Microsoft admits an Office bug exposed confidential user emails to Copilot


  • Copilot Chat read sent and draft emails, but the Inbox folder appears to be protected
  • The bug (CW1226324) was identified in January, a fix followed in February
  • Although the fix is ​​rolling out, this is still an ongoing issue

Microsoft has confirmed that a bug in M365 Copilot Chat allowed the AI ​​chatbot to digest confidential emails without users’ permission, bypassing data loss prevention (DLP) policies and sensitivity/confidentiality labels designed to block Copilot from accessing emails in the first place.

Although inboxes were unaffected, Copilot Chat gained access to Sent and Drafts folders and presumably entire threads within them, including incoming emails.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top