Story perspectives
Microsoft 365 Bug Exposes Confidential Emails, Fix Rolling Out
2/20/2026
1 of 2
Story summary
- Microsoft confirmed a bug in its 365 Copilot, CW1226324, identified on January 21, 2026, that allowed unauthorized access to confidential Outlook emails by bypassing Data Loss Prevention policies.
- The flaw affected emails in Sent Items and Drafts, including confidential ones.
- Microsoft began rolling out a fix in February.
- The number of affected users or organizations has not been disclosed.
- The European Parliament has disabled AI tools on official devices.
1 / 2
