Outage Affected All LucidLink Customers

December 6, 2024

INCIDENT

LucidLink experienced a malicious attack resulting in an outage that affected all customers. Access was fully restored for everyone on May 1, 2024 at 12:06 UTC.

The company believes that, “the root cause of the event to be malicious exploitation of an internal server with access to the production environment. This server was utilized to gain elevated privilege and to execute a script that corrupted the disk attached to each metadata server.”

As LucidLink clients became disconnected, they contact the discovery service to determine the IP address of the metadata server they need to reconnect to. Having all of the company’s clients attempt to do this at once overloaded the discovery service, leading the company to initially suspect a DDoS attack.

Incident Date

April 29, 2024

Estimated Cost

Offline for 2 days

Victims

Type of Malware

No Malware identified

Threat Source

No threat source identified