Microsoft and Google E-mail by default fail discreetly and expose data sensitive to patients without notifying anyone or register anything


  • Experts warn the emails sent with sensitive data is always delivered unacysed, and no one is informed
  • Microsoft 365 sends an email in raw text when encryption fails, without alerting the user at all
  • Google Workspace still uses TLS 1.0 and 1.1 without security without warning sender or rejecting messages

Most users assume that emails sent via the cloud services are encrypted and secure by default, but it may not always be the case, said new research.

A Paubox report revealed that Microsoft 365 and Google Workspace Mishandle these failures in a way that leaves the messages exposed, without notifying the sender or saving the failure.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top