What happened
Security researchers at Varonis Threat Labs disclosed a chain of three vulnerabilities in Microsoft 365 Copilot Enterprise Search that, when combined, created a single-click path to steal emails, calendar entries, MFA codes, and indexed files from a victim's account. Dubbed SearchLeak, the attack worked through a link pointing to a legitimate microsoft.com domain, allowing it to bypass standard URL-filtering and anti-phishing defenses entirely. Microsoft has since patched the flaws. Separately, investigative reporting from Krebs on Security shed light on the administrator behind The Gentlemen, a ransomware operation that has rapidly become the second most prolific gang by victim count, in part by offering affiliates an unusually high 90 percent cut of ransom proceeds.
Why it matters for your business
The SearchLeak vulnerability underscores a growing risk with AI-powered productivity tools: enterprise search capabilities that aggregate sensitive data across email, files, and calendars create high-value targets that legacy security controls were not designed to protect. Because the malicious link carried a genuine Microsoft domain, organizations relying solely on URL reputation or perimeter filtering would have had no warning. Businesses adopting Microsoft 365 Copilot should audit who has access to Enterprise Search, apply the latest patches immediately, and evaluate whether behavioral detection tools can flag anomalous data-retrieval activity. On the ransomware front, The Gentlemen's aggressive affiliate model signals that the group is scaling rapidly, meaning mid-market companies — which often lack dedicated threat intelligence — face elevated exposure.
What to watch next
Microsoft's patch closes the specific SearchLeak chain, but the episode is likely to prompt further security research into how Copilot and similar AI assistants handle permissioned data access at scale. Law enforcement and threat intelligence teams will continue efforts to deanonymize The Gentlemen's leadership, and any arrest or indictment could disrupt affiliate recruitment — though copycat groups typically fill such voids quickly. Organizations should monitor ransomware tracker feeds and adjust incident-response playbooks to account for the group's growing operational footprint.
