Ransomware

Rackspace Hosted Exchange Play Ransomware Attack β€” Permanent Service Shutdown

πŸ“… 2022-12-02 🏒 Rackspace Hosted Exchange (managed Microsoft Exchange service) 🦠 Play ransomware πŸ”Ž CVE-2022-41080 Β· CVE-2022-41082
Primary Source β†—

Incident Details

On 2 December 2022, Play ransomware attacked Rackspace’s Hosted Exchange email service, forcing Rackspace to permanently shut down the service. Rackspace had approximately 30,000 Hosted Exchange customers at the time. The company took the entire Hosted Exchange environment offline and ultimately decided not to restore it, instead migrating affected customers to Microsoft 365 at no charge. CrowdStrike, engaged to investigate, discovered the Play group had used a zero-day technique (OWASSRF β€” a new exploit technique for CVE-2022-41080 that bypassed existing ProxyNotShell mitigations). The attackers exfiltrated data belonging to 27 Rackspace customers. Personal data of those customers β€” including names, addresses, emails, phone numbers, dates of birth, Social Security numbers, and account information β€” was accessed. Rackspace faced numerous lawsuits from customers for the loss of email access and historical email data, as well as for the personal data breach affecting the 27 customers. The company paid approximately $10.8 million in settlements. The OWASSRF exploit technique discovered through the Rackspace investigation was subsequently published by CrowdStrike, enabling defenders to detect and remediate the vulnerability. Rackspace took a $9 million revenue charge related to the incident and incurred approximately $10.8 million in legal and remediation costs.

Technical Details

Initial Attack Vector
Play ransomware group exploited CVE-2022-41080 (OWASSRF β€” Microsoft Exchange Server ProxyNotShell bypass) combined with CVE-2022-41082 to achieve remote code execution on Rackspace's Hosted Exchange environment; the vulnerability bypassed existing mitigations Rackspace had applied for ProxyNotShell
Vendor / Product
Rackspace Hosted Exchange (managed Microsoft Exchange service)
Malware Family
Play ransomware
CVE / GHSA References
CVE-2022-41080 CVE-2022-41082

Timeline

  1. 2022-12-02 Breach occurred
  2. 2022-12-06 Publicly disclosed
  3. 2022-12-06 Customers notified