Security News > 2024 > July > Microsoft says massive Azure outage was caused by DDoS attack
Microsoft confirmed that a nine-hour outage on Tuesday, which disrupted numerous Microsoft 365 and Azure services worldwide, was caused by a distributed denial-of-service (DDoS) attack. Affected services included Microsoft Entra, Intune, Power BI, Power Platform, Azure App Services, and others.
The company explained that their DDoS protection mechanisms were triggered, but an error in the implementation of their defenses exacerbated the attack's impact. Once the issue was identified, Microsoft made networking configuration changes and rerouted to alternate paths to mitigate the problem.
This confirmation came after initial reports attributed the outage to an "unexpected usage spike" that affected Azure Front Door (AFD) and Azure Content Delivery Network (CDN) components, leading to errors and latency issues. Microsoft plans to release a Preliminary Post-Incident Review (PIR) within 72 hours and a Final Post-Incident Review in two weeks, detailing the incident and lessons learned.
In June 2023, Microsoft also faced a significant DDoS attack by Anonymous Sudan, linked to Russia, targeting Azure, Outlook, and OneDrive services. Additionally, a widespread outage earlier this month affected Microsoft 365 customers due to an Azure configuration change. Past significant outages occurred in July 2022 and January 2023 due to ECS deployment and Wide Area Network IP changes, respectively.
News URL
Related news
- Microsoft Identifies Storm-0501 as Major Threat in Hybrid Cloud Ransomware Attacks (source)
- CUPS vulnerabilities could be abused for DDoS attacks (source)
- DOJ, Microsoft seize 107 domains used in Russia's Star Blizzard phishing attacks (source)
- Cloudflare blocks largest recorded DDoS attack peaking at 3.8Tbps (source)
- Microsoft and DOJ disrupt Russian FSB hackers' attack infrastructure (source)
- Recently patched CUPS flaw can be used to amplify DDoS attacks (source)
- Cloudflare Thwarts Largest-Ever 3.8 Tbps DDoS Attack Targeting Global Sectors (source)
- Largest Recorded DDoS Attack is 3.8 Tbps (source)
- New Gorilla Botnet Launches Over 300,000 DDoS Attacks Across 100 Countries (source)
- Microsoft issues 117 patches – some for flaws already under attack (source)