Sunday, 21 Jun 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • 🔥
  • Trump
  • House
  • White
  • ScienceAlert
  • VIDEO
  • man
  • Trumps
  • Season
  • star
  • Years
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
American Focus > Blog > Tech and Science > Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one
Tech and Science

Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one

Last updated: February 20, 2026 1:00 pm
Share
Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one
SHARE

In a shocking revelation, Microsoft’s AI assistant, Copilot, breached confidentiality protocols by reading and summarizing sensitive emails for a period of four weeks starting on January 21. Despite strict sensitivity labels and Data Loss Prevention (DLP) policies in place to prevent such breaches, Copilot managed to access confidential emails from organizations such as the U.K.’s National Health Service, leading to a major security incident labeled as INC46740412 by the NHS and tracked as CW1226324 by Microsoft.

This incident is not the first of its kind involving Copilot. In June 2025, Microsoft patched a critical zero-click vulnerability, known as CVE-2025-32711 or “EchoLeak,” which allowed malicious emails to bypass Copilot’s security measures and exfiltrate enterprise data without requiring any user interaction. This vulnerability, with a CVSS score of 9.3, highlighted a serious flaw in Copilot’s retrieval pipeline.

The root causes of both incidents, EchoLeak and CW1226324, can be attributed to a code error and a sophisticated exploit chain, respectively. These incidents exposed a fundamental flaw in Copilot’s design, where trusted and untrusted data are processed in the same manner, making the system vulnerable to manipulation.

Endpoint Detection and Response (EDR) and Web Application Firewalls (WAFs) failed to detect these breaches because they were not designed to monitor the specific layer where the violations occurred. Copilot’s retrieval pipeline operates behind an enforcement layer that traditional security tools are unable to observe, leading to a blind spot in the security stack.

To prevent future incidents, security leaders are advised to conduct a five-point audit that includes testing DLP enforcement directly against Copilot, blocking external content from reaching Copilot’s context window, auditing Purview logs for anomalous interactions, enabling Restricted Content Discovery for sensitive SharePoint sites, and developing an incident response playbook for vendor-hosted inference failures.

See also  Alcohol Profoundly Changes The Way Your Brain Communicates, Study Finds : ScienceAlert

The implications of these incidents extend beyond Copilot to any AI assistant that accesses internal data. Organizations must prioritize governance and security controls around AI assistants to mitigate the risk of unauthorized behavior. By implementing the recommended controls and conducting regular audits, organizations can ensure the security and integrity of their sensitive data.

As the deployment of AI assistants continues to grow, it is crucial for organizations to stay vigilant and proactive in safeguarding their data against potential breaches. The five-point audit outlined in this article serves as a roadmap for enhancing security measures and addressing vulnerabilities in AI-driven systems.

TAGGED:CaughtCopilotDLPLabelsMicrosoftMonthssensitivityStack
Share This Article
Twitter Email Copy Link Print
Previous Article Pete Hegseth Accused of ‘Wearing Makeup’ In ‘Embarrassing’ Workout Video Pete Hegseth Accused of ‘Wearing Makeup’ In ‘Embarrassing’ Workout Video
Next Article Beauty That Moves With You Beauty That Moves With You
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.

Popular Posts

Temu Online Marketplace Halts Shipments from China to US as Trump Closes Loophole |

Temu Blocks U.S. Customers from Purchasing Chinese Goods Amid Tariff Changes In a significant policy…

May 4, 2025

A Texas doctor provides healing to patients with vinyl music : NPR

Dr. Tyler Jorgensen, a palliative care doctor at Dell Seton Medical Center, plays a Charlie…

December 22, 2025

Feds likely eyeing ‘cover-ups’ to bust Mexican cartels along border: former DEA agent

Mexican drug cartels have been using sophisticated tunnels equipped with rail and cart systems to…

February 12, 2025

Igloos on Mars? How Future Astronauts Could Use Ice to Survive

Humans dreaming of colonizing Mars have long been faced with the challenge of finding suitable…

December 20, 2025

The Scientist Betting That Worm Secretions Fix Autoimmune Diseases

Welcome to the first edition of the Prototype! Every week, I’ll be sharing the latest…

September 21, 2024

You Might Also Like

Polymarket reportedly paid creators to post deceptive videos about fake bets
Tech and Science

Polymarket reportedly paid creators to post deceptive videos about fake bets

June 21, 2026
We’ve found a mysterious substance on Titan and Pluto
Tech and Science

We’ve found a mysterious substance on Titan and Pluto

June 21, 2026
Ubisoft co-founder Claude Guillemot dies in plane crash
Tech and Science

Ubisoft co-founder Claude Guillemot dies in plane crash

June 21, 2026
I’ve tested Android 17. You’re missing nothing
Tech and Science

I’ve tested Android 17. You’re missing nothing

June 21, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?