Rackspace will discontinue its Exchange service after confirming hackers accessed the personal data of 27 customers during the December 2022 ransomware attack
Cloud computing giant Rackspace has confirmed hackers accessed customer data during last month's ransomware attack.
Context & Ripple Effects
Rackspace’s December security incident first forced an extended shutdown of its hosted Exchange offering, with customers reporting poor support and Rackspace warning that recovery could take days. The confirmation that customer personal data was accessed turns that operational disruption into a service-retirement decision.
The episode sits alongside the earlier ransomware lockout at web host SmarterASP.NET, where customers were also unable to access data. In Rackspace’s case, the service’s withdrawal makes the incident consequential beyond the immediate outage.
First-order effects
- Rackspace will wind down its Exchange service, requiring its remaining hosted-Exchange customers to move their email operations elsewhere.
- The confirmed access to 27 customers’ personal data expands Rackspace’s immediate response from outage recovery to breach handling for those affected customers.
Second-order effects
- Hosted-email providers gain an opening to compete for Rackspace customers leaving Exchange, while Rackspace’s prior support complaints make transition assistance a central retention issue.
- Rackspace’s service exit makes the cost of a ransomware incident visible in lost product revenue and customer relationships, not solely remediation work.
Third-order effects
- If ransomware-driven outages repeatedly end in product withdrawals, managed hosting will face greater pressure to treat recovery capability and customer support as core service commitments rather than incident-response functions.
- The comparison with SmarterASP.NET’s customer data lockout points to ransomware as a force that can reshape hosting-provider portfolios when availability failures undermine customer trust.
The trend: Ransomware is increasingly testing whether managed-service providers can preserve customer trust after an outage, not just restore affected systems.