Friday July 24th, 2026
0800 PT: All systems are operating as expected. Incident Closed.
Thursday July 23rd, 2026
2000 PT: All services restored and operating as expected. Will continue to monitor until tomorrow morning. Next update by 0800 PT.
1600 PT: Command Center and EJ Archiving services are restoring now. Still working on a few back end services and SAN. Next update by 2000 PT.
1500 PT: Still working with MS support to recover our services. Next update by 1600 PT.
1400 PT: Microsoft reports the issue as resolved however our services have not recovered. Our team is attempting to cycle our services while escalating with MS support. Command Center, EJ Archiving and SAN continue to remain down. Conveyance is processing deposits but the portal is unavailable. Next update by 1500 PT.
1200 PT: Conveyance deposit images are successfully uploading and being sent to processors. Microsoft is still working to restore funcationality and our other services are still affected. Next update by 1400 PT.
1130 PT: Microsoft is still working to restore funcationality. We have confirmed that this interruption is also affecting Conveyance deposit image uploads and will prevent deposit processing. We are looking into alternatives if Azure is not restored soon. Next update by 1400 PT.
1000 PT: Microsoft is still working to restore functionality to their WESTUS data center. Next update by 1200 PT.
0910 PT: Microsoft Azure is reporting an issue with WESTUS datacenters that appear to be affecting our services. Microsoft has a P1 issue opened and is troubleshooting. Next update by 1000 PT.
0900 PT: Our Service Request system used to dispatch field technicians is also affected and may result in delays to service. Next update by 0930 PT.
0830 PT: We are aware of an issue that may be affecting our SAN and Electronic Journal Archiving service. Our team is currently investigating the cause. Next update by 0930 PT.
We have received multiple reports of an increase Man in the Middle (MITM) attacks targeting ATMs in the Pacific Northwest and across the United States. All ATM manufacturers are susceptible to this type of attack which targets the physical network infrastructure. A key difference with this current round of MITM attacks is they can defeat basic TLS 1.2.
We recommend the following actions are taken immediately:
· Verify top hat of ATM is alarmed and create a response plan for active alarms to include historical footage review.
· Contact your ATM Host to confirm availability of TLS 1.2 Enhanced.
· Confirm BIOS and firmware are up to date with the latest security releases.
· Verify HDE encryption is enabled on all ATMs.
· Inspect for tampering daily.
· Increase monitoring through Command Center or other remote management tools.
· Report any suspicious activity to the NOC immediately.
These attacks are highly coordinated and often occur after hours. Quick reporting and verification of system integrity are critical in preventing losses. For RVATM users you can confirm HDE, BIOS version and TLS 1.2 Enhanced via Command Center. If you have any questions, please open a ticket with our Support team by visiting cc.cooksolutionsgroup.com or via email at Support@cooksolutionsgroup.com.