The encyclopedia · Software & IT · Technical decision · 2022
Rackspace let a known Exchange bug take down its hosted email for thousands of customers
One unpatched Microsoft Exchange vulnerability let ransomware silence a legacy Rackspace product and rack up about $11 million in costs.
Rackspace Technology · 2022-12-06
What happened
On 6 December 2022 Rackspace Technology announced a ransomware attack on its Hosted Exchange environment, knocking out email for thousands of customers, most of them small and mid-sized businesses. The company said the incident was isolated to Hosted Exchange and that its other products were unaffected.
The intrusion was not exotic. Rackspace ultimately blamed the Play ransomware crew, who got in by exploiting CVE-2022-41080, a critical Microsoft Exchange privilege-escalation bug, before Microsoft shipped a fix. A single known, pre-disclosed vulnerability against a legacy hosted-email product took an entire product line offline.
The bill was large for a product the company was already winding down. Rackspace racked up about $11 million in ransomware-related expenses, roughly half covered by insurance, and the Hosted Exchange business it was sunsetting generated around $30 million a year in revenue it now risked losing. The outage also drew lawsuits over the service disruption.
The case is a decision about what a company chooses to keep running. Rackspace was phasing Hosted Exchange out, yet the platform still held thousands of paying customers and sat exposed to a bug that had already been disclosed publicly. The cost of retiring a product is not just migration — it is hardening the legacy service until the last customer leaves.
Why it happened
- Rackspace kept the legacy Hosted Exchange platform running unpatched against a publicly known Exchange bug, so one CVE took the whole product offline
- The company was already sunsetting the product, so it under-invested in hardening a service that still held thousands of paying customers
- The attack hit a single product line, so thousands of SMB customers lost email all at once, not gradually through a planned migration
- The roughly $11 million in costs and the $30 million revenue segment show a sunset product still carried real exposure Rackspace had not priced in
The lesson
A legacy product you are sunsetting still needs hardening until the last customer leaves — a publicly known bug against an under-invested platform is how a wind-down becomes a breach.
Sources
- Rackspace Technology 8-K on the Hosted Exchange ransomware incident — SEC, December 2022
- Rackspace racks up $11M in ransomware-related costs — The Register, November 2023
spotted an error? The club wants to know.
More like this
Microsoft 365 falls for five hours after a maintenance bug cut West US off the network
The Therac-25 killed patients — software replaced the hardware safety interlock
TSMC's Arizona mega-fab costs US$165 billion and still runs 30% dearer than Taiwan
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.