Varonis researchers disclosed “CoSnitch”, a set of flaws in Copilot Personal (tracked as CVE-2026-24301) where one malicious link could silently extract email, calendar and connected-drive data. Microsoft patched it on 18 August. The research did not say that Microsoft 365 Copilot — the work version — was affected.
The bug is fixed. The lasting lesson is about which AI your staff use for work. A personal Copilot, ChatGPT or Gemini account connected to a personal inbox sits outside anything the business controls: no audit trail, no retention, no data-loss rules, and no say over what gets connected to it. When staff paste work into personal AI tools, that’s where the work ends up.
Microsoft 365 Copilot Chat signed in with a work account comes with enterprise data protection, shown by a green shield at the top of the chat window, and Microsoft states that prompts and responses aren’t used to train its foundation models. That’s the version to standardise on — and to show staff — before they choose their own.
