
Microsoft Corp. said a distributed denial-of-service cyber attack caused an outage of its Azure cloud applications. The attack began early Tuesday, the company said in a status update, which was compounded by a mistake in Microsoft's automated protection mechanisms.
The outage disrupted businesses in many regions, including the ability to run their systems on Azure. For instance, the mobile ordering system for Starbucks —an Azure-driven service, according to a person familiar with the matter— was interrupted for hours by the Azure issues.
Denial-of-service attacks inundate websites with internet traffic in an attempt to shut them down. It has been a nagging problem for financial institutions, as sometimes they face intermittent downtime, and their security teams have to ward off the activity.
Reports of outages on Azure and Microsoft 365 began to spike shortly after 7 a.m. in New York, with hundreds of complaints at the peak of the incident, according to user reports compiled by Downdetector. Microsoft said the issue was resolved by about 5 p.m. in New York.
Earlier this month, some 8 million computers running the Windows operating system crashed following a flawed software update from cybersecurity firm CrowdStrike Holdings Inc. Microsoft has also been dealing with the aftermath of a string of cyberattacks that prompted the US government to issue a report that was highly critical and called for company wide action.
Microsoft CEO Satya Nadella called out progress in the company's cybersecurity products on a conference call Tuesday after the company's quarterly earnings report. More than 1.2 million security customers are now using Microsoft, he pointed out, saying, "We continue to prioritise security above all else."
It shows contemporary challenges and vulnerabilities in cloud service providers. As cyber threats evolve, the requirement for better security measures and quick response mechanisms becomes critical to maintain trust and reliability among customers for tech giants such as Microsoft.