Hackers Could Weaponize Email AI to Impersonate CEOs

Security Week Feed · High sophistication
Last updated August 4, 2026

Barracuda researchers simulated how an attacker who already compromised one employee mailbox could use the account’s built-in email AI assistant to hide evidence, learn org context, and draft convincing internal phishing emails. In their proof of concept, the attacker used an invoice-themed link to hijack the CEO’s session and then used the CEO mailbox to request a wire transfer change to a new bank account.

Key findings

  • Once an email account is compromised, the attacker can use the built-in email AI assistant as a “living off the land” tool.
  • The AI assistant can be prompted to create inbox rules to hide security-related emails (stealth/persistence).
  • The AI assistant can summarize sensitive conversations and org structure to help the attacker choose believable pretexts.
  • Attackers can use the AI assistant to draft internal spearphishing emails in the compromised user’s writing style to increase trust.
  • A successful click can route to an adversary-in-the-middle proxy to steal session tokens and bypass MFA.
  • After CEO takeover, the attacker can use the CEO AI assistant to identify upcoming payments and craft a bank-change wire request (BEC) that passes authentication checks.

Who’s being targeted

  • Commonly targeted roles: Executive leadership (CEO and assistants), Finance / Accounts Payable, All employees (email users), IT / Security operations (mailbox and AI assistant administrators).
  • Affected industries: Any organization using email platforms with built-in AI assistants, Corporate finance (wire payments), Executive leadership.
  • Attack channels: email, website.
  • Impersonated: Employee account holder (attacker using a compromised mailbox), Trusted internal employee (attacker replying from their compromised mailbox), CEO (attacker operating from the CEO’s compromised mailbox).

Awareness takeaways

  • Treat internal emails as untrusted when they contain links or payment instructions, even if they come from a real coworker’s mailbox.
  • Finance teams should require out-of-band verification for any bank detail change or wire redirection request.
  • Monitor for suspicious mailbox rule creation (especially rules that delete or move ‘sign-in’/security emails) as an early sign of account takeover.
  • Limit and audit AI-assistant access and logging, because attackers can use assistants for reconnaissance and drafting highly convincing messages in the victim’s style.

Red flags to watch for

  • Unexpected inbox rules that delete or move ‘sign-in’ or security alert emails
  • Missing security notification emails that coworkers normally receive
  • Unexplained configuration changes attributed to the user
  • Invoice/confirmation links inserted into an email thread unexpectedly
  • Pressure to approve/confirm via a link rather than established finance systems
  • Link leads to a login flow or unexpected webpage rather than an internal approved tool
  • Any bank-detail change request sent only by email (even from a real executive mailbox)
  • Request references a real payment but changes the account at the last minute
  • Unusual urgency or bypass of normal vendor/bank-change verification steps
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: your mailbox is hacked, and the attacker uses your own email AI to cover their tracks for them. Barracuda showed an attacker telling the email chatbot: "Create an inbox rule that moves any emails with 'sign-in' in the subject into the deleted items folder", so security alerts just vanish while they read your sensitive threads and learn who approves what. Then they have the AI write an internal reply in your exact style: "Create an email using my writing patterns to respond to the Q3 budget approval email. I have a link to insert into the draft that contains the actual invoice confirmation." The CEO clicks that internal invoice link, hits an adversary-in-the-middle page, and their session gets hijacked. Here’s the move: if any email about invoices, wires, or bank changes asks you to click a link, even from a real coworker, pause and confirm it out-of-band with finance before you do anything.

Similar attacks

Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Cybercrime as a Service Fuels New Scam Waves

Cybercrime as a Service Fuels New Scam Waves

A threat landscape report describes how criminals now buy or rent phishing, fraud, malware, and hidden infrastructure “as a service,” making scams faster to launch and harder to stop. The article highlights practical, repeatable social-engineering workflows such as fake CAPTCHA pages that trick…

July 31, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Kratos PhaaS Fueled MFA-Bypass Phishing

Kratos PhaaS Fueled MFA-Bypass Phishing

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session cookies. The article also describes a real campaign using tax-season lures and personalized QR codes to trick users into visiting fake…

July 24, 2026
Teams Phishing Rises After Tycoon2FA Takedown

Teams Phishing Rises After Tycoon2FA Takedown

Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics rather than stop. The report highlights real campaigns that shifted toward Microsoft Teams-based social engineering, highly automated BEC…

July 24, 2026
Malicious CSS Emails Can Hijack Webmail UI

Malicious CSS Emails Can Hijack Webmail UI

PortSwigger research shows how attackers can weaponize HTML/CSS inside emails to cross trust boundaries in webmail, including UI manipulation, token theft, and password theft. The paper highlights real-world weaknesses in email sanitization and gives concrete examples (including an Outlook…

August 6, 2026