Site navigation

Microsoft Confirms Outages Were Caused by DDoS Attack

Michael Edgar

,

Microsoft DDoS attack
Recent outages affecting Microsoft Outlook, OneDrive, and Azure have now been confirmed by Microsoft to be the result of Layer 7 DDoS attacks launched against the company by a threat actor known as Storm-1359.

The initial attacks took place on June 7th (Outlook), June 8th (OneDrive), and June 9th (Azure). While the threat actor – Storm-1359, who identifies themselves as Anonymous Sudan – had taken responsibility for the attacks publicly, Microsoft had not explicitly disclosed the cause until now. 

“We have seen no evidence that customer data has been accessed or compromised,” said Microsoft in a statement on the issue. 

Before Microsoft addressed the prospect of a cyber attack, there was evidence of it being one early in the process. According to a preliminary post incident review, the initial analysis showed an anomalous spike in HTTP requests issued against Azure portal origins, which bypassed the automatic preventative measures and triggered the ‘service unavailable’ response. 

Microsoft had also mentioned they were implementing load balancing processes to mitigate the issues. Load balancing is a textbook defence against DDoS attacks, as it distributes network traffic to avoid overloading one particular resource. 

Now Microsoft has confirmed the outages were because of a Layer DDoS attack, which attacks web services by overwhelming them with a large volume of requests, causing the services to become unresponsive due to an inability to process all the incoming requests.


Recommended


Microsoft had highlighted three Layer 7 DDoS attack techniques used by Storm-1359: 

  • HTTP(S) flood attack: Where the attack exhausts the system with a high load of ‘SSL/TLS handshakes’ and HTTP(S) request processing. Millions of requests, distributed across IP addresses around the world, causes the backend to run out of compute resources. 
  • Cache bypass: Which bypasses the content delivery network layer, overloading the origin servers. The attackers do this by sending queries against generated URLs, forcing the frontend layer to forward all requests to the origin, rather than serving from cached contents. 
  • Slowloris: An attack where the client opens a connection to the web server to request a resource, then fails to acknowledge the download which forces the web server to keep the connection open and the resource in memory. 

The threat actor group known as both Storm-1359 and Anonymous Sudan emerged in early 2023 conducting attacks against countries that opposed Sudan. The group has claimed responsibility for attacks against large companies such as Scandinavian Airlines, Tinder, Lyft, as well as several attacks on hospitals and organisations in the United States.

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data