TrekkSoft global issue affecting several production functionalities
Incident Report for TrekkSoft
Postmortem

What was the cause of the issue?

TrekkSoft was targeted by a DDOS attack, which affected the availability of the system to our users. DDOS is a type of cybercrime where an unknown attacker is flooding the servers with high internet traffic, that is preventing users from accessing our system. You can read more about what DDOS attack is and how it works here.

This particular DDOS attack generated an abnormal spike (1000x higher) in HTTP requests, which overloaded our servers.

Impact

The impact was global and most of the Trekksoft services were affected for all our customers.

What did we do?

As soon as the attack was initiated around 8am CEST, our developers started working on identifying the root cause of the issue. Once the cause was identified as a DDOS attack, we started working on preventing it by blocking the source of abnormal activity, as well as improving the configuration of the firewall solution.

The mentioned solution was fully configured at roughly 1pm CEST, when we started seeing improvements and our system was again accessible as well as bookings started coming in. Performance of features was still impacted until all the issues from the attack were resolved at around 7pm CEST. After that all the services were again performing as expected, and we continued to monitor the situation closely until the next day. We subsequently confirmed that the incident was resolved.

Learnings

DDOS attacks are well thought through cyber crimes, using new methods and technologies, which renders them unpredictable and challenging to neutralize.

In the aftermath of the recent attack, we are further improving our firewall protection, as well as investigating and expanding into new 3rd party solutions designed for tackling external security threats. These extra layers of protection will further add to the resilience of our system in similar situations.

Posted Jul 25, 2022 - 17:32 CEST

Resolved
The incident has been resolved and all the Trekksoft functionalities are again operational as normal.

We will provide a postmortem of the incident in the following days.

Once again we want to apologize for any inconvenience this might have caused you.
Posted Jul 21, 2022 - 10:28 CEST
Update
Trekksoft functionalities had been stable since the last update and we are observing that the speed of services has stabilised as well.

We will continue to monitor the situation closely.
Posted Jul 20, 2022 - 21:53 CEST
Monitoring
Trekksoft functionalities are again operational for the vast majority of our users, however, you might be still experiencing some issues such as reduced speed.

We keep working on this and monitoring the situation.
Posted Jul 20, 2022 - 17:09 CEST
Update
TrekkSoft is currently being targeted by a DDOS attack, which affects the availability of the system to users. DDOS is a type of cybercrime where an unknown attacker is flooding the servers with high internet traffic, that is preventing users from accessing our system.

Please note that the DDOS attack affects the availability of the system to users. The attack does not compromise user data held in the system, i.e. there is no breach of private data.

As we implement solutions, there are time frames where the system is operational. We recommend that, if you are able to access your account at any point, you download the data which you need to run your daily operations.

We continue to work hard on addressing this malicious activity, and resolve it as soon as possible.

We will keep you updated and apologize for the inconvenience caused.
Posted Jul 20, 2022 - 14:33 CEST
Identified
Our developers identified the cause of the issue and are currently working on it's resolution.

We will keep you updated and apologize for the inconvenience caused.
Posted Jul 20, 2022 - 09:35 CEST
Update
We are continuing to investigate this issue.
Posted Jul 20, 2022 - 08:42 CEST
Investigating
We are currently experiencing global issues in several Trekksoft production functionalities (a.o. Backoffice, POS Desk)

Our developers are already investigating on finding the root cause of the issue.

We will keep you updated and apologize for the inconvenience caused.
Posted Jul 20, 2022 - 08:30 CEST
This incident affected: TrekkSoft Application, TrekkSoft API, Backend Mobile Applications, POS Desk, and TrekkSoft Website.