Wednesday, 22 Apr 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • 🔥
  • Trump
  • House
  • ScienceAlert
  • White
  • VIDEO
  • man
  • Trumps
  • Season
  • star
  • Years
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
American Focus > Blog > Tech and Science > Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one
Tech and Science

Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one

Last updated: February 20, 2026 1:00 pm
Share
Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one
SHARE

In a shocking revelation, Microsoft’s AI assistant, Copilot, breached confidentiality protocols by reading and summarizing sensitive emails for a period of four weeks starting on January 21. Despite strict sensitivity labels and Data Loss Prevention (DLP) policies in place to prevent such breaches, Copilot managed to access confidential emails from organizations such as the U.K.’s National Health Service, leading to a major security incident labeled as INC46740412 by the NHS and tracked as CW1226324 by Microsoft.

This incident is not the first of its kind involving Copilot. In June 2025, Microsoft patched a critical zero-click vulnerability, known as CVE-2025-32711 or “EchoLeak,” which allowed malicious emails to bypass Copilot’s security measures and exfiltrate enterprise data without requiring any user interaction. This vulnerability, with a CVSS score of 9.3, highlighted a serious flaw in Copilot’s retrieval pipeline.

The root causes of both incidents, EchoLeak and CW1226324, can be attributed to a code error and a sophisticated exploit chain, respectively. These incidents exposed a fundamental flaw in Copilot’s design, where trusted and untrusted data are processed in the same manner, making the system vulnerable to manipulation.

Endpoint Detection and Response (EDR) and Web Application Firewalls (WAFs) failed to detect these breaches because they were not designed to monitor the specific layer where the violations occurred. Copilot’s retrieval pipeline operates behind an enforcement layer that traditional security tools are unable to observe, leading to a blind spot in the security stack.

To prevent future incidents, security leaders are advised to conduct a five-point audit that includes testing DLP enforcement directly against Copilot, blocking external content from reaching Copilot’s context window, auditing Purview logs for anomalous interactions, enabling Restricted Content Discovery for sensitive SharePoint sites, and developing an incident response playbook for vendor-hosted inference failures.

See also  iMac "Pro" 27 pouces : date de sortie, prix et autres rumeurs

The implications of these incidents extend beyond Copilot to any AI assistant that accesses internal data. Organizations must prioritize governance and security controls around AI assistants to mitigate the risk of unauthorized behavior. By implementing the recommended controls and conducting regular audits, organizations can ensure the security and integrity of their sensitive data.

As the deployment of AI assistants continues to grow, it is crucial for organizations to stay vigilant and proactive in safeguarding their data against potential breaches. The five-point audit outlined in this article serves as a roadmap for enhancing security measures and addressing vulnerabilities in AI-driven systems.

TAGGED:CaughtCopilotDLPLabelsMicrosoftMonthssensitivityStack
Share This Article
Twitter Email Copy Link Print
Previous Article Pete Hegseth Accused of ‘Wearing Makeup’ In ‘Embarrassing’ Workout Video Pete Hegseth Accused of ‘Wearing Makeup’ In ‘Embarrassing’ Workout Video
Next Article Beauty That Moves With You Beauty That Moves With You
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.

Popular Posts

Vance says Trump ‘may’ take further action to end Iran’s nuclear enrichment

Donald Trump Considering Further Action to Stop Iran's Uranium EnrichmentVice-president JD Vance suggested on Tuesday…

June 17, 2025

West Texas Measles Cases Threaten Elimination Status in the U.S. Here’s Why That Matters

Additionally, there has been a rise in the anti-vaccine movement, fueled by misinformation and fear…

May 17, 2025

Loving In Your Radiant Season? Here are 9 K-dramas to add to your watchlist

In Your Radiant Season, featuring Lee Sung-kyung and Chae Jong-hyeop, tells a reflective tale centered…

March 16, 2026

Autobiography Poem Template Bundle (Free Printable Worksheets)

Writing poetry can often seem like a daunting endeavor, but when the subject matter is…

March 13, 2026

Freya Dalsjø Copenhagen Fall 2026 Collection

Fall Fashion: Freya Dalsjø's CollectionFreya Dalsjø's fall collection is a study in simplicity with a…

February 1, 2026

You Might Also Like

Oppo Find X9 Ultra: Release Date, Price and Features
Tech and Science

Oppo Find X9 Ultra: Release Date, Price and Features

April 21, 2026
If a bird flu pandemic starts, we may have an mRNA vaccine ready
Tech and Science

If a bird flu pandemic starts, we may have an mRNA vaccine ready

April 21, 2026
Oppo Find X9 Ultra Hands-on: 3 Things I Love, and 1 I Hate
Tech and Science

Oppo Find X9 Ultra Hands-on: 3 Things I Love, and 1 I Hate

April 21, 2026
EHR Implementation Process Guide: Framework, Steps & Costs
Tech and Science

EHR Implementation Process Guide: Framework, Steps & Costs

April 21, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?