PhishML Evaluations Causing PML:BYPASSED Tags to Apply

Incident Report for KnowBe4

Postmortem

On Tuesday, June 30, 2026, from approximately 07:40 to 19:15 (UTC), customers experienced incorrect results from PhishER's PhishML scoring. Affected emails received a PML:BYPASSED tag instead of a legitimate PhishML classification, and confidence scores were missing from impacted messages. Rules and actions that depend on PhishML results also did not activate.

This issue was caused by a code refactor introduced approximately two weeks earlier. This refactor introduced a faulty update that omitted essential drivers required for PhishML scoring to run. However, the issue remained dormant until another update triggered a new PhishML model deployment, which caused the scoring issue to emerge. To resolve this issue, our team rolled back to the last stable deployment and added more capacity to process the resulting backlog of email evaluations. PhishER's PhishML scoring returned to normal performance by 19:15 (UTC).

To prevent this type of issue in the future, we have improved health checks by introducing a new endpoint for smoke testing new models before deployment.

Posted Jul 22, 2026 - 13:20 UTC

Resolved

This incident has been resolved.
Posted Jun 30, 2026 - 19:11 UTC

Monitoring

We’ve implemented a fix for PhishER and we’re monitoring the results to make sure no further issues occur. Impacted messages can be replayed through all rules and actions. Please be aware this could cause duplicate responses to be sent if an action successfully ran during this incident. If you have further questions or concerns please contact our support team directly: https://support.knowbe4.com/hc/en-us/requests/new

 The following Knowledge Base Article contains instructions on how to replay messages: https://support.knowbe4.com/hc/en-us/articles/13169303385619-PhishER-Inbox-Guide#h_01HCNEBF8CJQ98GE9PGM7HGDZ0
Posted Jun 30, 2026 - 15:42 UTC

Investigating

We have identified an issue where PhishML evaluations are causing the "PML:BYPASSED" tag to be applied.
Posted Jun 30, 2026 - 14:18 UTC
This incident affected: PhishER (PhishML).