Microsoft admits Office bug exposed users’ confidential emails to Copilot


  • Copilot Chat was reading sent and draft emails, but the Inbox folder appears to have been protected
  • The bug (CW1226324) was identified in January, a fix followed in February
  • Although the fix is ​​rolling out, this is still a persistent issue.

Microsoft has confirmed that a bug in M365 Copilot Chat allowed the AI ​​chatbot to summarize confidential emails without users’ permission, bypassing data loss prevention (DLP) policies and sensitivity/privacy labels designed to prevent Copilot from accessing emails in the first place.

Although inboxes were not affected, Copilot Chat had access to the Sent and Drafts folders, and likely entire email threads within those, which also include incoming emails.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top