{
  "meta": {
    "version": "v1",
    "pricing": {
      "public": {
        "label": "Public",
        "description": "Read-only API access for lightweight status checks and public integrations."
      },
      "premium": {
        "label": "Premium",
        "description": "API keys with higher hourly quotas, plus Slack, Discord, webhook, and email outage alerts across your vendor stack."
      }
    },
    "generatedAt": "2026-07-23T14:09:49.541Z"
  },
  "data": {
    "id": "incident_statuspage_knowbe4_ktd1r36b5r4l",
    "slug": "knowbe4-phishml-evaluations-causing-pml-bypassed-tags-to-apply-2026-06-30",
    "title": "PhishML Evaluations Causing PML:BYPASSED Tags to Apply",
    "summary": "PhishML Evaluations Causing PML:BYPASSED Tags to Apply",
    "status": "resolved",
    "severity": "minor",
    "startedAt": "2026-06-30T14:18:11.367+00:00",
    "updatedAt": "2026-07-22T13:20:49.661+00:00",
    "resolvedAt": "2026-06-30T19:11:55.79+00:00",
    "provider": {
      "slug": "knowbe4",
      "name": "KnowBe4"
    },
    "affectedServices": [],
    "links": {
      "html": "/incidents/knowbe4-phishml-evaluations-causing-pml-bypassed-tags-to-apply-2026-06-30",
      "api": "/api/v1/incidents/knowbe4-phishml-evaluations-causing-pml-bypassed-tags-to-apply-2026-06-30",
      "providerHtml": "/providers/knowbe4"
    },
    "impactSummary": "KnowBe4 reported a minor event for the affected tracked services.",
    "source": {
      "id": "source_knowbe4_status",
      "kind": "official_api",
      "name": "KnowBe4 Status",
      "checkedAt": "2026-07-23T14:00:49.613+00:00",
      "officialUrl": "https://status.knowbe4.com",
      "statusPageUrl": "https://status.knowbe4.com"
    },
    "updates": [
      {
        "id": "update_statuspage_knowbe4_ktd1r36b5r4l_rr0h41k36k5r",
        "status": "investigating",
        "body": "We have identified an issue where PhishML evaluations are causing the \"PML:BYPASSED\" tag to be applied.",
        "createdAt": "2026-06-30T14:18:11.458+00:00"
      },
      {
        "id": "update_statuspage_knowbe4_ktd1r36b5r4l_v1wwk525g24k",
        "status": "monitoring",
        "body": "We’ve implemented a fix for PhishER and we’re monitoring the results to make sure no further issues occur. Impacted messages can be replayed through all rules and actions. Please be aware this could cause duplicate responses to be sent if an action successfully ran during this incident. If you have further questions or concerns please contact our support team directly: https://support.knowbe4.com/hc/en-us/requests/new\n\n The following Knowledge Base Article contains instructions on how to replay messages: https://support.knowbe4.com/hc/en-us/articles/13169303385619-PhishER-Inbox-Guide#h_01HCNEBF8CJQ98GE9PGM7HGDZ0",
        "createdAt": "2026-06-30T15:42:58.656+00:00"
      },
      {
        "id": "update_statuspage_knowbe4_ktd1r36b5r4l_hjnzs6sr7n73",
        "status": "resolved",
        "body": "This incident has been resolved.",
        "createdAt": "2026-06-30T19:11:55.79+00:00"
      },
      {
        "id": "update_statuspage_knowbe4_ktd1r36b5r4l_z7fv6j26qnm1",
        "status": "resolved",
        "body": "On Tuesday, June 30, 2026, from approximately 07:40 to 19:15 \\(UTC\\), customers experienced incorrect results from PhishER's PhishML scoring. Affected emails received a PML:BYPASSED tag instead of a legitimate PhishML classification, and confidence scores were missing from impacted messages. Rules and actions that depend on PhishML results also did not activate.\n\nThis issue was caused by a code refactor introduced approximately two weeks earlier. This refactor introduced a faulty update that omitted essential drivers required for PhishML scoring to run. However, the issue remained dormant until another update triggered a new PhishML model deployment, which caused the scoring issue to emerge. To resolve this issue, our team rolled back to the last stable deployment and added more capacity to process the resulting backlog of email evaluations. PhishER's PhishML scoring returned to normal performance by 19:15 \\(UTC\\).\n\nTo prevent this type of issue in the future, we have improved health checks by introducing a new endpoint for smoke testing new models before deployment.",
        "createdAt": "2026-07-22T13:20:19.796+00:00"
      }
    ],
    "access": {
      "plan": "public",
      "keyed": false
    }
  }
}