R2 object storage disabled during a phishing report remediation
Feb 6, 08:14 UTCFeb 6, 09:36 UTC
Duration
1h 22m
Impact
Major
Root cause
Operator
Cloudflare, 90 days
50 incidents
Affected
R2Durable ObjectsStreamImagesGlobal
Lesson: Abuse tooling needs the same guardrails as production changes: scope checks and a second pair of eyes before an action can disable a whole service.
What happened
While remediating a phishing URL report, an employee disabled the R2 Gateway service instead of a single bucket. Operations against R2 failed at a 100% error rate from 08:14 to 09:13 UTC, and reconnecting clients overloaded the metadata layer until 09:36 UTC.
More from Cloudflare
Full history| Started | Incident | Impact | Duration |
|---|---|---|---|
| Sep 2318:42 UTC | Network Performance Degradation , Asia-Pacific | minor | Ongoing |
| Sep 2315:54 UTC | Elevated Errors with any / all in http_response_cache_settings | minor | 2h 14m |
| Sep 2309:08 UTC | Intermittent authentication errors for API and R2 | minor | 11h 51m |
| Sep 2308:09 UTC | Increased Errors for Durable Objects | minor | 1h 51m |
| Sep 2304:08 UTC | Elevated number of R2 503 errors in Australian Eastern Coast region | minor | 17m |
| Sep 2300:42 UTC | Issues with 1.1.1.1 for Families | minor | 44m |
Also caused by operator action
All| Started | Vendor | Incident | Impact | Duration |
|---|---|---|---|---|
| Apr 507:38 UTC | Maintenance script deletes 883 customer sites | critical | 12d 16h | |
| Feb 2817:37 UTC | Mistyped command removes S3 index servers in US-EAST-1 | critical | 4h 17m | |
| Jan 3123:00 UTC | Primary database data accidentally deleted, 18-hour restore | critical | 19h |
From vendors' own status pages and disclosures. Times as reported. Logos via logo.dev; trademarks belong to their owners.