Menu
Browse

Cyber Incident Victim: Oxford United Football Club

Date:

Jul 2023

Location:

United Kingdom

Summary

Oxford United Football Club reported that online members were unable to access online ticketing and club shop services due to a Microsoft outage. The outage resulted from a distributed denial-of-service attack on Azure that triggered protection mechanisms which initially worsened the impact. The outage also affected services such as Teams, Xbox Live, and NatWest banking services before being resolved after network changes. The club confirmed the issue prevented online members from accessing online ticketing and club shop services.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On Tuesday a distributed denial‑of‑service attack targeted Microsoft’s Azure cloud platform, triggering the company’s DDoS protection mechanisms. The protection had been misconfigured during a recent rollout, which caused it to amplify the attack rather than mitigate it. Microsoft responded by making network configuration changes that reduced the traffic load and eventually restored normal operation. The company later stated that the issue had been resolved.

Cyber Incident Image

The disruption affected a range of Microsoft services, with users reporting problems accessing Teams, Xbox Live and other applications. External organisations also experienced difficulties; NatWest apologised to customers who could not reach some of its webpages. Oxford United Football Club used its X account to inform members that the outage prevented them from using the club’s online ticketing system and club shop. The club’s post confirmed that online members were unable to complete purchases or access ticketing services during the incident.

Microsoft said its initial investigations found that an error in the rollout of its own defences had amplified the impact of the attack. The company indicated it would publish an incident review within 72 hours to provide further detail on what occurred. Oxford United Football Club’s statement on X served as the primary public communication from the club regarding the service interruption.

Sources
Sources available to members
1 source