News: 1670366706

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Rackspace confirms ransomware behind days-long Exchange email outage

(2022/12/06)


Rackspace has admitted a ransomware infection was to blame for the days-long email outage that disrupted services for customers.

The [1]security snafu took down some of Rackspace's hosted Microsoft Exchange services on Friday afternoon. In its most recent [2]update , posted at 0826 Eastern Time on Tuesday, Rackspace said it has now "determined this suspicious activity was the result of a ransomware incident," and has hired a "leading cyber defense firm to investigate."

The company hasn't yet determined what customer data was touched. "If we determine sensitive information was affected, we will notify customers as appropriate," it added.

[3]

Rackspace [4]reiterated that the intrusion was isolated to its hosted Exchange businesses, and noted no impact to Rackspace Email and its other products.

[5]

[6]

As it has in previous updates, Rackspace urged customers to migrate their users and domains to Microsoft 365, and admitted it doesn't have a timeline for restoring the hosted Exchange email services. An earlier update posted on Monday claimed to have helped "thousands of customers move tens of thousands of users" to Microsoft 365.

[7]Rackspace customers rage as email outage continues and migrations create migraines

[8]Rackspace rocked by 'security incident' that has taken out hosted Exchange services

[9]Hive ransomware crooks extort $100m from 1,300 global victims

[10]FBI warns about Cuba, no, not that one — the ransomware gang

Rackspace declined to answer The Register 's questions about how many customers were affected, who is responsible for the ransomware attack, how they breached the network, or the payment demanded, among others.

In an emailed statement, the spokesperson repeated much of what has already been said in the incident report:

On Friday, December 2nd, Rackspace detected suspicious activity on its Hosted Exchange environment. Upon discovery, Rackspace immediately took proactive measures to isolate the Hosted Exchange environment to contain the incident, working alongside industry-leading third-party cybersecurity experts.

The ongoing investigation has determined the activity to be the result of ransomware. Our technical teams are working diligently to help affected customers migrate to a new environment as quickly as possible. Based on the investigation to date, we believe that this incident was isolated to the Hosted Exchange business.

The Company's other products and services are fully operational, and we have not experienced an impact to our Rackspace Email product line and platform. Out of an abundance of caution, we have put additional security measures in place and will continue to actively monitor for any suspicious activity.

However, the spokesperson did clarify a point from a [11]press release issued today about the ransomware attack that indicated the incident may result in a loss of revenue for its hosted Exchange biz, which Rackspace said brings in about $30 million annually. The press release also noted that the company may be on the hook for "incremental costs" related to incident response.

These costs will not be passed on to Rackspace customers, according to the spokesperson. ®

Get our [12]Tech Resources



[1] https://www.theregister.com/2022/12/03/rackspace_security_incident_hosted_exchange/

[2] https://status.apps.rackspace.com/index/viewincidents?group=2

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y4-JlKkxCceFrxLMO@wREgAAAIE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.theregister.com/2022/12/05/rackspace_hosted_exchange_security_update/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y4-JlKkxCceFrxLMO@wREgAAAIE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y4-JlKkxCceFrxLMO@wREgAAAIE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/12/05/rackspace_hosted_exchange_security_update/

[8] https://www.theregister.com/2022/12/03/rackspace_security_incident_hosted_exchange/

[9] https://www.theregister.com/2022/11/18/hive_ransomware_fbi/

[10] https://www.theregister.com/2022/12/02/fbi_warning_cuba_ransomware/

[11] https://www.rackspace.com/newsroom/rackspace-technology-hosted-exchange-environment-update

[12] https://whitepapers.theregister.com/



"It is easy to sympathize with the MIS staffs around the world, I mean who hasn't lost work due to Windows or a Microsoft application crashing?"

-- Chris DiBona, happy he's been using Linux and can avoid such things, from the introduction. (Open Sources, 1999 O'Reilly and Associates)