On 2 December 2022 Rackspace customers began losing access to their Hosted Exchange environments. The company confirmed a ransomware incident, later attributed by its forensic investigation to the Play operation.
Rackspace’s security officer stated the root cause was CVE-2022-41080, a privilege escalation flaw in Microsoft Exchange Server, exploited as a zero-day via a technique researchers documented as OWASSRF — not the ProxyNotShell chain initially suspected. Customers were offered Microsoft 365 as a stopgap, and tens of thousands of users and domains were migrated. The Hosted Exchange service was not brought back.
The Remedy Was A Different Product
Most incidents in this corpus end with restoration: systems rebuilt, service resumed, a notification letter posted. This one ends with the service being retired and its customers moved onto a competitor’s platform.
That is a judgement that the thing was not worth restoring — commercially, operationally, or both. The corpus records the nearest equivalent at 23-0518, where the vendor’s advice was to replace the appliance rather than patch it. Here the replacement was the entire service.
Hosting Concentrates The Blast
The organisations affected were mostly small businesses that had deliberately chosen not to run their own mail server. That was a sound decision: running Exchange securely is difficult, and 2022 was a year that proved it repeatedly.
The consequence is that the difficulty was pooled rather than removed. The corpus files the same structure at 25-0917, where one backup store held every customer’s firewall configuration, and at 26-0704. Outsourcing a hard problem concentrates it; it does not solve it, and the pooled version fails for everyone at once.
The Initial Diagnosis Was Wrong
ProxyNotShell was widely assumed at the time — it was the Exchange story of that quarter and the timing fit. The forensic conclusion named a different CVE and a different technique.
The desk records this because the corpus is built from contemporaneous reporting, and this is a clean example of contemporaneous reporting being confidently wrong for several weeks. The dating discipline in the handbook exists for exactly this: what was known on 6 December and what was true are different objects.
Built on contemporaneous reporting and on Rackspace’s subsequent statements. The 2 December 2022 onset, the confirmation of ransomware, the attribution to the Play operation by Rackspace’s forensic investigation, the identification of CVE-2022-41080 rather than the ProxyNotShell chain, the OWASSRF technique as documented by researchers, the Microsoft 365 migration of tens of thousands of users and domains, and the retirement of Hosted Exchange are as reported. No figure is asserted for total customers affected — none was authoritatively published. The note about the initial ProxyNotShell assumption is drawn from the sequence of reporting itself. Graded high. Corrections: corrections@forensicpost.com.