Microsoft confirmed an ongoing Exchange Online incident, tracked as EX1467029, that is delaying inbound and outbound messages involving external domains. Affected users have intermittently encountered “Server busy” errors across multiple mailboxes; Microsoft said anti-spam protections may be compounding delays for a subset of accounts while it analyzes service telemetry to isolate the issue.
Microsoft had not identified a root cause, the affected regions or user count, or a remediation timeline. The disruption follows the recently mitigated EX1464935 incident, which caused authentication, mailbox-search, and mail-delivery problems from August 31 through September 3; organizations relying on external email should account for delayed business communications, security alerts, and email-based MFA messages.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft confirmed and investigated Exchange Online incident EX1467029, which delayed inbound and outbound email involving external domains and intermittently produced “Server busy” errors. The company said anti-spam protections might be compounding delays for some users while it analyzed telemetry to determine the cause and mitigation path.
Microsoft declared EX1464935 fully mitigated after testing and gradually deploying remediation across affected infrastructure.
Microsoft 365 experienced Exchange Online incident EX1464935, causing authentication failures, mailbox-search problems, and delayed message delivery. Microsoft later attributed the incident to a fault in a core authentication component shared across multiple Microsoft 365 services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.