Hackers Exploit Copilot Studio’s New Connected Agents Feature to Gain Backdoor Access
On Thu, Dec 30, 2025, Microsoft introduced a new feature named "Connected Agents" as part of Copilot Studio during the Build 2025 event. This feature has introduced a security vulnerability that has been actively exploited by attackers to gain…
On Thu, Dec 30, 2025, Microsoft introduced a new feature named "Connected Agents" as part of Copilot Studio during the Build 2025 event. This feature has introduced a security vulnerability that has been actively exploited by attackers to gain unauthorized backdoor access to critical business systems.
The Connected Agents feature allows AI-to-AI integration, enabling agents to share functionality and reuse logic across different environments. While this was developed to enhance efficiency, it presents significant security risks when misconfigured or deliberately exploited.
Overview of the Connected Agents Security Risk
By default, the Connected Agents feature is enabled for all new agents in Copilot Studio. Once activated, it exposes an agent’s knowledge, tools, and topics to all other agents within the same environment, creating potential security vulnerabilities.
Notably, there is no built-in visibility to identify which agents have connected to another, resulting in a blind spot for security monitoring. This gap is being exploited by attackers who create malicious agents to connect with legitimate, privileged agents, particularly those with access to sensitive business data or email capabilities.
On Thu, Dec 30, 2025, Microsoft introduced a new feature named "Connected Agents" as part of Copilot Studio during the Build 2025 event.
Proof-of-concept demonstrations have shown that threat actors can compromise support agents configured to send emails from official company domains, enabling large-scale phishing and impersonation attacks. An attacker can create a backdoor agent that connects to a legitimate agent, triggering email functionality without leaving traces in activity logs. This allows the attacker to send emails impersonating the company, potentially damaging brand reputation and triggering domain-blocking through spam filters.
Organizations are advised to conduct immediate audits of agents currently in production. It is recommended to disable the Connected Agents feature on all agents containing unauthenticated tools or sensitive knowledge sources. Implementing tool authentication to require explicit user credentials for sensitive actions is also advised. For critical business agents, disabling the Connected Agents feature entirely is recommended.
Reviewing all knowledge sources and publishing channels is crucial to ensure that only legitimate users have access to exposed capabilities. The recommendation is for Microsoft to set the default for this feature to disabled, requiring developers to opt in, rather than necessitating reactive security measures post-publication. Until comprehensive solutions are implemented, any agent with Connected Agents enabled should be treated as publicly accessible for security purposes.
Based on reporting by Cyber Security News.
