Quick Answer — On December 2, 2022, Rackspace disclosed a “security incident” in its Hosted Exchange business; within days it was confirmed ransomware, and customers’ email stayed down for weeks. The product never came back — it was killed, and customers were migrated to Microsoft 365. The final toll: tens of thousands of paying customers offline, an ~$12M-plus incident cost per filings, and a hard lesson: a “legacy” multi-tenant platform you can’t retire quietly becomes the outage that retires you.
What happened
- December 2: Rackspace reports “security incident” and service disruption for Hosted Exchange; 911-style status updates follow. Core product: Microsoft Exchange in shared Rackspace-run infrastructure for small and midsize businesses.
- December 5–6: Company confirms it isolated the environment; incident response (CrowdStrike) engaged. Customers still blacked out.
- December 9 (8-K filing): Rackspace acknowledges the incident is expected to have a material impact; later filings estimate ~$12M incident-related costs.
- December 13: Formal statement confirms ransomware was the cause; the company pivots customers toward Microsoft 365 and begins sunsetting the legacy Exchange offering.
- Attribution: Reporting tied the intrusion to the Play ransomware operation; Rackspace kept attribution language minimal in official filings.
Impact snapshot
| Metric | Value |
|---|---|
| Service outage | Weeks for most customers; full restoration effectively never (product sunset) |
| Customer base affected | Tens of thousands of Hosted Exchange paying accounts (SMB-focused) |
| Data | Some customer data exfiltrated/staged per incident statements; mbox recovery via support ticket only |
| Direct costs | ~US$12M+ per SEC filings (response, migration credits, experts) |
| Product outcome | Hosted Exchange permanently retired; forced migration to M365 |
| Root cause themes | Legacy shared infrastructure, flat trust between tenants, single-vendor monoculture |
Why this incident structure is so brutal
Hosted Exchange was a shared-platform monoculture: one email stack, professionally run but aging, serving thousands of tenants whose businesses depended on it. That architecture multiplies ransomware’s leverage three ways. First, one intrusion becomes everyone’s outage — isolation of the environment to stop encryption meant cutting off every customer simultaneously. Second, restoration equals migration: you can’t “restore” a legacy shared platform the attackers understand better than your own runbooks; Rackspace’s pragmatic answer was to move the world to a different service. Third, communication debt compounds technical debt: early “security incident” phrasing left customers guessing for days, and each ambiguous update became its own reputational damage stream.
Timeline
| Date | Event |
|---|---|
| 2022-12-02 | “Security incident” declared; Hosted Exchange down |
| 2022-12-05 → 06 | Environment isolated; CrowdStrike engaged |
| 2022-12-09 | 8-K: material impact expected |
| 2022-12-13 | Ransomware confirmed; M365 migration path offered; product sunset begins |
| 2023 H1 | Final data exports; costs tallied ~$12M+; lawsuits and customer churn follow |
Lessons for service providers and their customers
- Legacy platforms need end-of-life security budgets. If a product can’t be modernized, its isolation, monitoring, and IR runbooks deserve more investment, not less — it’s the platform attackers know best.
- Tenant isolation is the whole game in shared infra. Flat internal trust means one foothold crosses every customer boundary; segment per-tenant paths and assume compromise of the management plane.
- Practiced restoration beats perfect prevention. Rackspace’s recovery meant mass migration, not restore — providers must know, per product, which one they’re actually capable of, and rehearse it.
- Own the comms. Affected SMBs needed day-one honesty: what’s down, what’s at risk, what to tell their own customers. Vague incident language has a body count.
- Customers: provider redundancy is cheap insurance. A secondary MX, cached mail, exported PSTs — any of these would have softened a multi-week total outage for a small business.
Why it still matters in 2026
The Rackspace incident became the reference case for supply-chain email outages as business-ending events — not because data loss was uniquely large, but because it showed continuity failing wholesale for an entire product’s customer base at once. It accelerated two shifts: providers moving SMB email to hyperscaler platforms (with the risk concentration that implies), and customers demanding contractual RTO/RPO commitments with teeth plus documented exit and export paths. In 2026’s environment of recurring MSP and provider compromises, the December 2022 lesson stands: the question isn’t only “is our provider secure” but “what happens to our business the week their platform doesn’t come back.”
Was customer data stolen?
Rackspace’s statements acknowledged data was staged/accessed for some customers during the intrusion, but the company never published a comprehensive data-impact accounting — a point of ongoing criticism and litigation. The honest summary: exfiltration was plausible-to-confirmed for portions of the base, unspecified in scope, and rendered moot for many by the product’s retirement.
Why couldn’t they just restore from backups?
Public reporting and expert analysis converge on: the compromise predated detection long enough that clean restoration of a legacy shared Exchange estate was judged infeasible within any reasonable time — hence migration as “recovery.” Shared platforms multiply restore complexity: tenant data, configs, and trust relationships interlock, and validating clean state across all of them post-ransomware is slower than rebuilding elsewhere.
What is Play ransomware?
A criminal operation (also seen as PlayCrypt) active since mid-2022, known for double extortion and repeated strikes at managed service providers and corporate email estates — including documented exploits of Exchange vulnerabilities and edge-device footholds. Attribution of the Rackspace intrusion to Play came from incident-response reporting; Rackspace itself did not formally name the group.
Part of the hmmnm.com security-timeline series — one event per month, 2021–2024, indexed here.
