Prompt injection that reproduces through ordinary Word workflows

Håkon Måløy’s controlled tests used Copilot for Word. Instructions hidden in an input document influenced the generated report and were copied into it. When that report became source material for another Copilot session, the instructions could activate again and reproduce into another document.

The original malicious file no longer needed to be present. Propagation happened through the normal reuse of documents in AI-assisted drafting and editing.

The demonstration included altered financial figures, making the problem one of information integrity as well as prompt injection. An internally produced report could become a carrier despite arriving through an apparently ordinary workflow.

Måløy coordinated with Microsoft for 144 days before the July disclosure. Microsoft deployed mitigations that stopped particular payloads; he reported reproducing the broader mechanism with modified inputs at publication. That describes the disclosure’s tested state, rather than asserting that every version remains vulnerable today.

Simon highlights the architectural difficulty: source material must be read to be useful, while instructions inside that material must remain untrusted. Recording provenance and model edits can help investigation even when it does not prevent the initial injection.