Azure VM Security Incident – Immediate Support Required

Jessi Software 0 Reputation points
2025-12-04T08:49:24.0633333+00:00

We had a virtual machine named <removed PII>. On 22-Dec, we observed that the VM was impacted by a ransomware attack. We immediately shut down the VM and created a new one. Our key requirements and concerns are as follows:

  1. We need to recover the data from the affected VM.
  2. Since it is a managed machine, we assumed Microsoft would protect it from such attacks. We request the RCA (Root Cause Analysis) for the ransomware incident.
  3. What guarantees and mitigation measures are in place to prevent similar attacks on the newly created VM?
  4. Although the affected VM has been stopped for the past two weeks, we are still being billed for associated resources. How can we request a waiver for these charges? 

R.Vaira Selvam

REMOVED PII

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.