It was a DDos attack! Hackers Launched Massive Attack on Microsoft Azure Leads Global Outage

 

 

Microsoft confirms that Several Microsoft services, such as Azure App Services, Application Insights, Azure IoT Central, Azure Log Search Alerts, Azure Policy, and the Azure interface, were negatively impacted by a global outage caused on July 30, 2024, by a Distributed Denial-of-Service (DDoS) attack.

The event also affected another subset of Microsoft 365 and Microsoft Purview services.

Between 11:45 UTC and 19:43 UTC, an unexpected usage spike caused Azure Front Door (AFD) and Azure Content Delivery Network (CDN) components to perform below acceptable thresholds, resulting in:

  • Intermittent errors
  • Timeout issues
  • Latency spikes

Although the DDoS protection mechanisms were activated, an error in implementing these defenses amplified the impact of the attack instead of mitigating it.

Microsoft's response team investigated the issue and implemented the following measures:

  1. Networking configuration changes to support DDoS protection efforts
  2. Failovers to alternate networking paths to provide relief
  3. Updated mitigation approach, rolled out across regions in Asia Pacific, Europe, and the Americas

The initial network configuration changes successfully mitigated most of the impact by 14:10 UTC. However, some customers reported less than 100% availability, which 18:00 UTC addressed. 19:43 UTC mitigated the incident, and failure rates returned to pre-incident levels.

Post-Incident Review and Next Steps

Microsoft will conduct an internal retrospective to understand the incident in more detail. The following reports will be published:

  1. Preliminary Post Incident Review (PIR) within approximately 72 hours
  2. Final Post Incident Review with additional details and learnings within 14 days

Users can configure and maintain Azure Service Health alerts to stay informed about future Azure service issues.

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.