Quick Facts
- Microsoft Copilot ignored sensitivity labels and DLP policies for four weeks starting January 21, exposing confidential emails
- This marks the second major security breach in eight months, following the EchoLeak vulnerability in June 2025
- The UK’s National Health Service was among affected organizations, though Microsoft has not disclosed the total number impacted
Microsoft’s AI-powered Copilot assistant violated data protection controls twice in eight months, exposing confidential information despite multiple security layers designed to prevent such breaches.
The latest incident, designated CW1226324, ran from January 21 to February 2026. For four weeks, Copilot read and summarized confidential emails marked with sensitivity labels that should have blocked access. Microsoft’s data loss prevention (DLP) stack failed to detect the breach.
Microsoft spokesperson confirmed the company “identified and addressed an issue where Microsoft 365 Copilot Chat could return content from emails labeled confidential authored by a user and stored within their Draft and Sent Items in Outlook desktop.”
The bug occurred because a code-path error allowed messages in Sent Items and Drafts to enter Copilot’s retrieval system despite sensitivity labels and DLP rules, according to Microsoft’s advisory. The company began rolling out a fix in early February and is monitoring deployment while contacting affected customers.
Among the affected organizations was the UK’s National Health Service, which logged the incident as INC46740412. NHS officials indicated that while the system processed draft or sent emails, patient data was not exposed beyond authorized users.
This follows the EchoLeak vulnerability (CVE-2025-32711) discovered in June 2025. That critical flaw, with a CVSS score of 9.3, allowed attackers to extract internal files through prompt injection without user interaction.
The incidents highlight a fundamental challenge with AI-powered enterprise tools. About 90% of Microsoft 365 environments now have access to Copilot, with daily usage around 30%. Recent research shows 67% of enterprise security teams express concerns about AI tools exposing sensitive information.
“Any RAG-based assistant pulling from enterprise data runs through the same pattern: a retrieval layer selects content, an enforcement layer gates what the model can see, and a generation layer produces output,” security researchers noted. “If the enforcement layer fails, the retrieval layer feeds restricted data to the model, and the security stack never sees it.”
The financial services sector has responded with heightened caution. 58% of financial services firms have implemented additional security controls when deploying Copilot. The US House of Representatives banned congressional staff from using Copilot in March due to data security concerns.
Nader Henein, a data protection analyst at Gartner, described these types of errors as “unavoidable” given the rapid rollout of new AI features. Security expert predictions suggest such incidents will surge in 2026, potentially becoming the most frequent type of security incident at companies globally.
Microsoft has not disclosed how many organizations were affected during the four-week exposure window. The company updated Copilot’s protections and implemented additional defense measures to prevent similar breaches.
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
