<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>KnowBe4 incidents — Vendor Status Watch</title><link>https://approjects-vendor-status-watch.static.hf.space/v/knowbe4.html</link><description>Incidents from KnowBe4's public status page, polled daily.</description><lastBuildDate>Wed, 16 Sep 2026 12:28:20 +0000</lastBuildDate><item><title>Defend | Emails Not Being Rendered in Classic Outlook [resolved]</title><link>https://stspg.io/p788lzy5p9z9</link><guid isPermaLink="false">knowbe4:2026-09-08T07:00:00.000Z</guid><pubDate>Tue, 08 Sep 2026 07:00:00 +0000</pubDate><description>On Septermber 8th we made aware that inbound HTML emails rendered partially or blank in Classic Outlook due to a routine HTML library upgrade in Defend&#x27;s harmful-code-removal engine interacting with Classic Outlook&#x27;s legacy Word rendering engine. New Outlook and Outlook on the web were unaffected. This was strictly a display issue: no email was delayed, lost, or compromised, and threat detection remained fully active. Engineering has reverted the update to restore normal rendering. If you temporarily disabled harmful-code removal during this window, please re-enable it to ensure complete protection.</description></item><item><title>Workspace | Email MFA Verification Issues [resolved]</title><link>https://stspg.io/qk3mw5plt3kg</link><guid isPermaLink="false">knowbe4:2026-09-04T10:53:59.000Z</guid><pubDate>Fri, 04 Sep 2026 10:53:59 +0000</pubDate><description>This incident has been resolved.</description></item><item><title>PhishER - Message Processing Delays [resolved]</title><link>https://stspg.io/lv4v7whd9w20</link><guid isPermaLink="false">knowbe4:2026-08-26T16:19:52.231Z</guid><pubDate>Wed, 26 Aug 2026 16:19:52 +0000</pubDate><description>Our engineering team has implemented a fix for the issue that causing message processing delays in PhishER.</description></item><item><title>PAB | Error Reporting Phish using Gmail Phish Alert Button [postmortem]</title><link>https://stspg.io/97cd088qr41p</link><guid isPermaLink="false">knowbe4:2026-08-21T08:52:22.748Z</guid><pubDate>Fri, 21 Aug 2026 08:52:22 +0000</pubDate><description>On Friday, August 21, 2026, from approximately 05:20 to 12:55 \(UTC\), some customers experienced intermittent failures when using the Gmail Phish Alert Button add-in to report suspicious emails, receiving the &quot;An internal error has occurred&quot; message instead of a successful report confirmation. The issue affected customers across all regions, with the highest error volumes concentrated in the EU-West and US-East service regions.

This issue was caused by a disruption in a caching service on Google&#x27;s Apps Script platform, which the add-in relies on to store per-user session configuration. The service began intermittently returning empty results on read while still accepting new writes, causing affected report submissions to fail. KnowBe4 engaged Google directly and filed a formal bug report</description></item><item><title>PAB sending a Non-Delivery Report after an Email is Reported (US Only) [resolved]</title><link>https://stspg.io/p1k0h84nj514</link><guid isPermaLink="false">knowbe4:2026-08-18T14:29:27.958Z</guid><pubDate>Tue, 18 Aug 2026 14:29:27 +0000</pubDate><description>This incident has been resolved.</description></item><item><title>Google Workspace PhishRIP errors [resolved]</title><link>https://stspg.io/pbn7ggjs3kgd</link><guid isPermaLink="false">knowbe4:2026-08-05T19:29:46.279Z</guid><pubDate>Wed, 05 Aug 2026 19:29:46 +0000</pubDate><description>Upon further investigation we have determined that the errors affecting Google PhishRIP queries were related to individual issues on Google accounts.</description></item><item><title>SAT Account Settings not Loading [resolved]</title><link>https://stspg.io/sdc4j1sg5f6l</link><guid isPermaLink="false">knowbe4:2026-08-04T19:19:15.607Z</guid><pubDate>Tue, 04 Aug 2026 19:19:15 +0000</pubDate><description>This incident has been resolved.</description></item><item><title>Unexpected Emails being quarantined by PhishRIP [postmortem]</title><link>https://stspg.io/xn4ddvjkjgm7</link><guid isPermaLink="false">knowbe4:2026-07-28T20:00:15.608Z</guid><pubDate>Tue, 28 Jul 2026 20:00:15 +0000</pubDate><description>## **Summary**

On July 28, 2026, an update to the PhishRIP service caused some PhishRIP search queries to match more broadly than they should have. Benign emails that didn&#x27;t meet the configured sender criteria were quarantined across some customer accounts.

Automated monitoring and customer support tickets surfaced the problem quickly. Engineering reverted the change within approximately 25 minutes of declaring the incident and stopped the unintended quarantining. Engineering then manually restored the incorrectly quarantined emails to customers’ inboxes.

## **Root cause**

On July 28, 2026, we deployed a maintenance update to the query service behind PhishRIP. This update was designed to improve the handling of invalid sender addresses by allowing the system to fall back to searching o</description></item><item><title>Protect blank purchasing page on store.knowbe4.com [resolved]</title><link>https://stspg.io/cddcxl6t1s55</link><guid isPermaLink="false">knowbe4:2026-07-17T13:18:28.786Z</guid><pubDate>Fri, 17 Jul 2026 13:18:28 +0000</pubDate><description>This incident has been resolved.</description></item><item><title>Defend - Redirect Upon Login [postmortem]</title><link>https://stspg.io/btwk3mml7w2v</link><guid isPermaLink="false">knowbe4:2026-07-16T19:48:18.636Z</guid><pubDate>Thu, 16 Jul 2026 19:48:18 +0000</pubDate><description>On Thursday, July 16, 2026, from approximately 19:57 to 21:12 \(UTC\), some customers experienced difficulty logging in to the Defend console, seeing a **Find Out More** screen instead of console access.

This issue was caused by a synchronization issue between Salesforce and our internal licensing systems, which incorrectly set some customer license counts to zero. As a result, affected customers were unable to log in. To resolve this issue, our team applied a temporary license override to restore access for affected customers while correcting the underlying licensing records in Salesforce. Once corrected, the systems automatically synchronized the accurate values, and the Defend console access returned to normal performance by approximately 21:12 \(UTC\).

To prevent this type of issue i</description></item><item><title>Protect blank purchasing page on store.knowbe4.com [resolved]</title><link>https://stspg.io/gn0q3mjn62z8</link><guid isPermaLink="false">knowbe4:2026-07-15T16:46:33.000Z</guid><pubDate>Wed, 15 Jul 2026 16:46:33 +0000</pubDate><description>This incident has been resolved.</description></item><item><title>PhishML Degradation [resolved]</title><link>https://stspg.io/fnqbqws7cr8v</link><guid isPermaLink="false">knowbe4:2026-07-10T14:30:00.000Z</guid><pubDate>Fri, 10 Jul 2026 14:30:00 +0000</pubDate><description>An upstream feature flag service issue degraded model routing in collaboration-inference, causing PhishML evaluations to return 0/0/0 default errors. The third party deployed a fix, and a code update was deployed to production adding static fallback routing.
All services have recovered and are operating normally.</description></item><item><title>KSAT Intermittent Login Issues - US [postmortem]</title><link>https://stspg.io/k9xxcyp7v05w</link><guid isPermaLink="false">knowbe4:2026-07-01T14:40:41.868Z</guid><pubDate>Wed, 01 Jul 2026 14:40:41 +0000</pubDate><description>## **Executive Summary**

On July 1, 2026, the KnowBe4 Security Awareness Training \(KSAT\) platform experienced a period of degraded performance resulting in intermittent login errors and high latency for users on our United States \(US\) instance. The issue was initiated following a routine platform deployment that introduced an unoptimized database query. This query placed an excessive operational load on our primary database reader cluster, causing database sessions to saturate and subsequent login requests to queue up.

Engineering teams promptly identified the degradation, reverted the deployment, and systematically cleared the backlogged database sessions to restore optimal performance. The issue did not affect data integrity or security, and service was fully stabilized.

## **Tech</description></item><item><title>Defend - Increased Email Latency (US Only) [postmortem]</title><link>https://stspg.io/5s14r8s5mq15</link><guid isPermaLink="false">knowbe4:2026-06-30T16:14:53.577Z</guid><pubDate>Tue, 30 Jun 2026 16:14:53 +0000</pubDate><description>#### Summary

On June 30, 2026, customers using the Defend US service experienced delays in email processing. The incident began at approximately 14:00 UTC and was fully resolved by 19:45 UTC.

‌

#### What Happened

A scheduled maintenance operation began in the early morning of June 30. As this operation progressed, it placed an unexpectedly high load on our infrastructure, which caused email processing to slow down across our US service.

‌

Our team identified the issue and declared an incident at 16:00 UTC. Steps were taken to reduce the load and restore normal processing speeds, including pausing non-essential background activity and engaging our infrastructure provider for additional support.

‌

By 17:45 UTC, email delivery delays had been fully resolved. Email analysis continued t</description></item><item><title>PhishML Evaluations Causing PML:BYPASSED Tags to Apply [postmortem]</title><link>https://stspg.io/xt1mc4pk5tdn</link><guid isPermaLink="false">knowbe4:2026-06-30T14:18:11.378Z</guid><pubDate>Tue, 30 Jun 2026 14:18:11 +0000</pubDate><description>On Tuesday, June 30, 2026, from approximately 07:40 to 19:15 \(UTC\), customers experienced incorrect results from PhishER&#x27;s PhishML scoring. Affected emails received a PML:BYPASSED tag instead of a legitimate PhishML classification, and confidence scores were missing from impacted messages. Rules and actions that depend on PhishML results also did not activate.

This issue was caused by a code refactor introduced approximately two weeks earlier. This refactor introduced a faulty update that omitted essential drivers required for PhishML scoring to run. However, the issue remained dormant until another update triggered a new PhishML model deployment, which caused the scoring issue to emerge. To resolve this issue, our team rolled back to the last stable deployment and added more capacity t</description></item><item><title>KCM GRC - 500 Errors Upon Login [postmortem]</title><link>https://stspg.io/blhxy7cq7jsc</link><guid isPermaLink="false">knowbe4:2026-06-24T15:48:26.151Z</guid><pubDate>Wed, 24 Jun 2026 15:48:26 +0000</pubDate><description>From Tuesday, June 23, 2026, at approximately 10:03 \(UTC\) to Thursday, June 25, 2026, at approximately 11:54 \(UTC\), some US and EU customers experienced intermittent 502 errors when logging in to KCM GRC.

This issue was caused by network traffic attempting to connect to invalid multilevel subdomains, which overwhelmed the cache serving KCM GRC and resulted in login errors. Our team initially updated the configuration of our content delivery network, which temporarily resolved the errors, but they returned later that day. After further investigation, we identified the caching issue as the root cause and deployed an infrastructure-level fix to prevent multi-level subdomain traffic from affecting the cache. KCM GRC returned to normal performance by 11:54 \(UTC\) on June 25, 2026.

To pre</description></item><item><title>Phishing test report tab unavailable [postmortem]</title><link>https://stspg.io/4gtp2g55nxc4</link><guid isPermaLink="false">knowbe4:2026-06-18T21:14:38.770Z</guid><pubDate>Thu, 18 Jun 2026 21:14:38 +0000</pubDate><description>From Tuesday, June 16, 2026, at approximately 17:34 \(UTC\), to Thursday, June 18, 2026, at approximately 22:41 \(UTC\), some customers experienced intermittent unavailability of the **Phishing Security Test Reports** page in the KnowBe4 console.

This issue was caused by a code change that introduced a conflict between two methods for processing phishing campaign data. As a result, phishing campaigns still using legacy phishing categories were unable to load the **Phishing Security Test Reports** page. To resolve this issue, we updated the code to process campaigns correctly under both classification systems, and the **Phishing Security Test Reports** page returned to normal performance by June 18, 2026, at 22:41 \(UTC\).

No data loss occurred as a result of this issue.</description></item><item><title>KnowBe4 Security Center (KSC) | Human Risk Managment Widget Showing No Results [postmortem]</title><link>https://stspg.io/m5t4dpw6q2j1</link><guid isPermaLink="false">knowbe4:2026-06-18T15:13:09.435Z</guid><pubDate>Thu, 18 Jun 2026 15:13:09 +0000</pubDate><description>From Wednesday, June 17, 2026, at approximately 19:00 \(UTC\), to Thursday, June 18, 2026, at approximately 18:20 \(UTC\), some customers were unable to view results in the KnowBe4 Security Center’s Human Risk Management widget.

‌

This issue was caused by a recent infrastructure migration that left an internal service connection pointing to an outdated endpoint. Though the underlying data processing was unaffected, the Human Risk Management widget could not retrieve data or display results. To resolve this issue, our team updated and reapplied the connection configuration, and the KnowBe4 Security Center returned to normal performance by approximately 18:20 \(UTC\) on June 18, 2026.

To prevent this type of issue in the future, we are improving our migration process to ensure that all en</description></item><item><title>Data and User Inconsistencies in Reporting [postmortem]</title><link>https://stspg.io/4tkf5xjd4z79</link><guid isPermaLink="false">knowbe4:2026-06-16T22:23:16.540Z</guid><pubDate>Tue, 16 Jun 2026 22:23:16 +0000</pubDate><description>From Tuesday, June 16, 2026, at approximately 22:23 \(UTC\), to Wednesday, June 17, 2026, at approximately 20:19 \(UTC\), some customers experienced inaccurate user counts in KSAT reporting. Downstream features that rely on this data were also affected, including AIDA Orchestration, Risk Score, and ModStore recommendations.

This issue was caused by an incomplete rebuild of the users&#x27; data table. A data storage policy removed historical data earlier than intended, so when a full table rebuild ran, some older data was unavailable, causing user counts to drop. To resolve this issue, our team performed a full data migration sync on the users&#x27; table and retriggered the dependent data pipelines to update downstream systems. We then tested and confirmed that user counts were returning correct re</description></item><item><title>Latency Issues [postmortem]</title><link>https://stspg.io/k39rjhspld1r</link><guid isPermaLink="false">knowbe4:2026-06-15T16:56:34.054Z</guid><pubDate>Mon, 15 Jun 2026 16:56:34 +0000</pubDate><description>On Monday, June 15, 2026, from approximately 15:30 to 16:34 \(UTC\), some customers experienced processing delays with phishing and training campaigns in the KnowBe4 console.

This issue was caused by an update that introduced an incompatible software version. This software prevented our background processing service from completing queued tasks. As a result, training enrollments, notification sending, and SmartGgroup enrollments were delayed. To resolve this issue, our team deployed a fix that reverted the affected dependency and restored normal job processing. Once the fix was deployed, the affected queues cleared, and the KnowBe4 console returned to normal performance by 16:34 \(UTC\).

To prevent this issue in the future, we have implemented additional testing layers for similar deploy</description></item><item><title>KSAT - Widespread User Profile Access Issues [postmortem]</title><link>https://stspg.io/bxsdm75mg6kq</link><guid isPermaLink="false">knowbe4:2026-06-03T15:07:44.987Z</guid><pubDate>Wed, 03 Jun 2026 15:07:44 +0000</pubDate><description>On Wednesday, June 3, 2026, from approximately 14:49 to 16:09 \(UTC\), customers experienced errors when accessing the **User Details** page in the KSAT console.

This issue was caused by an update that introduced missing fields, which prevented the **User Details** page from loading. To resolve this issue, our team updated the console again to restore the missing fields, and the KSAT console returned to normal performance by approximately 16:09 \(UTC\). To prevent similar issues in the future, additional automated tests were added.

No data loss occurred as a result of this issue.</description></item><item><title>Unable to upload custom content to the new Modstore [postmortem]</title><link>https://stspg.io/gxmg8ggjlr0p</link><guid isPermaLink="false">knowbe4:2026-05-28T18:17:52.922Z</guid><pubDate>Thu, 28 May 2026 18:17:52 +0000</pubDate><description>On Thursday, May 28, 2026, from approximately 18:07 to 18:57 \(UTC\), some customers experienced issues uploading custom content to the new ModStore in KnowBe4 Security Awareness Training \(KSAT\).

This issue was caused by an update to the new ModStore that disabled the language selection field in the “Add Translation” upload step, preventing customers from completing that required part of the upload process. To resolve this issue, our engineering team identified the recent deployment responsible for the defect, corrected it, and deployed the update to production. KSAT returned to normal performance by 18:57 \(UTC\).

To prevent this type of issue in the future, we are improving test coverage for the affected upload flow and adding automated checks to catch similar issues before they reac</description></item><item><title>Protect -  Intermittent Issues with Sending Emails (UK Only) [resolved]</title><link>https://stspg.io/g73wyjkt9zm9</link><guid isPermaLink="false">knowbe4:2026-05-27T10:05:45.801Z</guid><pubDate>Wed, 27 May 2026 10:05:45 +0000</pubDate><description>This incident has been resolved.</description></item><item><title>New Modstore 500 Errors [postmortem]</title><link>https://stspg.io/nxp2k09gjg8s</link><guid isPermaLink="false">knowbe4:2026-05-21T13:40:58.947Z</guid><pubDate>Thu, 21 May 2026 13:40:58 +0000</pubDate><description># **Summary**

On Wednesday, May 21, 2026, customers using the new ModStore experience within KnowBe4 Security Awareness Training \(KSAT\) were unable to access the ModStore and received HTTP 500 errors. The disruption affected all regional instances and lasted approximately 23 minutes, from 13:17 to 13:40 \(UTC\).

This issue was caused by a defective code change in a routine ModStore deployment. The deployment itself completed successfully, but the change caused the application to return server errors when customers attempted to load the new ModStore. Our engineering team identified the faulty deployment within minutes, rolled it back, and confirmed full restoration of service at 13:40 \(UTC\).

Only the new ModStore experience was affected. Customers using the classic ModStore, and all </description></item><item><title>Microsoft Ribbon PAB Operation Timeout [postmortem]</title><link>https://stspg.io/fltk6zvgb6j9</link><guid isPermaLink="false">knowbe4:2026-05-19T14:16:44.172Z</guid><pubDate>Tue, 19 May 2026 14:16:44 +0000</pubDate><description>From Monday, May 18, 2026, at approximately 14:00 \(UTC\), to Tuesday, May 19, 2026, at approximately 15:00 \(UTC\), users experienced timeouts when attempting to use the Microsoft Ribbon Phish Alert Button \(PAB\) in Classic Outlook.

This issue was caused by an update to the PAB&#x27;s authentication process that was incompatible with the Classic Outlook environment. The update used a loading method that Classic Outlook does not support, which caused the PAB to time out before it could connect to KnowBe4&#x27;s servers. 

To resolve this issue, we updated how the authentication library is packaged with the PAB to ensure compatibility with Classic Outlook. The Microsoft Ribbon PAB returned to normal performance by approximately 15:00 \(UTC\) on May 19, 2026.

To prevent this type of issue in the fu</description></item><item><title>KSAT Latency Issues [resolved]</title><link>https://stspg.io/r0f7y6z1nz4w</link><guid isPermaLink="false">knowbe4:2026-05-18T17:28:51.875Z</guid><pubDate>Mon, 18 May 2026 17:28:51 +0000</pubDate><description>Our team has identified and resolved the issue causing latency with the KSAT console</description></item><item><title>KnowBe4 Academy - Access Issues [postmortem]</title><link>https://stspg.io/3t1tx2yfyldc</link><guid isPermaLink="false">knowbe4:2026-05-13T18:09:24.097Z</guid><pubDate>Wed, 13 May 2026 18:09:24 +0000</pubDate><description>On Wednesday, May 13, 2026, from approximately 18:00 until 18:45 \(UTC\), some users experienced issues with accessing the KnowBe4 Academy.  

This incident was caused by a service disruption with an external service provider. The provider restored service and the Academy returned to normal performance by 18:45 \(UTC\).

No data loss occurred as a result of this issue.</description></item><item><title>Unable to upload items on Workspace - US [postmortem]</title><link>https://stspg.io/3hg37wvr9vp1</link><guid isPermaLink="false">knowbe4:2026-05-12T10:52:31.827Z</guid><pubDate>Tue, 12 May 2026 10:52:31 +0000</pubDate><description>On Tuesday, May 12, 2026, from approximately 10:12 until 11:43 \(UTC\), some US customers experienced issues while attempting to upload files or process data within the Workspace console.

This incident was caused by a networking disruption that affected a backend messaging service, preventing it from properly syncing data. While file downloads remained available, new file uploads and certain background tasks were blocked. To resolve this issue, we temporarily paused new network traffic and restored the messaging service. The Workspace console returned to normal performance by 11:43 \(UTC\).

To prevent this type of issue in the future, we are reviewing our messaging service configuration and improving network monitoring to more quickly identify synchronization issues.

No data loss occurr</description></item><item><title>PhishER - Unable to Login (US) [postmortem]</title><link>https://stspg.io/tt7wn4r4953b</link><guid isPermaLink="false">knowbe4:2026-05-08T02:05:27.831Z</guid><pubDate>Fri, 08 May 2026 02:05:27 +0000</pubDate><description>On Friday, May 8, 2026, from approximately 01:45 to 03:08 \(UTC\), some US customers experienced issues accessing the PhishER console and PasswordIQ.

This incident was caused by a localized infrastructure failure at our cloud service provider, which affected authentication traffic and prevented login verifications. To resolve this issue, we reprovisioned our authentication resources to healthy environments. After we rerouted login traffic to the healthy environments, PhishER and PasswordIQ returned to regular performance by 03:08 \(UTC\).

No data loss occurred as a result of this issue.</description></item><item><title>PhishER - Unable to Login (UK) [resolved]</title><link>https://stspg.io/299x95lm5rgt</link><guid isPermaLink="false">knowbe4:2026-04-30T13:47:54.885Z</guid><pubDate>Thu, 30 Apr 2026 13:47:54 +0000</pubDate><description>We have identified an issue with customers signing into PhishER in the UK instance and implemented a fix. Customers should be able to login successfully.</description></item></channel></rss>