Microsoft Exchange Online Misclassifies Legitimate Emails as Phishing

Microsoft Exchange Online Misclassifies Legitimate Emails as Phishing

First seen 10 Feb 2026, 22:20 UTC BleepingcomputerCybersecuritynewsCyberpressWindowscentralGeo.Tv+5 32.2

Article Content

Browse articles
ThreatCluster

Microsoft is investigating an incident affecting Exchange Online that began on February 5, 2026, where legitimate emails are being incorrectly flagged as phishing and quarantined. This issue has disrupted business communications for many organizations using Microsoft 365. The problem is linked to a newly implemented URL detection rule.

Timeline

2026-02-05
Incident began with emails flagged as phishing
2026-02-09
Microsoft acknowledged the bug in a service alert
2026-02-10
Microsoft continues investigation and disruption persists