Whalebone incident

Increased number of False Positives

Minor Resolved View vendor source →

Whalebone experienced a minor incident on September 11, 2026 affecting Europe (exo-01) and Europe (eu-01) and 1 more component, lasting 6d 3h. The incident has been resolved; the full update timeline is below.

Started
Sep 11, 2026, 12:18 PM UTC
Resolved
Sep 17, 2026, 03:28 PM UTC
Duration
6d 3h
Detected by Pingoru
Sep 11, 2026, 12:18 PM UTC

Affected components

Europe (exo-01)Europe (eu-01)Europe (DNS4EU)Threat Intelligence updatesAustralia (AUS-03)Threat Intelligence updates

Update timeline

  1. investigating Sep 14, 2026, 12:18 PM UTC

    We are investigating more frequent reports of False Positive domains. We are mitigating false positives reported by the clients, and we are actively investigating the root cause of the incident.

  2. investigating Sep 16, 2026, 01:54 PM UTC

    We have discovered the root cause of the False Positive Indicdent - changes in the source caused lapses in the detection logic score calculation. We have adjusted the calculation for the domains in our database received from this source, so it correctly reflects the severity/maliciousness of the detected domains. Along with this, we have launched a separate investigation to discover any potential vestigial FPs from the duration of the incident

  3. resolved Sep 17, 2026, 03:28 PM UTC

    The issue causing an increase in legitimate domains being incorrectly blocked has been resolved. We have corrected the detection scoring affected by changes in an upstream data source and removed the false-positive classifications identified during our investigation. We are closing this incident. If you still encounter a website you believe is incorrectly blocked, please contact our support team so we can review it individually. We apologise for the disruption and thank you for your patience.