Landbot Domain Suspended
Incident Report for Landbot
Postmortem

On 05/05 Landbot.io suffered a major incident with an impact on all features and customers. The root cause of this incident was
a suspended domain of landbot.io due to the misuse of our bots in phishing activities.

Main activities held and their timelines:

04/05 (01:34) CEST - Our provider send us an email informing us that some of our bots were being used in phishing activities and that if we did nothing our domain was going to be suspended.
04/05 (15:50) CEST - By this time, we told our provider that we had already stopped those bots.
05/05 (00:50) CEST - Our provider informed us again of more bots being used for phishing attacks.
05/05 (01:40) CEST - Our Domain was suspended.

05/05 (07:30) CEST - We contacted our provider for support but we did not get a prompt action because their department was in another timezone and they did not had 24x7 support.
05/05 (08:40) CEST - We were able to reestablish some of the bots in a new existing domain (with some limitations)
05/05 (11:00) CEST - We bought a temporary domain and started moving all the bots to the new domain.
(...) We continued to try to talk with our provider on multiple channels (LinkedIn, Phone) to see if we could get a prompt response.
05/05 (13:00) CEST - We finished moving all bots to the new domain.
05/05 (15:00) CEST - We were finally able to get a call to our provider in Az to see if they could unblock our domain.
05/05 (16:10) CEST - After 1 hour on a call, we were finally notified that the issue has been fixed.
05/05 (16:40) CEST - We had restored full service.

Main Actions to Take:

  • Review our On-Call program. There were a couple of hours between the incident and us acknowledging it. This was due to us relying on email for alarmistic and we did not receive emails due to the domain suspension.
  • Review the Incident Management process. There are some improvements we can do to speed up our process, mostly regarding the organization of the incident.
  • Proactive identification of abuse use cases and finding protection measures for bots not being used for malicious purposes.
  • Find a domain provider with better worldwide support (24x7)
  • Review our abuse policies & terms of use

We really want to thank our customers for their empathy and support during this incident.

Posted May 11, 2022 - 20:43 CEST

Resolved
Landbot.io suffered a major incident with an impact on all features and customers. The root cause of this incident was
a suspended domain of landbot.io due to the misuse of our bots in phishing activities.
Posted May 05, 2022 - 01:30 CEST