A follow-up to Monday – that outage at Rackspace has now been confirmed as a ransomware attack. Rackspace says that the investigation, led by a cyber defense firm and its own internal security team, is in its early stages with no info on “what, if any, data was affected.”
The cloud service provider says it will notify customers if it finds evidence that the attackers gained access to their sensitive information.
And from the Record, “Cybersecurity expert Kevin Beaumont examined evidence from the incident and said the attack may have been caused by hackers exploiting ProxyNotShell – a dangerous set of vulnerabilities affecting Exchange Server software.”
Rackspace said in an SEC filing Tuesday that the attack “may result in a loss of revenue” for its $30 million Hosted Exchange business and other “incremental costs.”
As this saga continues, it’s simply reinforcing my comments from Monday. Rackspace wasn’t ready for an incident. But more importantly, while the analysts are observing how many SMBs are impacted… those same SMBs were also not prepared. And that’s why we care. Go get them ready.

