RSA ID Plus Service Incident (EMEA Region)

Incident Report for RSA ID Plus

Postmortem

Summary

On June 4, 2026, between approximately 04:48:49 UTC and 05:00:18 UTC, customers hosted in the RSA EU West production environment experienced intermittent authentication failures and service degradation resulting from a cloud-provider networking event.

What Happened

During the incident window, RSA services experienced connectivity disruptions to underlying cloud infrastructure dependencies within our cloud provider environment. These connectivity issues impacted communication between application components and supporting platform services required for authentication processing.

As a result, authentication requests were intermittently unable to complete successfully, resulting in customer-facing service degradation.

Timeline of Events

Application telemetry indicates the event consisted of multiple periods of degradation and recovery as the underlying cloud-provider networking infrastructure stabilized and recovery operations were processing. While customer impact was observed between approximately 04:49 UTC and 05:00 UTC, the severity of the event fluctuated during that period rather than remaining constant throughout.

Root Cause

RSA completed an investigation in collaboration with our cloud provider.

The incident was caused by a planned cloud provider platform maintenance activity that resulted in unexpected instability within shared networking infrastructure servicing cloud platform dependencies in the EU West region.

The networking instability affected connectivity between RSA application services and cloud platform services required for authentication processing, including caching and storage dependencies used by the authentication platform.

As part of the investigation, RSA confirmed that the affected systems were distributed across multiple independent infrastructure groups, as required by the architecture of ID Plus. This distribution is a foundational design principle of the EU West environment and is intended to isolate routine maintenance activities and localized infrastructure failures from causing broader service impact.

However, the cloud provider determined that this event involved shared networking infrastructure servicing multiple infrastructure groups simultaneously. As a result, systems that would normally operate independently experienced connectivity degradation at the same time, reducing the effectiveness of the within-region resiliency mechanisms designed to protect against localized infrastructure events.

The cloud provider further determined that the maintenance activity did not proceed as expected and resulted in networking instability that exceeded the duration and recovery characteristics normally associated with routine platform maintenance activities. RSA services are designed to tolerate the brief transient interruptions that can occur during normal cloud platform maintenance operations, and the behavior observed during this incident was not representative of the brief interruptions typically expected during standard maintenance events.

Resolution

RSA engineering teams responded to the incident, validated service recovery, and engaged the cloud provider to perform a detailed review of the underlying infrastructure event.

During the incident, RSA monitoring and automated service recovery mechanisms detected the degradation and initiated standard recovery actions designed to maintain service availability and recover application health. These actions included automated platform health monitoring and workload recovery processes operating within the affected environment.

Service stability was restored as connectivity within the underlying cloud provider infrastructure recovered and networking services stabilized. Once connectivity was re-established, application services returned to normal operation and customer authentication processing resumed successfully.

Posted Jun 30, 2026 - 23:12 UTC

Resolved

On June 4, 2026, between approximately 04:48:49 UTC and 05:00:18 UTC, customers hosted in the RSA EU West production environment experienced intermittent authentication failures and service degradation resulting from a cloud-provider networking event.
Posted Jun 04, 2026 - 04:30 UTC