Back to the archive

The encyclopedia · Software & IT · Technical decision · 2022

Rackspace let a known Exchange bug take down its hosted email for thousands of customers

One unpatched Microsoft Exchange vulnerability let ransomware silence a legacy Rackspace product and rack up about $11 million in costs.

Rackspace Technology · 2022-12-06

What happened

On 6 December 2022 Rackspace Technology announced a ransomware attack on its Hosted Exchange environment, knocking out email for thousands of customers, most of them small and mid-sized businesses. The company said the incident was isolated to Hosted Exchange and that its other products were unaffected.

The intrusion was not exotic. Rackspace ultimately blamed the Play ransomware crew, who got in by exploiting CVE-2022-41080, a critical Microsoft Exchange privilege-escalation bug, before Microsoft shipped a fix. A single known, pre-disclosed vulnerability against a legacy hosted-email product took an entire product line offline.

The bill was large for a product the company was already winding down. Rackspace racked up about $11 million in ransomware-related expenses, roughly half covered by insurance, and the Hosted Exchange business it was sunsetting generated around $30 million a year in revenue it now risked losing. The outage also drew lawsuits over the service disruption.

The case is a decision about what a company chooses to keep running. Rackspace was phasing Hosted Exchange out, yet the platform still held thousands of paying customers and sat exposed to a bug that had already been disclosed publicly. The cost of retiring a product is not just migration — it is hardening the legacy service until the last customer leaves.

Why it happened

  • Rackspace kept the legacy Hosted Exchange platform running unpatched against a publicly known Exchange bug, so one CVE took the whole product offline
  • The company was already sunsetting the product, so it under-invested in hardening a service that still held thousands of paying customers
  • The attack hit a single product line, so thousands of SMB customers lost email all at once, not gradually through a planned migration
  • The roughly $11 million in costs and the $30 million revenue segment show a sunset product still carried real exposure Rackspace had not priced in
What it costabout $11 million spent, half covered by insurancecostly

The lesson

A legacy product you are sunsetting still needs hardening until the last customer leaves — a publicly known bug against an under-invested platform is how a wind-down becomes a breach.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →