the account even after the victim changes their…

August 24, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Russian Clusters Hijack Accounts via OAuth & WhatsApp

Russian Clusters Hijack Accounts via OAuth & WhatsApp

Google says multiple suspected Russia-linked espionage clusters targeted academics, government, and defense-related personnel by abusing legitimate sign-in features instead of using obvious fake login pages. The campaigns used realistic lures (file sharing, conference invites, and “secure WhatsApp”…

August 20, 2026
Real-Time Smishing Tool Steals 2FA Codes Live

Real-Time Smishing Tool Steals 2FA Codes Live

Cisco Talos reported a real-time phishing framework called “JWR” that guides victims through fake checkout and login pages while attackers watch keystrokes live. It is being delivered through SMS messages that impersonate toll and postal authorities, and it can capture payment details, identity…

August 13, 2026