Seravo incident

Networking issue in cluster fi-sestak

Major Resolved View vendor source →

Seravo experienced a major incident on September 21, 2026 affecting fi-sestak cluster, lasting 1h 47m. The incident has been resolved; the full update timeline is below.

Started
Sep 21, 2026, 10:16 AM UTC
Resolved
Sep 21, 2026, 12:03 PM UTC
Duration
1h 47m
Detected by Pingoru
Sep 21, 2026, 10:16 AM UTC

Affected components

fi-sestak cluster

Update timeline

  1. identified Sep 21, 2026, 10:16 AM UTC

    We identified a networking issue in cluster fi-sestak. Our team is working on it to fix it. We apologise for any inconvenience.

  2. resolved Sep 21, 2026, 12:03 PM UTC

    This incident has been resolved.

  3. postmortem Sep 22, 2026, 10:06 AM UTC

    ## DDoS attack at FI-Sestak On Monday, June 21, 2026, Seravo's server cluster FI-Sestak became a target of a large-scale DDoS attack. DDoS stands for Distributed Denial of Service, a malicious cyberattack that floods a server with overwhelming internet traffic to make it unresponsive and stop working for real users. ‌ The attack started at 12:45 \(UTC\+3\). During the attack most of the websites hosted in FI-Sestak experienced degraded service, but there was no other security threat to the sites. Visitors received connection timeouts or HTTP502 errors while trying to visit the sites. ‌ At approximately 13:15, an incident occurred in another cluster, FI-Ellington, initially raising concerns that the incident might be related to the DDoS attack in FI-Sestak. No indication of a connection between the two incidents was found. However, the overlap temporarily diverted attention and delayed recovery of FI-Sestak. ‌ As a part of our response, we deployed new tooling to assist with mitigating an attack like this in the future. The tooling proved useful during the incident and will be retained in our toolkit for similar incidents in future. ‌ The attack ended at approximately 14:20, after which we continued to monitor the situation. The incident was marked as resolved on our end at 15:03. ‌ We apologize for the inconvenience caused by this attack. ‌ Seravo provides real-time updates on all disruptions at [status.seravo.com](http://status.seravo.com). We highly recommend subscribing to incident notifications via email, for example. ## Timeline \(UTC\+3\) * 12:45 DDoS starts * 12:49 First signs of abnormal web traffic * 12:55 First blocks deployed to mitigate the attack * 13:15 A simultaneous, unrelated issue in another server cluster slows down investigation * 13:45 New tooling deployed * 14:08 New tooling proves effective * 14:20 DDoS ends * 15:03 Incident marked as resolved