Critical September 18, 2026 - Detected by Pingoru
- Sep 18, 2026, 11:07 AM UTC
- Resolved
- Sep 18, 2026, 04:48 PM UTC
- Duration
- 5h 40m
Affected: Console
Timeline · 2 updates
-
investigating Sep 18, 2026, 11:07 AM UTC
We have received reports that users are unable to login to the DE and UK instances of KSAT. We are investigating this issue and will update this page when we have more information.
-
resolved Sep 18, 2026, 04:48 PM UTC
This incident has been resolved.
Read the full incident report →
Critical September 17, 2026 - Detected by Pingoru
- Sep 17, 2026, 10:44 PM UTC
- Resolved
- Sep 18, 2026, 04:47 PM UTC
- Duration
- 18h 3m
Affected: Console
Timeline · 4 updates
-
investigating Sep 17, 2026, 10:44 PM UTC
We have received reports that users are unable to login to the US instance of KSAT. We are investigating this issue and will update this page when we have more information.
-
monitoring Sep 18, 2026, 01:28 AM UTC
We’ve implemented a fix and we’re monitoring the results to make sure no further issues occur.
-
investigating Sep 18, 2026, 02:02 PM UTC
We have received new reports of users being unable to login to the US instance of KSAT. We are investigating this issue and will update this page when we have more information.
-
resolved Sep 18, 2026, 04:47 PM UTC
This incident has been resolved.
Read the full incident report →
Critical September 16, 2026 - Detected by Pingoru
- Sep 16, 2026, 05:47 PM UTC
- Resolved
- Sep 16, 2026, 08:58 PM UTC
- Duration
- 3h 11m
Affected: ConsoleConsoleLearner Experience (LX)
Timeline · 3 updates
-
identified Sep 16, 2026, 05:47 PM UTC
We have identified an issue causing login and access issues for accounts on our UK instance.
-
monitoring Sep 16, 2026, 06:16 PM UTC
A fix has been implemented and we are monitoring the results.
-
resolved Sep 16, 2026, 08:58 PM UTC
This incident has been resolved.
Read the full incident report →
Notice September 11, 2026 - Detected by Pingoru
- Sep 11, 2026, 12:43 PM UTC
- Resolved
- Sep 08, 2026, 07:00 AM UTC
- Duration
- —
Timeline · 1 update
-
resolved Sep 11, 2026, 12:43 PM UTC
On Septermber 8th we made aware that inbound HTML emails rendered partially or blank in Classic Outlook due to a routine HTML library upgrade in Defend's harmful-code-removal engine interacting with Classic Outlook's legacy Word rendering engine. New Outlook and Outlook on the web were unaffected. This was strictly a display issue: no email was delayed, lost, or compromised, and threat detection remained fully active. Engineering has reverted the update to restore normal rendering. If you temporarily disabled harmful-code removal during this window, please re-enable it to ensure complete protection.
Read the full incident report →
- Detected by Pingoru
- Sep 04, 2026, 10:53 AM UTC
- Resolved
- Sep 07, 2026, 08:25 AM UTC
- Duration
- 2d 21h
Affected: Secure Workspace
Timeline · 3 updates
-
investigating Sep 04, 2026, 10:53 AM UTC
We have received reports of an issue with delivery of Email verification MFA for Workspace. We are investigating this issue and will update this page when we have more information.
-
monitoring Sep 04, 2026, 02:24 PM UTC
We have received reports that the issue with delivery of Email verification MFA for Workspace has been mitigated by Microsoft, and we are monitoring the results.
-
resolved Sep 07, 2026, 08:25 AM UTC
This incident has been resolved.
Read the full incident report →
- Detected by Pingoru
- Aug 26, 2026, 04:19 PM UTC
- Resolved
- Aug 26, 2026, 07:51 PM UTC
- Duration
- 3h 31m
Affected: Inbox
Timeline · 3 updates
-
investigating Aug 26, 2026, 04:19 PM UTC
We have identified an issue where users may experience delays in messages being processed, and our engineering team is looking into a fix.
-
monitoring Aug 26, 2026, 04:46 PM UTC
Our engineering team has implemented a fix for the issue that causing message processing delays in PhishER, and we are monitoring the results.
-
resolved Aug 26, 2026, 07:51 PM UTC
Our engineering team has implemented a fix for the issue that causing message processing delays in PhishER.
Read the full incident report →
- Detected by Pingoru
- Aug 21, 2026, 08:52 AM UTC
- Resolved
- Aug 21, 2026, 02:57 PM UTC
- Duration
- 6h 4m
Affected: Phish Alert Button
Timeline · 5 updates
Read the full incident report →
- Detected by Pingoru
- Aug 18, 2026, 02:29 PM UTC
- Resolved
- Aug 18, 2026, 08:14 PM UTC
- Duration
- 5h 44m
Affected: Phish Alert Button
Timeline · 3 updates
-
investigating Aug 18, 2026, 02:29 PM UTC
We are investigating an issue causing a Non-Delivery Report (NDR) to be returned when a message is reported via the Phish Alert Button and "Send Us a Copy" is enabled in Account Settings
-
monitoring Aug 18, 2026, 03:26 PM UTC
A fix has been implemented and we are monitoring the results.
-
resolved Aug 18, 2026, 08:14 PM UTC
This incident has been resolved.
Read the full incident report →
- Detected by Pingoru
- Aug 05, 2026, 07:29 PM UTC
- Resolved
- Aug 06, 2026, 09:56 PM UTC
- Duration
- 1d 2h
Affected: PhishRIP
Timeline · 3 updates
-
investigating Aug 05, 2026, 07:29 PM UTC
We are currently investigating an issue affecting Google PhishRIP queries, which may cause them to fail.
-
monitoring Aug 05, 2026, 09:24 PM UTC
Based on our investigation into the recent errors affecting Google PhishRIP queries, it appears these may be related to suspended Gmail accounts. We are continuing to monitor the issue.
-
resolved Aug 06, 2026, 09:56 PM UTC
Upon further investigation we have determined that the errors affecting Google PhishRIP queries were related to individual issues on Google accounts.
Read the full incident report →
- Detected by Pingoru
- Aug 04, 2026, 07:19 PM UTC
- Resolved
- Aug 05, 2026, 12:17 PM UTC
- Duration
- 16h 58m
Affected: Console
Timeline · 3 updates
-
identified Aug 04, 2026, 07:19 PM UTC
We have identified an issue preventing account settings from loading in the SAT console.
-
monitoring Aug 04, 2026, 07:51 PM UTC
A fix has been implemented and we are monitoring the results.
-
resolved Aug 05, 2026, 12:17 PM UTC
This incident has been resolved.
Read the full incident report →
- Detected by Pingoru
- Jul 28, 2026, 08:00 PM UTC
- Resolved
- Jul 29, 2026, 06:58 PM UTC
- Duration
- 22h 57m
Affected: PhishRIP
Timeline · 4 updates
Read the full incident report →
- Detected by Pingoru
- Jul 22, 2026, 09:01 PM UTC
- Resolved
- Jul 10, 2026, 02:30 PM UTC
- Duration
- —
Timeline · 1 update
-
resolved Jul 22, 2026, 09:01 PM UTC
An upstream feature flag service issue degraded model routing in collaboration-inference, causing PhishML evaluations to return 0/0/0 default errors. The third party deployed a fix, and a code update was deployed to production adding static fallback routing. All services have recovered and are operating normally.
Read the full incident report →
- Detected by Pingoru
- Jul 17, 2026, 01:18 PM UTC
- Resolved
- Sep 11, 2026, 03:04 PM UTC
- Duration
- 56d 1h
Affected: KnowBe4 Website
Timeline · 6 updates
-
investigating Jul 17, 2026, 01:18 PM UTC
We are investigating users being unable to purchase Protect licenses on store.knowbe4.com. We will update this page when we have more information.
-
monitoring Jul 17, 2026, 06:55 PM UTC
We’ve implemented a fix and we’re monitoring the results to make sure no further issues occur.
-
investigating Jul 20, 2026, 06:24 PM UTC
We have received reports that customers are unable to purchase Protect licenses on store.knowbe4.com. We are investigating this issue and will update this page when we have more information.
-
monitoring Jul 29, 2026, 06:40 PM UTC
We’ve implemented a fix for the online store and we’re monitoring the results to make sure no further issues occur.
-
monitoring Aug 17, 2026, 09:02 PM UTC
We are continuing to monitor the implemented fix for the online store, to ensure that no further issues occur.
-
resolved Sep 11, 2026, 03:04 PM UTC
This incident has been resolved.
Read the full incident report →
- Detected by Pingoru
- Jul 16, 2026, 07:48 PM UTC
- Resolved
- Jul 16, 2026, 09:20 PM UTC
- Duration
- 1h 32m
Affected: Console
Timeline · 4 updates
-
investigating Jul 16, 2026, 07:48 PM UTC
We have identified an issue where users may receive a redirect upon logging into Defend, and our engineering team is looking into a fix.
-
identified Jul 16, 2026, 08:09 PM UTC
A fix has been identified, and we will be monitoring the results as it rolls out.
-
resolved Jul 16, 2026, 09:20 PM UTC
This incident has been resolved.
-
postmortem Aug 20, 2026, 09:32 PM UTC
On Thursday, July 16, 2026, from approximately 19:57 to 21:12 \(UTC\), some customers experienced difficulty logging in to the Defend console, seeing a **Find Out More** screen instead of console access. This issue was caused by a synchronization issue between Salesforce and our internal licensing systems, which incorrectly set some customer license counts to zero. As a result, affected customers were unable to log in. To resolve this issue, our team applied a temporary license override to restore access for affected customers while correcting the underlying licensing records in Salesforce. Once corrected, the systems automatically synchronized the accurate values, and the Defend console access returned to normal performance by approximately 21:12 \(UTC\). To prevent this type of issue in the future, we are implementing improvements to the Salesforce synchronization process to ensure accurate license counts. No data loss occurred as a result of this issue.
Read the full incident report →
- Detected by Pingoru
- Jul 01, 2026, 02:40 PM UTC
- Resolved
- Jul 01, 2026, 06:01 PM UTC
- Duration
- 3h 20m
Affected: Console
Timeline · 4 updates
Read the full incident report →
- Detected by Pingoru
- Jun 30, 2026, 04:14 PM UTC
- Resolved
- Jun 30, 2026, 07:46 PM UTC
- Duration
- 3h 31m
Affected: Mail Flow
Timeline · 3 updates
Read the full incident report →
- Detected by Pingoru
- Jun 30, 2026, 02:18 PM UTC
- Resolved
- Jun 30, 2026, 07:11 PM UTC
- Duration
- 4h 53m
Affected: PhishML
Timeline · 4 updates
Read the full incident report →
- Detected by Pingoru
- Jun 24, 2026, 03:48 PM UTC
- Resolved
- Jun 25, 2026, 01:10 PM UTC
- Duration
- 21h 22m
Affected: KCM GRC
Timeline · 4 updates
-
investigating Jun 24, 2026, 03:48 PM UTC
We have identified an issue where users may receive a 500 error upon logging into KCM GRC, and our engineering team is looking into a fix.
-
monitoring Jun 24, 2026, 10:06 PM UTC
We have identified an issue where users may receive a 500 error upon logging into KCM GRC. A fix has been implemented, and we will continue to monitor this issue.
-
resolved Jun 25, 2026, 01:10 PM UTC
We have identified an issue where users may receive a 500 error upon logging into KCM GRC. A fix has been implemented, and users should be able to login without error.
-
postmortem Aug 04, 2026, 02:50 PM UTC
From Tuesday, June 23, 2026, at approximately 10:03 \(UTC\) to Thursday, June 25, 2026, at approximately 11:54 \(UTC\), some US and EU customers experienced intermittent 502 errors when logging in to KCM GRC. This issue was caused by network traffic attempting to connect to invalid multilevel subdomains, which overwhelmed the cache serving KCM GRC and resulted in login errors. Our team initially updated the configuration of our content delivery network, which temporarily resolved the errors, but they returned later that day. After further investigation, we identified the caching issue as the root cause and deployed an infrastructure-level fix to prevent multi-level subdomain traffic from affecting the cache. KCM GRC returned to normal performance by 11:54 \(UTC\) on June 25, 2026. To prevent this type of issue in the future, we are evaluating additional protections to guard against similar traffic that could affect the cache. No data loss occurred as a result of this issue.
Read the full incident report →
- Detected by Pingoru
- Jun 18, 2026, 09:14 PM UTC
- Resolved
- Jun 19, 2026, 02:01 PM UTC
- Duration
- 16h 47m
Affected: Reporting
Timeline · 5 updates
-
investigating Jun 18, 2026, 09:14 PM UTC
We have received reports of the Phishing test reports tab currently being unavailable. We are investigating this issue and will update this page when we have more information.
-
investigating Jun 18, 2026, 09:16 PM UTC
We are continuing to investigate this issue.
-
monitoring Jun 18, 2026, 10:42 PM UTC
A fix has been implemented and we are monitoring the results.
-
resolved Jun 19, 2026, 02:01 PM UTC
This incident has been resolved.
-
postmortem Jul 07, 2026, 07:45 PM UTC
From Tuesday, June 16, 2026, at approximately 17:34 \(UTC\), to Thursday, June 18, 2026, at approximately 22:41 \(UTC\), some customers experienced intermittent unavailability of the **Phishing Security Test Reports** page in the KnowBe4 console. This issue was caused by a code change that introduced a conflict between two methods for processing phishing campaign data. As a result, phishing campaigns still using legacy phishing categories were unable to load the **Phishing Security Test Reports** page. To resolve this issue, we updated the code to process campaigns correctly under both classification systems, and the **Phishing Security Test Reports** page returned to normal performance by June 18, 2026, at 22:41 \(UTC\). No data loss occurred as a result of this issue.
Read the full incident report →
- Detected by Pingoru
- Jun 18, 2026, 03:13 PM UTC
- Resolved
- Jun 18, 2026, 07:12 PM UTC
- Duration
- 3h 59m
Affected: KnowBe4 Security Center
Timeline · 4 updates
-
investigating Jun 18, 2026, 03:13 PM UTC
We have received reports that the Human Risk Managment widget is showing no results in the KnowBe4 Security Center. We are investigating this issue and will update this page when we have more information.
-
monitoring Jun 18, 2026, 03:43 PM UTC
We’ve implemented a fix for the Human Risk Management widget and we’re monitoring the results to make sure no further issues occur.
-
resolved Jun 18, 2026, 07:12 PM UTC
This incident has been resolved.
-
postmortem Sep 08, 2026, 03:44 PM UTC
From Wednesday, June 17, 2026, at approximately 19:00 \(UTC\), to Thursday, June 18, 2026, at approximately 18:20 \(UTC\), some customers were unable to view results in the KnowBe4 Security Center’s Human Risk Management widget. This issue was caused by a recent infrastructure migration that left an internal service connection pointing to an outdated endpoint. Though the underlying data processing was unaffected, the Human Risk Management widget could not retrieve data or display results. To resolve this issue, our team updated and reapplied the connection configuration, and the KnowBe4 Security Center returned to normal performance by approximately 18:20 \(UTC\) on June 18, 2026. To prevent this type of issue in the future, we are improving our migration process to ensure that all endpoints are valid after a migration. We are also strengthening known-good rollback procedures in cases where a migration cannot be completed as planned. No data loss occurred as a result of this issue.
Read the full incident report →
- Detected by Pingoru
- Jun 16, 2026, 10:23 PM UTC
- Resolved
- Jun 17, 2026, 08:19 PM UTC
- Duration
- 21h 56m
Affected: Reporting
Timeline · 4 updates
Read the full incident report →
- Detected by Pingoru
- Jun 15, 2026, 04:56 PM UTC
- Resolved
- Jun 15, 2026, 04:56 PM UTC
- Duration
- —
Affected: ConsolePhishingTraining
Timeline · 2 updates
-
resolved Jun 15, 2026, 04:56 PM UTC
This incident has been resolved.
-
postmortem Aug 20, 2026, 07:41 PM UTC
On Monday, June 15, 2026, from approximately 15:30 to 16:34 \(UTC\), some customers experienced processing delays with phishing and training campaigns in the KnowBe4 console. This issue was caused by an update that introduced an incompatible software version. This software prevented our background processing service from completing queued tasks. As a result, training enrollments, notification sending, and SmartGgroup enrollments were delayed. To resolve this issue, our team deployed a fix that reverted the affected dependency and restored normal job processing. Once the fix was deployed, the affected queues cleared, and the KnowBe4 console returned to normal performance by 16:34 \(UTC\). To prevent this issue in the future, we have implemented additional testing layers for similar deployments. No data loss occurred as a result of this issue.
Read the full incident report →
- Detected by Pingoru
- Jun 03, 2026, 03:07 PM UTC
- Resolved
- Jun 03, 2026, 06:14 PM UTC
- Duration
- 3h 7m
Affected: Console
Timeline · 4 updates
-
investigating Jun 03, 2026, 03:07 PM UTC
We have received reports of 500 errors occurring when navigating to user profiles. We are investigating this issue and will update this page when we have more information.
-
monitoring Jun 03, 2026, 04:16 PM UTC
A fix has been implemented and we are monitoring the results.
-
resolved Jun 03, 2026, 06:14 PM UTC
This incident has been resolved.
-
postmortem Jul 15, 2026, 03:23 PM UTC
On Wednesday, June 3, 2026, from approximately 14:49 to 16:09 \(UTC\), customers experienced errors when accessing the **User Details** page in the KSAT console. This issue was caused by an update that introduced missing fields, which prevented the **User Details** page from loading. To resolve this issue, our team updated the console again to restore the missing fields, and the KSAT console returned to normal performance by approximately 16:09 \(UTC\). To prevent similar issues in the future, additional automated tests were added. No data loss occurred as a result of this issue.
Read the full incident report →
- Detected by Pingoru
- May 28, 2026, 06:17 PM UTC
- Resolved
- May 28, 2026, 07:13 PM UTC
- Duration
- 55m
Affected: Training
Timeline · 3 updates
-
investigating May 28, 2026, 06:17 PM UTC
We are currently investigating an issue preventing customers from uploading custom content to the new Modstore
-
resolved May 28, 2026, 07:13 PM UTC
We have identified an issue with uploading custom content to the new Modstore and implemented a fix. Customers should be able to upload custom content successfully.
-
postmortem Jul 07, 2026, 07:43 PM UTC
On Thursday, May 28, 2026, from approximately 18:07 to 18:57 \(UTC\), some customers experienced issues uploading custom content to the new ModStore in KnowBe4 Security Awareness Training \(KSAT\). This issue was caused by an update to the new ModStore that disabled the language selection field in the “Add Translation” upload step, preventing customers from completing that required part of the upload process. To resolve this issue, our engineering team identified the recent deployment responsible for the defect, corrected it, and deployed the update to production. KSAT returned to normal performance by 18:57 \(UTC\). To prevent this type of issue in the future, we are improving test coverage for the affected upload flow and adding automated checks to catch similar issues before they reach production. No data loss occurred as a result of this issue.
Read the full incident report →
- Detected by Pingoru
- May 27, 2026, 10:05 AM UTC
- Resolved
- May 27, 2026, 03:44 PM UTC
- Duration
- 5h 38m
Affected: Mail Flow
Timeline · 4 updates
-
investigating May 27, 2026, 10:05 AM UTC
We have received reports that there is a Intermittent issue sending emails for Protect. We are investigating this issue and will update this page when we have more information.
-
monitoring May 27, 2026, 02:39 PM UTC
We’ve implemented a fix and we’re monitoring the results to make sure no further issues occur.
-
resolved May 27, 2026, 03:44 PM UTC
This incident has been resolved.
-
postmortem Sep 16, 2026, 01:47 PM UTC
On Wednesday, May 27, 2026, from approximately 09:22 to 15:24 \(UTC\), some UK customers experienced intermittent issues with outbound email delivery in Protect. This issue was caused by a configuration change that disrupted outbound email processing. Affected emails failed to send and were instead held in a delivery queue. To resolve this issue, our team temporarily rerouted traffic while investigating the root cause and then updated the affected configuration. After the configuration was updated, all queued messages were delivered, and Protect returned to normal performance by 15:24 \(UTC\). To prevent this type of issue in the future, we are integrating the configuration update into future deployments. We are also improving monitoring to detect similar disruptions more quickly. No data loss occurred as a result of this issue.
Read the full incident report →