Rackspace names Play ransomware as threat actor behind December attack

Share post:

Rackspace Technology has revealed that the ransomware attack that disrupted email access for its Hosted Exchange customers in early December was carried out by the threat actor known as Play. Following a forensic investigation led by CrowdStrike, the FBI, and other experts, the threat actor was identified.

According to Rackspace, a previously unknown exploit was used to gain access to its network and steal data. On November 29, the attackers gained access to one of the company’s servers after a customer’s credentials were compromised.

Rackspace was forced to shut down its Hosted Exchange environment as a result of the incident. The company is currently working to recover the data stored on the impacted Exchange servers.

In its latest and final status update, Rackspace stated that “more than half” of its customers who lost their hosted email service last month now have “some or all of their data available for download.”

Rackspace has given customers free licenses to migrate their email from its Hosted Exchange platform to Microsoft 365 since the attack was discovered.

The company is also working on providing affected users with download links to their mailboxes (containing Hosted Exchange email data before December 2) via an automated queue through its customer portal.

The sources for this piece include an article in BleepingComputer.

Featured Tech Jobs



Related articles

Kaspersky uncovers malware targeting iPhones running iOS 15.7 and below

Kaspersky has uncovered a sophisticated malware campaign specifically designed to infect iPhones running up to iOS 15.7 through...

Apple’s App Store ecosystem generate $1.1 Trillion in developer billings and sales in 2022

According to a study done by Analysis Group, the whole ecosystem of Apple's App Store earned $1.1 trillion...

Dell beats profit estimates in Q1

After a drop in demand, Dell exceeded earnings estimates in the first quarter, indicating a brighter future for...

WordPress fixes critical Jetpack plugin vulnerability

WordPress has addressed a critical flaw discovered in the Jetpack plugin, which had the potential to enable authors...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways