Legitimate emails being marked as phish in Adaptive Email Security
Resolved·Degraded performance

The issue of safe URLs being incorrectly flagged on inbound and internal emails has now been resolved and classification of emails has returned to normal. Customers wishing for release of all emails that were quarantined within the impacted timeframe should raise a request to tessian-support@proofpoint.com.

The availability of manual release of emails from the portal has been intermittent due to the increased load on our systems but has now been resolved. A limited event view may be shown in some cases to allow the email to be remediated.

Wed, Feb 12, 2025, 06:17 PM
(4 months ago)
·
Affected components
Updates

Resolved

The issue of safe URLs being incorrectly flagged on inbound and internal emails has now been resolved and classification of emails has returned to normal. Customers wishing for release of all emails that were quarantined within the impacted timeframe should raise a request to tessian-support@proofpoint.com.

The availability of manual release of emails from the portal has been intermittent due to the increased load on our systems but has now been resolved. A limited event view may be shown in some cases to allow the email to be remediated.

Wed, Feb 12, 2025, 06:17 PM

Monitoring

The situation remains stable, with no new URL's being incorrectly flagged. The team are still assessing options to re-process emails affected by the incident, but this will take time. For customers experiencing issues viewing events in the portal, we are seeing steady improvements when loading events. In the meantime, we recommend manually reviewing and releasing emails where possible. Thank you for your patience, we'll continue to share updates as progress is made.

Tue, Feb 11, 2025, 05:29 PM(1 day earlier)

Monitoring

As of approximately 6:00 AM UTC there should be no more emails incorrectly flagged as phishing because of the corrupted rule - the team is continuing to monitor the incident. Any edits made to Adaptive Email Security filters because of this incident can now be reverted. We are assessing the options for remediation of emails incorrectly flagged as phishing during this incident and will update once a decision has been made.

Tue, Feb 11, 2025, 10:09 AM(7 hours earlier)

Identified

The team continues to make progress identifying URLs impacted by the initial incident and remediating each in turn, but an ETA on when this will be complete is not yet available. We are also looking into additional remediation steps for emails incorrectly flagged as Phish as a part of this incident, and will update once we have more information.

Tue, Feb 11, 2025, 05:34 AM(4 hours earlier)

Identified

The team has identified a bad rule in the Proofpoint integration which incorrectly flagged URLs as Phish. The issue with the corrupted rule has been resolved, and Proofpoint is working to identify and resolve all URLs incorrectly flagged.

Tue, Feb 11, 2025, 03:28 AM(2 hours earlier)

Investigating

We currently have elevated rates of legitimate emails being marked for phish. Customers may observe some legitimate emails containing specific URLs are being flagged and actioned based off their configuration.
The team is currently investigating to understand the cause and take immediate steps to mitigate.

Tue, Feb 11, 2025, 03:00 AM(28 minutes earlier)
Powered by