Security researcher Johann Rehberger has demonstrated how a hidden prompt buried inside a Word document can hijack Microsoft Copilot for Word — silently altering content, then embedding itself into every new document Copilot touches. It spreads through normal document-sharing workflows without macros, without traditional malware, and without the user noticing.
The technique is straightforward. An attacker hides a JSON-formatted instruction as white text on a white background inside a Word file. When someone asks Copilot to draft or edit content using that document as a reference, Copilot strips the formatting, reads the hidden text, and treats it as a legitimate instruction. Copilot then modifies the active document and appends the same hidden prompt. That document becomes a new carrier. Anyone who later feeds it into Copilot repeats the cycle.
What makes this genuinely concerning is that Microsoft hasn’t been able to fully fix it. The researcher reproduced the full worm chain even after multiple patches, including upgrades to GPT-5.5 and 5.6 models. The underlying problem is architectural: in current LLM systems, attacker-controlled content and trusted instructions share the same context window. There’s no reliable way to separate them.
This matters right now because Copilot became the default in Microsoft 365 Business plans from 1 July. A lot of Australian businesses now have it switched on without having made a deliberate decision to adopt it — and without reviewing what it can access. In our client environments across Sydney, the Central West and Brisbane, we’re seeing Copilot active on tenants where document-sharing permissions were never tightened. That’s exactly the kind of environment where a self-propagating prompt injection spreads fastest.
What to Do
If you use Copilot for Word, treat external documents as untrusted before feeding them to the AI. Review Copilot-generated content before sharing it onward. If you don’t actively use Copilot, consider disabling it until Microsoft resolves this class of attack. And regardless, now is the time to tighten SharePoint and OneDrive permissions so Copilot can only reach what it should.
If you want a hand reviewing your Copilot settings and document-sharing permissions, get in touch.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
