Microsoft Investigates Widespread Microsoft 365 Outage Affecting SharePoint, Teams, and OneDrive

Microsoft is investigating a widespread Microsoft 365 outage affecting SharePoint, Teams, OneDrive, and other cloud services as a hacktivist group claims responsibility without independent evidence.
Microsoft 365 logo on a black and red background.

Update (July 24): Microsoft has completed its preliminary investigation and said the widespread Microsoft 365 outage was caused by a bug in its automated network maintenance request system, not a confirmed cyberattack. According to the company, the bug mistakenly removed IP routes from more network devices than intended during routine maintenance in its West US Azure region, disrupting connectivity for Microsoft 365 and Azure services. Microsoft also said it has found no evidence that malicious activity caused the outage.

Microsoft is investigating a widespread outage impacting multiple Microsoft 365 services after users across North America reported issues accessing SharePoint Online, Microsoft Teams, OneDrive, Excel, Power Automate, the Microsoft 365 Admin Center, and other cloud services.

The incident, tracked by Microsoft as MO1437424, began on July 23, with thousands of users reporting service disruptions. Downdetector recorded a sharp increase in outage reports, with SharePoint accounting for the majority of complaints as organizations experienced errors, slow performance, and intermittent connectivity issues. Microsoft acknowledged the incident and said engineers were investigating service telemetry and diagnostic data to determine the source of the disruption.

Services impacted

According to Microsoft’s service health updates, the outage affected multiple Microsoft 365 workloads, including:

  • SharePoint Online
  • Microsoft Teams
  • OneDrive
  • Power Automate
  • Microsoft 365 Admin Center
  • Copilot Chat
  • Microsoft Loop

Users reported issues ranging from “Something went wrong” errors in SharePoint to degraded Teams functionality, missing images in chats, intermittent OneDrive access, and slow or unavailable administrative portals.

Microsoft begins mitigation

As the outage progressed, Microsoft said it was scaling traffic rerouting efforts and implementing mitigation measures after identifying a networking-related issue affecting service availability. Later updates indicated that a networking change had been reverted and telemetry suggested services were beginning to recover while engineers continued monitoring the environment and validating restoration with affected customers.

Hacktivist group claimed responsibility

During the outage, the hacktivist group known as 313 Team, also known as the Islamic Cyber Resistance in Iraq, published Telegram posts claiming responsibility for a distributed denial-of-service (DDoS) attack targeting Microsoft’s SharePoint infrastructure. The posts included screenshots of Downdetector outage reports and asserted that multiple Microsoft 365 services had been disrupted.

Microsoft has since released a preliminary post-incident review attributing the outage to an internal networking error during routine maintenance. According to the company, a bug in its automated maintenance request system incorrectly removed IP routes from additional network devices, disrupting traffic between its West US Azure region and Microsoft’s wide-area network.

Microsoft has not identified any evidence that the outage resulted from a cyberattack. As a result, there is currently no independent evidence supporting 313 Team’s claim of responsibility.

Telegram post from 313 Team claiming responsibility for the Microsoft 365 outage and sharing Downdetector screenshots of reported SharePoint and Microsoft 365 service disruptions.
Telegram posts from 313 Team claim responsibility for the Microsoft 365 outage. Microsoft has not confirmed the disruption was caused by a cyberattack.

Microsoft publishes preliminary findings

Microsoft said the outage began at 10:44 a.m. ET on July 23 after a routine maintenance request incorrectly removed network routes from more infrastructure than intended. Engineers traced the issue to Microsoft’s West US Azure region and rolled back the networking change beginning at 1:45 p.m. ET, completing the rollback at 2:26 p.m. ET.

The company said service telemetry confirmed recovery after the rollback, with affected Microsoft 365 and Azure services returning to normal later that afternoon. Microsoft is conducting a full post-incident review and said it plans to publish a final root cause analysis after completing its internal investigation.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site