Article Details

Scrape Timestamp (UTC): 2024-08-26 19:49:32.845

Source: https://www.theregister.com/2024/08/26/microsoft_365_email_malware/

Original Article Text

Click to Toggle View

Microsoft mistake blows up admins' inboxes with fake malware alerts. Legitimate emails misclassified in software snafu. Many administrators have had a trying Monday after getting spammed out with false malware reports by Microsoft. In the last hour the Microsoft 365 service center put out an alert on Xitter, oddly, even before sending out the customary 365 Service Alert email, users complained. Others pointed out that the issue was flagged up on reddit more than two hours before Microsoft got around to alerting customers. "We're investigating an issue in which some users' email messages may be incorrectly flagged as malware and quarantined. More info can be found in the admin center under EX873252," Microsoft posted. "We identified an issue affecting our malware detection systems. We've implemented a mitigation to unblock legitimate emails that were mistakenly quarantined. The replay of impacted emails is in progress." For the moment it seems admins will have to manually unblock legitimate emails. Given the volume of material, and the need for care not to let actual malware through, this might take some time. It also appears that the original EX873252 article has been taken down, although you can see it here. The issue appears to have kicked off around 0900 ET (1300 UTC), and Britain's National Health Service issued an alert a few hours later. Redmond has reportedly said it is fixing the problem but, while many are reporting the flood of false positives has eased, it doesn't appear that the issue is fully resolved as yet. One amateur sysadmin sleuth suggests it's down to an issue with the Microsoft Defender Threat Explorer and the PowerShell Get-QuarantineMessage cmdlet. We'll update this piece when there's a solid statement from Microsoft.

Daily Brief Summary

MISCELLANEOUS // Microsoft Error Triggers False Malware Alerts, Floods Admins

Microsoft experienced a software issue that misclassified legitimate emails as malware, causing false alerts.

Administrators reported receiving a high volume of these false malware notifications, complicating their workload.

The problem was first noticed and reported by users on reddit before Microsoft issued an official notification on its service channel.

Microsoft acknowledged the issue on Xitter and their service alert, citing difficulties with their malware detection systems and implemented a mitigation strategy.

The fix involves manually unblocking the legitimate emails which were incorrectly quarantined, a process that could be time-intensive due to the volume and security risks.

Microsoft's communication stated that a replay of impacted emails was underway, although the resolution to the issue was still incomplete.

Further updates are anticipated from Microsoft to confirm the resolution of the problem, which began affecting users around 0900 ET.