Back to News
technology

Microsoft says Office bug exposed customers’ confidential emails to Copilot AI

Zack Whittaker
Loading...
3 min read
0 likes
⚡ Quantum Brief
A critical bug in Microsoft 365 Copilot allowed the AI to access and summarize confidential emails without permission since January 2026, bypassing existing data loss prevention policies. The flaw (tracked as CW1226324) affected draft and sent emails labeled as confidential, exposing content to Copilot’s chat feature in Office apps like Word and Excel for paying customers. Microsoft began rolling out fixes in early February but hasn’t disclosed how many users were impacted or provided further comment on the breach’s scope. The incident follows the European Parliament’s recent ban on AI tools in lawmakers’ devices, citing risks of confidential data being uploaded to cloud services. This underscores growing concerns about AI-driven data leaks, as organizations weigh productivity gains against potential security vulnerabilities in enterprise AI systems.
AI Audio Summary
0:00 / 0:00
Click to play
Untitled design (38).png
Quantum News · Media Library

In Brief Posted: 6:44 AM PST · February 18, 2026 Image Credits:Rafael Henrique/SOPA Images/LightRocket / Getty Images Zack Whittaker Microsoft says Office bug exposed customers’ confidential emails to Copilot AI Microsoft has confirmed that a bug allowed its Copilot AI to summarize customers’ confidential emails for weeks without permission. The bug, first reported by Bleeping Computer, allowed Copilot Chat to read and outline the contents of emails since January, even if customers had data loss prevention policies to prevent ingesting their sensitive information into Microsoft’s large language model. Copilot Chat allows paying Microsoft 365 customers to use the AI-powered chat feature in its Office software products, including Word, Excel, and PowerPoint. Microsoft said the bug, trackable by admins as CW1226324, means that draft and sent email messages “with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat.” The tech giant said it began rolling out a fix for the bug earlier in February. A spokesperson for Microsoft did not respond to a request for comment, including a question about how many customers are affected by the bug. Earlier this week, the European Parliament’s IT department told lawmakers that it blocked the built-in AI features on their work-issued devices, citing concerns that the AI tools could upload potentially confidential correspondence to the cloud. Topics AI, AI, chatbot, Copilot, cybersecurity, data protection, Microsoft, Security October 13-15 San Francisco, CA Tickets are live at the lowest rates of the year. Save up to $680 on your pass now.Meet investors. Discover your next portfolio company. Hear from 250+ tech leaders, dive into 200+ sessions, and explore 300+ startups building what’s next. Don’t miss these one-time savings. REGISTER NOW Newsletters See More Subscribe for the industry’s biggest tech news TechCrunch Daily News Every weekday and Sunday, you can get the best of TechCrunch’s coverage. TechCrunch Mobility TechCrunch Mobility is your destination for transportation news and insight.

Startups Weekly Startups are the core of TechCrunch, so get our best coverage delivered weekly. StrictlyVC Provides movers and shakers with the info they need to start their day. No newsletters selected. Subscribe By submitting your email, you agree to our Terms and Privacy Notice.

Related Startups Kana emerges from stealth with $15M to build flexible AI agents for marketers Ram Iyer 36 minutes ago Security European Parliament blocks AI on lawmakers’ devices, citing security risks Zack Whittaker 23 hours ago AI Adani pledges $100B to build AI data centers as India seeks bigger role in the global AI race Jagmeet Singh 1 day ago Latest in Security Fundraising This former Microsoft PM thinks she can unseat CyberArk in 18 months Connie Loizos 45 minutes ago In Brief Microsoft says Office bug exposed customers’ confidential emails to Copilot AI Zack Whittaker 1 hour ago Security Intellexa’s Predator spyware used to hack iPhone of journalist in Angola, research says Lorenzo Franceschi-Bicchierai 16 hours ago

Read Original

Tags

startup

Source Information

Source: TechCrunch

Discussion

0 professional contributions

Sign in to join this professional discussion.

Be the first to add a constructive contribution.