Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
patch-regressionoperational-disruptionwidely-deployed-product-advisory

Microsoft 365 Disruptions: Exchange Online False-Positive Phishing Blocks and Microsoft Teams Service Degradation

Updated 3mo agoFirst seen Feb 18, 20262 sources

Microsoft reported a Microsoft 365 security-service failure in which Exchange Online anti-phishing heuristics incorrectly classified thousands of legitimate URLs as credential-phishing, leading to quarantined emails, blocked link access, and removal of messages via automated actions (including ZAP) across email and Microsoft Teams. The incident (tracked as EX1227432) ran from Feb 5 to Feb 12 and generated false XDR-style alerts such as “potentially malicious URL click was detected”; Microsoft attributed the impact to a logic error in newly updated heuristic detection, with additional tooling and a separate signature-system bug compounding and delaying rollback.

Separately, Microsoft also worked an active Microsoft Teams outage/service degradation (tracked as TM1233974) affecting some users in the United States and Europe, with delays/failures sending and receiving chats that include inline media and issues joining meetings or signing in. A third item—abuse of Atlassian Jira Cloud notification emails to deliver localized scam lures and redirect victims to casino/investment fraud—describes a distinct threat campaign unrelated to the Microsoft 365 incidents and should be treated as a separate story.

Share:
Microsoft 365 Disruptions: Exchange Online False-Positive Phishing Blocks and Microsoft Teams Service Degradation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Feb 17, 20264mo ago

Microsoft mitigates Teams outage by reverting configuration change

About an hour after reporting the Teams disruption on 2026-02-17, Microsoft said the impact was remediated by reverting a configuration change. The company attributed the outage to a subsection of Teams caching infrastructure falling below performance thresholds.

Microsoft reports Teams service degradation in the US and Europe

On 2026-02-17, Microsoft disclosed incident TM1233974 affecting some Teams users in Europe and the United States, causing access delays and failures, problems joining meetings, signing in, and issues sending or receiving chat messages with inline media. Microsoft also noted separate concurrent Teams incidents affecting meeting joins via the Join button and Copilot Studio agent updates in Teams.

Feb 12, 20264mo ago

Microsoft fully resolves Exchange Online and Teams false-positive blocking incident

On 2026-02-12, Microsoft said it fully resolved incident EX1227432 after rollback efforts were delayed by a separate bug in security signature systems. The company later published a preliminary post-incident report and said a final report would follow within five business days.

Feb 5, 20265mo ago

Faulty anti-phishing rule update begins misclassifying legitimate URLs

On 2026-02-05, a logic error introduced after an update to Exchange Online heuristic detection rules caused thousands of legitimate URLs to be incorrectly classified as phishing. The issue triggered automated URL blocking, message removals, quarantining of legitimate emails, and false security alerts across Exchange Online and Microsoft Teams.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Affected products
3 linked
Exchange OnlineGmailCopilot Studio
Organizations
4 linked
Microsoft CorporationTinesGoogleDowndetector
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft 365 Disruptions: Exchange Online False-Positive Phishing Blocks and Microsoft Teams Service Degradation | Mallory