Provider
KnowBe4Incident detail
PhishML Evaluations Causing PML:BYPASSED Tags to Apply
Timeline window
to
Outage alerts
Get alerted the next time KnowBe4 breaks
Free email alerts for up to 5 providers — no card, live in about a minute. Paid plans add Slack, Discord, and webhook delivery across your whole stack, plus higher API quotas.
Timeline
Incident updates
Updates are normalized from the official source chronology so timeline changes remain easy to scan.
Investigating
We have identified an issue where PhishML evaluations are causing the "PML:BYPASSED" tag to be applied.
Monitoring
We’ve implemented a fix for PhishER and we’re monitoring the results to make sure no further issues occur. Impacted messages can be replayed through all rules and actions. Please be aware this could cause duplicate responses to be sent if an action successfully ran during this incident. If you have further questions or concerns please contact our support team directly: https://support.knowbe4.com/hc/en-us/requests/new
The following Knowledge Base Article contains instructions on how to replay messages: https://support.knowbe4.com/hc/en-us/articles/13169303385619-PhishER-Inbox-Guide#h_01HCNEBF8CJQ98GE9PGM7HGDZ0
Resolved
This incident has been resolved.
Resolved
On Tuesday, June 30, 2026, from approximately 07:40 to 19:15 (UTC), customers experienced incorrect results from PhishER's PhishML scoring. Affected emails received a PML:BYPASSED tag instead of a legitimate PhishML classification, and confidence scores were missing from impacted messages. Rules and actions that depend on PhishML results also did not activate.
This issue was caused by a code refactor introduced approximately two weeks earlier. This refactor introduced a faulty update that omitted essential drivers required for PhishML scoring to run. However, the issue remained dormant until another update triggered a new PhishML model deployment, which caused the scoring issue to emerge. To resolve this issue, our team rolled back to the last stable deployment and added more capacity to process the resulting backlog of email evaluations. PhishER's PhishML scoring returned to normal performance by 19:15 (UTC).
To prevent this type of issue in the future, we have improved health checks by introducing a new endpoint for smoke testing new models before deployment.