Service disruption report for Friday 15 May 2026

Categories: Insights

The longest duration outage in FibreMax history, what happened, what a DDoS attack is, and what we are doing next.

On Friday 15 May 2026, FibreMax experienced the longest service outage in our history.

A significant internet connectivity disruption affected several of our hosted services. The incident impacted our hosted voice infrastructure, leaving many FibreMAXfone customers unable to make or receive calls normally.

Our Apology to Customers

We sincerely apologise to every customer affected by this outage.

We understand how critical phone services are to businesses. When phones go down, customers cannot get through, staff cannot communicate properly, bookings can be missed, and urgent enquiries can be delayed. For many businesses, the outage occurred during business hours, when reliable phone service matters most.

This was not the level of service we want any FibreMax customer to experience.

We are sharing this report to explain what happened, what caused the outage, what a DDoS attack is, how we restored services, and what we are doing to strengthen our resilience.

What Happened on Friday 15 May 2026?

At approximately 1.00 PM AEST on Friday 15 May 2026, some FibreMax hosted services began experiencing significant internet connectivity issues.

Our servers remained operational throughout the incident. The FibreMax phone platform itself did not fail, and the outage did not result from customer data, phone system configuration, handsets, routers, or NBN connections.

Instead, the disruption affected internet connectivity to our hosted infrastructure.

In simple terms, our servers continued running, but many users could not reliably reach them over the internet.

A large-scale Distributed Denial of Service attack, commonly known as a DDoS attack, caused the disruption. The attack targeted the network of our hosting infrastructure provider and, according to information from our hosting provider, reached approximately 400 Gbps.

That represents an extremely large volume of traffic.

All FibreMax phone services were back online by 10.00 PM AEST.

Was Customer Data at Risk?

No.

Customer data remained secure throughout the incident.

The attack targeted the network rather than FibreMax systems. It did not involve an intrusion into FibreMax systems, a hack of customer accounts, unauthorised access to servers, or a data breach.

Instead, the attackers attempted to overwhelm internet connectivity by flooding the network with traffic. This prevented legitimate users from reliably reaching the hosted services.

Although the attack significantly affected service availability, we found no indication that anyone accessed or compromised customer information, phone system settings, call data, or hosted services.

What Is a DDoS Attack?

DDoS stands for Distributed Denial of Service. It is a common form of large-scale internet disruption.

The easiest way to understand a DDoS attack is to imagine a business with a front door and a reception desk. Under normal conditions, genuine customers enter the building, speak to reception, and receive assistance.

Now imagine thousands or millions of fake visitors arriving at the same time. They do not want service. Instead, they crowd the entrance and overwhelm reception, preventing genuine customers from getting through.

That is similar to what happens during a DDoS attack.

Instead of fake visitors at a front door, attackers send massive amounts of traffic towards a network, server, or online service. The traffic can originate from many locations at the same time, often through compromised computers, servers, or devices around the world.

The target can then become overwhelmed by the sheer volume of traffic.

A DDoS attack does not need to break into a system to cause significant disruption. Attackers can make a service unreachable simply by overwhelming its network connectivity.

Why Can a DDoS Attack Affect Multiple Services?

Large DDoS attacks do not always affect just one website or server.

Modern hosting environments rely on multiple layers of internet connectivity, including data centres, routers, upstream carriers, internet exchanges, firewalls, and routing systems.

When an attack reaches a sufficient scale, it can overwhelm not only the targeted service but also the upstream network paths that carry traffic to and from that service.

In this case, the attack affected the primary upstream carrier connection used by our hosting infrastructure provider. Because the attack targeted the broader network block, multiple hosted services experienced connectivity issues at the same time.

This explains why the outage affected access to our hosted infrastructure rather than a single phone system or customer service.

Why Were FibreMAXfone Services Affected?

FibreMAXfone is a cloud-based voice service. Customer phones, mobile apps, and call-routing features connect securely over the internet to our hosted voice platform.

This connectivity allows us to provide features such as:

  • Call queues
  • Voicemail to email
  • Time-based routing
  • IVR menus
  • Mobile extensions
  • Call recording
  • Remote system management

Because we host the platform, customer devices need a reliable internet connection to reach the voice infrastructure.

During this incident, the hosted infrastructure continued running, but the internet path to it became disrupted. As a result, many customer phones could not maintain reliable registration with the platform, and calls could not process normally.

Think of it like a building with working phones inside, but a major road closure prevents people from reaching the building. The systems continue operating, but the network path to them becomes unavailable.

How Did We Restore the Service?

At approximately 6.30 PM AEST, our hosting provider engaged GSL Networks, also known as Global Secure Layer.

GSL Networks specialises in high-capacity DDoS mitigation at the internet service provider level. Its infrastructure could absorb and filter the attack traffic, allowing legitimate traffic to reach the affected network.

Once GSL Networks established the mitigation path, connectivity began to stabilise.

As routing recovered and clean traffic reached our hosted infrastructure, FibreMax services progressively returned to normal.

By 10.00 PM AEST, all FibreMax phone services had returned to normal operation.

Our Role During the Incident

Although the root cause occurred outside FibreMax’s direct infrastructure, our team remained actively involved throughout the incident.

We monitored our hosted services, followed updates from our infrastructure provider, tested service reachability as connectivity changed, and watched for signs of recovery across customer phone systems.

Our team also assessed the impact on hosted voice services as network paths returned.

We had to make careful decisions based on the information available at the time. During a DDoS event of this scale, no instant switch can restore every service immediately.

Recovery requires coordination between upstream carriers, routing changes, traffic filtering, mitigation capacity, and network stability. Some services may return before technicians fully mitigate the underlying attack, which can make the situation appear inconsistent from the customer side.

We understand that customers are not interested in technical explanations when their phones are down. Customers need their services to work. That is exactly why we are taking this incident seriously.

Our Apology to Customers

We sincerely apologise to every FibreMax customer affected by this outage.

We understand the position this placed many businesses in.

A business phone service is more than a technical product. It connects businesses with their customers and supports bookings, sales, customer support, urgent enquiries, and everyday operations.

When phones stop working, the impact can quickly spread across an entire business.

Although the incident resulted from a large-scale attack on our hosting provider’s network rather than a direct failure within the FibreMax phone platform, we recognise that customers experienced the disruption through a FibreMax service.

We take responsibility for that customer experience.

What We Are Doing Next

We are working with our hosting and network partners to review additional measures that can reduce the risk of a similar incident affecting FibreMax services.

Our review includes:

  • Additional failover options
  • Greater upstream network diversity
  • DDoS protection arrangements
  • Routing resilience
  • Business continuity planning for hosted voice services

Our goal is to maintain service availability even when a major upstream network provider experiences an incident.

We are also reviewing how we communicate during major service events. During an outage, customers need timely, clear, and practical updates. We want to improve the way we provide information during incidents, particularly when an issue occurs outside our direct infrastructure but still affects customer services.

No provider can honestly promise that large-scale internet incidents will never happen. The internet consists of many interconnected networks, carriers, hosting providers, routing paths, and infrastructure partners.

What we can promise is that when issues occur, FibreMax will act quickly, communicate as clearly as possible, work with the right technical partners, and do everything within our power to restore services as quickly as possible.

Final Update

The incident began at approximately 1.00 PM AEST on Friday 15 May 2026.

A large-scale DDoS attack targeting the network of our hosting infrastructure provider caused the disruption. The attack affected the primary upstream carrier path and created major internet connectivity issues for our hosted services.

Customer data remained secure, and no FibreMax systems were accessed or compromised.

All FibreMax phone services returned to normal by 10.00 PM AEST.

We apologise again to every customer affected.

This was the longest-duration outage in FibreMax history, and we are treating it as a serious event. We are working with our partners to strengthen resilience, improve failover capability, enhance DDoS protection, and reduce the impact of similar network-level incidents in the future.

×

Please enter your address first so we can show you the plans available at your location