Microsoft
Disclosed Feb 18, 20267 months agoUnverified
Microsoft 365 Copilot Chat bug processed confidential-labeled emails for weeks
Microsoft confirmed a bug (CW1226324) that let Microsoft 365 Copilot Chat read and summarize draft and sent emails carrying confidential labels since January 2026, bypassing customers' data loss prevention policies. A fix began rolling out in February.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Feb 18, 2026 |
| Attack | AI or model |
| Data exposed | Messages |
| Sector | Tech · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Microsoft says Office bug exposed customers' confidential emails to Copilot AItechcrunch.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Feb 18 |
Other breaches at Microsoft
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.