New DDoS attack impacting all services and websites
Incident Report for SMSFactor
Postmortem

🇬🇧

On 30th October, the platform was rendered unavailable due to a sustained Denial of Service (DDoS) attack from a threat actor. While no unauthorized access occurred, and no customer data was impacted, the volume of the attack prevented platform use until service was fully restored. In response, we expanded our DDoS protection to better manage this and any future attacks. Configuring these enhancements required some adjustments over the following days, leading to minor service interruptions, which have now been fully resolved.

🇫🇷

Le 30 octobre, la plateforme a été rendue indisponible en raison d'une attaque par déni de service (DDoS) soutenue provenant d'un acteur malveillant. Bien qu'aucun accès non autorisé n'ait eu lieu et qu'aucune donnée client n'ait été affectée, le volume de l'attaque a empêché l'utilisation de la plateforme jusqu'à ce que le service soit entièrement rétabli. En réponse, nous avons étendu notre protection contre les attaques DDoS pour mieux gérer cette attaque et toute attaque future. La configuration de ces améliorations a nécessité quelques ajustements au cours des jours suivants, entraînant des interruptions mineures du service, qui ont maintenant été entièrement résolues.

Posted Nov 12, 2024 - 09:37 CET

Resolved
This incident has been resolved.
Posted Nov 12, 2024 - 09:32 CET
Update
As you know by now, we've been DDoS'ed again today with an unprecedented force. Cloudflare managed to filter most of the unwanted requests but still too many were passing through. We had to work on the filters to enhance the efficiency of the firewall so that it reflects our needs the best way possible. Things are looking stable as of now but we remain vigilant and ready to intervene in case another wave occurs.

Thank you for your patience. If you need any help or if you have any question, please send an email to support@smsfactor.com
Posted Oct 31, 2024 - 17:43 CET
Monitoring
A fix has been implemented and we are monitoring the results.
Posted Oct 31, 2024 - 14:41 CET
Investigating
Cloudflare has already detected the attack and is taking action. We'll keep you updated soon.
Posted Oct 31, 2024 - 12:34 CET
This incident affected: API and Customers Portal.