Thank you for posting to Microsoft Community.
Based on your description, I understand there is an issue that user got an email, but the user is not mentioned in the email.
May I know if the sender of the email is also in your organization?
If yes, please double check if there are any rules (such as outbound policy) related to it since it could be caused by some BCC-related forwarding.
You could refer to Configure outbound spam policies - Microsoft Defender for Office 365 | Microsoft Learn for more information.
If no, please kindly make sure the content of the external email is not spam or phishing email.
If there's anything else missed or you need help, please feel free to let me know.