CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Microsoft 365 Copilot Bug Bypasses DLP Policies for Confidential Emails

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A bug in Microsoft 365 Copilot has been causing the AI assistant to summarize confidential emails since late January, bypassing data loss prevention (DLP) policies. The issue affects the Copilot 'work tab' chat feature, which incorrectly reads and summarizes emails stored in users' Sent Items and Drafts folders, including messages with confidentiality labels. Microsoft confirmed the bug and began rolling out a fix in early February, but the full remediation timeline and scope of impact remain undisclosed.

Timeline

  1. 18.02.2026 14:03 1 articles · 11h ago

    Microsoft 365 Copilot Bug Bypasses DLP Policies for Confidential Emails

    A bug in Microsoft 365 Copilot, first detected on January 21, 2026, causes the AI assistant to summarize confidential emails, bypassing DLP policies. Microsoft confirmed the issue and began rolling out a fix in early February, but the full remediation timeline and scope of impact remain undisclosed.

    Show sources

Information Snippets