Tuesday, December 6, 2022

12/6/22 @ 11:29 am CST - Hosted Exchange Outage Update

At this point, it appears the data center (and us) are the victim of a ransomware attack.  My understanding is they discovered it and then shut off access to everything.  At this point, I don't think the exchange system it's coming back. (at least any time soon)  I will be reaching out to everyone individually to discuss options going forward with regard to your mail and how best to make this a smooth transition to an alternative solution.  

For those that were using a mail client such as Outlook or other exchange mail client like Mail on a mac, you should have at a minimum a year+ of your data already synced and on your local computer.  As for myself, I had about 10+ years of email over there and it appears I am only going to get the last year because my Outlook was running in cached exchange mode which is only storing a year of mail locally in Outlook.

This process of calling each of you will take some time as I work through the logistics of this monumental task.  Until that time, please use the webmail for your immediate incoming/outgoing mail.  Each of you have unique mail requirements.  This disruption could not have come at a worse time for everyone.  You, me, everyone.  I am working with another exchange provider for a solution to this mess. I will be working with each of you individually to get this working for you.  Thank you for your patience as we all navigate this bad situation.

Here is the lasted update from the data center: 

12/6/22 7:28 CST - We appreciate your patience as we continue to work through the security issues that have affected our Hosted Exchange environment. As you know, on Friday, December 2nd, 2022, we became aware of suspicious activity and immediately took proactive measures to isolate the Hosted Exchange environment to contain the incident. We have since determined this suspicious activity was the result of a ransomware incident.

Alongside our internal security team, we have engaged a leading cyber defense firm to investigate. Our investigation is still in its early stages, and it is too early to say what, if any, data was affected. If we determine sensitive information was affected, we will notify customers as appropriate.

Based on the investigation to date, we believe that this incident was isolated to our Hosted Exchange business. The Company's other products and services are fully operational, and we have not experienced any impact to our other product lines and platform. Out of an abundance of caution, we have put additional security measures in place and will continue to actively monitor for any suspicious activity.