{
"vendor": "Box",
"slug": "box",
"platform": "statuspage",
"status_url": "https://status.box.com",
"last_checked": "2026-09-16T12:28:20Z",
"last_state": "ok",
"history_backfilled": true,
"first_watched": "2026-09-04T07:06:16Z",
"incidents": [
{
"body": "_Notice and disclaimer: Box is providing this preliminary information subject to further review and analysis. To the best of our knowledge, this is the current state and we may update as more information is confirmed._\n\nOn September 3, 2026 between 3:30 PM PDT and 7:12 PM PDT, some customers may have experienced missing, delayed, or inaccurate results within admin reporting features, including AI usage reports, in Box. Reports may have shown empty fields or data that did not reflect recent activity.\n\nThe issue was caused by an outage in a third\u2011party data service that interrupted our data ingestion pipelines. Service availability was restored after the provider mitigated the problem.\n\nWe are conducting a full engineering postmortem and our overview is subject to change with further analysis and findings. In the event our continuing investigation yields further substantive findings, we may publish additional analysis after the conclusion of the full engineering postmortem.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-09-03T20:03:26.934-07:00",
"resolved_inferred": false,
"started_at": "2026-09-03T19:10:06.402-07:00",
"state": "postmortem",
"title": "[Minor] Issue with Admin Reporting",
"updated_at": "2026-09-15T14:27:10.672-07:00",
"url": "https://stspg.io/jpryz8xs8k4r"
},
{
"body": "_Notice and disclaimer: Box is providing this preliminary information subject to further review and analysis. To the best of our knowledge, this is the current state and we may update as more information is confirmed._\n\nBetween August 27, 2026 at 11:18 PM PDT and August 28, 2026 at 2:48 AM PDT some customers may have been unable to access Box Hubs using shared links. Other Box functionality, such as file and folder access, was not broadly affected. \n\nThe issue occurred as a result of a recent code change in our ongoing effort to improve performance. We were able to resolve the issue by rolling back the change so traffic returned to the previous behavior. \n\nWe are conducting a full engineering postmortem, including a review of our deployment and configuration practices, to reduce the chance of similar issues in the future. Our overview is subject to change with further analysis and findings. In the event our continuing investigation yields further substantive findings, we may publish additional analysis after the conclusion of the full engineering postmortem.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-08-28T03:00:41.109-07:00",
"resolved_inferred": false,
"started_at": "2026-08-28T01:20:35.272-07:00",
"state": "postmortem",
"title": "[Medium] Issues with Box Hubs Shared Links",
"updated_at": "2026-09-06T15:49:44.165-07:00",
"url": "https://stspg.io/st2mtmmbkz5c"
},
{
"body": "After further monitoring, this incident is now considered resolved. If you continue to experience any issues, please contact Box Support at https://support.box.com.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-08-25T00:37:39.283-07:00",
"resolved_inferred": false,
"started_at": "2026-08-24T23:53:37.438-07:00",
"state": "resolved",
"title": "[Critical] Issue with Downloads",
"updated_at": "2026-08-25T00:37:39.316-07:00",
"url": "https://stspg.io/wyyrssnxky67"
},
{
"body": "We recently addressed issues affecting file uploads and other write operations within Box. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\nBetween 02:03 PM and 02:24 PM PDT on August 24, 2026, some users may have experienced difficulties while working in Box. During this time, users saw elevated error rates and reduced availability for uploads and other write-oriented actions.\n\nThe issue occurred when a background user-cleanup process generated a sudden surge of database update activity that was amplified by an unbounded retry loop, which overloaded a database shard and exhausted connection capacity. We restored normal service by applying a rate limit to the cleanup traffic and stopping the offending cleanup workload. After traffic subsided, we removed the temporary limits once systems were stable. In addition, we are making changes to limit background cleanup traffic and improve retry behavior to reduce the chance of recurrence.\n\n# Analysis\n\nFollowing this incident, we are now improving how similar types of background jobs are managed and retried, and making adjustments to better prioritize customer-facing operations over these tasks. Specifically, during this issue, rapid retry cycles amplified service friction, highlighting areas where additional safeguards can further protect against similar issues occurring again in the future. We are also reviewing rollout and feature-flag practices to avoid accidental large-scale job generation.\n\n# Corrective Actions\n\nBox has initiated the following corrective actions:\n\n* Implementing bounded exponential-backoff retries for background cleanup jobs.\n* Enforcing throttling and monitoring on background cleanup traffic so it cannot overwhelm write-path resources.\n* Introducing priority-aware protections so low-priority background work is shed before it affects customer-facing operations.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-08-24T15:03:07.119-07:00",
"resolved_inferred": false,
"started_at": "2026-08-24T14:21:52.400-07:00",
"state": "postmortem",
"title": "[Medium] Issue with Uploads",
"updated_at": "2026-09-10T17:13:37.300-07:00",
"url": "https://stspg.io/jlrhnrtb4pnf"
},
{
"body": "Between 3:44 PM and 4:27 PM PDT on August 19, 2026 and 10:28 AM and 11:21 AM PDT on August 24, 2026, some users may have experienced intermittent errors with some Box features, including Logins, Uploads, Downloads, and Box Sign.\n\nThe issues occurred after a rapid surge of external Box client connections overwhelmed front-end capacity in the affected region, which caused an increase in server-side error rates and prevented some requests from reaching our back-end services. We restored service by working with our cloud provider and applying operational mitigations until front-end error rates returned to normal and user requests succeeded again.\n\n# Analysis\n\nThis incident highlighted opportunities to improve our detection and correlation of frontend/load balancer health signals with our application telemetry and to strengthen joint monitoring and mitigation processes with our cloud provider during large-scale client connection events. It also underscored the importance of clearer detection thresholds and runbook steps for frontend degradations, so we can escalate and remediate faster without over or under communicating impact to customers.\n\n# Corrective Actions\n\nBox has initiated the following corrective actions:\n\n* Improving monitoring and observability for large-scale client connection events and working with our cloud provider on coordinated mitigation strategies.\n* Coordinating with our cloud provider to ensure connection rates are within expected thresholds.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-08-24T10:30:00.000-07:00",
"resolved_inferred": false,
"started_at": "2026-08-24T08:30:00.000-07:00",
"state": "postmortem",
"title": "[Minor] Issue with Logins & Files Page",
"updated_at": "2026-09-10T17:15:35.353-07:00",
"url": "https://stspg.io/ptjpkj753hy3"
},
{
"body": "From approximately 2:42 AM to 2:45 AM PDT (US Pacific Time), we observed an issue impacting Box Notes. Our systems automatically detected and corrected the underlying issue. There is no current impact and no further updates will be provided here. If you continue to experience any issues, please contact Box Support at https://support.box.com.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "none",
"last_seen": "2026-09-08T12:29:58Z",
"resolved_at": "2026-08-21T02:45:00.000-07:00",
"resolved_inferred": false,
"started_at": "2026-08-20T15:00:00.000-07:00",
"state": "resolved",
"title": "[Minor] Issues with Box Notes",
"updated_at": "2026-08-21T04:09:24.717-07:00",
"url": "https://stspg.io/fjshz04251vs"
},
{
"body": "We recently addressed issues affecting Box Edit, Microsoft Office Online, iWork, and other integrations in Box. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\n\u200c\n\nBetween 04:17 PM PDT and 6:30 PM PDT on August 19, 2026 some users may have experienced difficulties while working in Box. During this time, impacted users were unable to open files in Box Edit, Microsoft Office Online, iWork, and other integrations. Additionally, some users saw errors, timeouts, or slow responses while working in other areas of Box.\n\n\u200c\n\nThe issue occurred after a deployment of a backend service that provides integration and platform functionality. The deployment introduced a regression that caused the service\u2019s performance to degrade under peak load, which led to client timeouts and errors. We restored functionality by reverting the deployment to a previous version. We are taking steps to reduce recurrence by improving our pre-release validation and deployment safeguards, including validating the performance of the service under load, improving observability, and making defensive changes to the affected service.\n\n\u200c\n\n# Analysis\n\n\u200c\n\nThis incident highlighted opportunities for improving our pre-release validation to test how a change behaves under peak traffic. In this situation, a change in a backend service which handles integration and platform functionality modified its scalability characteristics under load. The service operated normally during non-peak traffic but was not able to keep up with peak traffic demand. Under peak load, the service\u2019s thread pool became saturated, causing requests to queue while waiting for an available worker and increasing latency.\n\n# Corrective Actions\n\nBox has initiated the following corrective actions:\n\n* Strengthening pre-release validation to include tests that better simulate peak traffic and scaling behavior for the affected service.\n* Improving observability so that scaling issues are more readily detected.\n* Implementing defensive changes in the affected service to reduce impact if a similar performance degradation were to occur.\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\n\u200c\n\nSincerely,\n\n\u200c\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-08-19T18:44:28.049-07:00",
"resolved_inferred": false,
"started_at": "2026-08-19T17:31:23.000-07:00",
"state": "postmortem",
"title": "[Medium] Issue with Microsoft Office Integration and Box Edit",
"updated_at": "2026-09-09T15:43:55.797-07:00",
"url": "https://stspg.io/ybdp1knrj9qt"
},
{
"body": "_Notice and disclaimer: Box is providing this preliminary information subject to further review and analysis. To the best of our knowledge, this is the current state and we may update as more information is confirmed._\n\nOn August 19, 2026 between 3:44pm PDT to 3:49pm PDT, some users may have experienced difficulties while working in Box. When attempting to access Box during this time, some users may have seen an error message. Preview, and Box Notes functionalities were impacted. This occurred because of an issue affecting Box\u2019s critical third party cloud ingress services.\n\nWe are conducting a full engineering postmortem in conjunction with our cloud provider, and our overview is subject to change with further analysis and findings. In the event our continuing investigation yields further substantive findings, we may publish additional analysis after the conclusion of the full engineering postmortem.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-08-19T15:00:00.000-07:00",
"resolved_inferred": false,
"started_at": "2026-08-19T15:00:00.000-07:00",
"state": "postmortem",
"title": "[Medium] Issues with Multiple Box Services",
"updated_at": "2026-08-21T11:09:28.474-07:00",
"url": "https://stspg.io/xslc1vyl1t88"
},
{
"body": "After further monitoring, this incident is now considered resolved. All Files Page Service has been restored to full functionality. If you continue to experience any issues, please contact Box Support at https://support.box.com.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-08-19T05:03:02.576-07:00",
"resolved_inferred": false,
"started_at": "2026-08-19T04:38:19.903-07:00",
"state": "resolved",
"title": "[Minor] Issues with All Files Page",
"updated_at": "2026-08-19T05:03:02.595-07:00",
"url": "https://stspg.io/s2cb5jfx5gj3"
},
{
"body": "_Notice and disclaimer: Box is providing this preliminary information subject to further review and analysis. To the best of our knowledge, this is the current state and we may update as more information is confirmed._\n\nOn Aug 6, 2026 between 6:42 PM PDT and 6:48 PM PDT and again between 7:27 PM to 7:33 PM PDT, some customers may have experienced intermittent failures affecting login, uploads/downloads, Notes, Box AI, and API access in Box.  The disruptions were caused by a temporary resource exhaustion on our front\u2011end infrastructure. \n\nWe are conducting a full engineering postmortem and our overview is subject to change with further analysis and findings. In the event our continuing investigation yields further substantive findings, we may publish additional analysis after the conclusion of the full engineering postmortem.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-08-06T22:16:57.766-07:00",
"resolved_inferred": false,
"started_at": "2026-08-06T19:37:34.595-07:00",
"state": "postmortem",
"title": "[Medium] Issues affecting multiple Box services",
"updated_at": "2026-08-10T19:52:50.558-07:00",
"url": "https://stspg.io/ybhf2bqz17mf"
},
{
"body": "On August 4, 2026 between 12:10 PM PDT and 1:20 PM PDT, some customers experienced failures and delays when uploading files to Box. The problem was caused by a routing issue on our frontend load balancers. We restored service by rerouting upload traffic and provisioning additional capacity.\n\n# Analysis\n\nA temporary network connectivity disruption impacted a small part of our load balancing fleet, causing a spike of TCP retransmit errors. Our engineering team mitigated the impact by redirecting traffic away from the affected region, which restored normal upload operations and resolved the errors. This incident highlighted opportunities to improve observable signals and alerting for TCP retransmit errors.\n\n# Corrective Actions\n\nBox has initiated the following corrective actions:\n\n* Improve monitoring and alerting for the isolated TCP retransmit issues. \n* Review and update operational runbooks for isolating problematic instances and for capacity management to shorten time to mitigation.\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-08-04T13:44:52.273-07:00",
"resolved_inferred": false,
"started_at": "2026-08-04T13:23:03.393-07:00",
"state": "postmortem",
"title": "[Medium] Issues with Uploads and Downloads",
"updated_at": "2026-08-24T10:02:23.873-07:00",
"url": "https://stspg.io/ldkcrysdxtkd"
},
{
"body": "We recently addressed issues affecting Shuttle standalone jobs. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\nBetween 3:41 AM and 3:57 AM PDT on July 31, 2026, some customers using Shuttle Standalone could sign in to their Shuttle Standalone accounts and view their dashboards, but could not view job details, change job settings, or create new standalone jobs. The Shuttle native experience was not affected. After we restored service, we confirmed that customers could access existing jobs and create new ones. \n\n# Analysis\n\nA misconfiguration in Shuttle resulted in depleted resources that accessed job history. This caused Shuttle pages that load job history to time out. We restored access by restarting the affected services at 3:57 AM PDT. Job management returned to normal, with no recurrence. This briefly blocked the standalone experience for affected customers, even though sign-in and the Shuttle native experience continued to work.\n\n# Corrective Actions\n\nBox has initiated the following corrective actions:\n\n* Updating the capacity allocation to avoid the recurrence of this issue\n* Adding monitoring to better preempt the issue from occurring \n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-07-31T04:30:17.820-07:00",
"resolved_inferred": false,
"started_at": "2026-07-31T04:09:34.000-07:00",
"state": "postmortem",
"title": "[Medium] Issues with Box Shuttle Standalone",
"updated_at": "2026-08-18T17:20:08.934-07:00",
"url": "https://stspg.io/vyz7j1dv5zqj"
},
{
"body": "We recently addressed issues affecting file uploads and edits that create new file versions. We want to explain what happened and what we have done to prevent it from happening again. \n\nBetween Jul 26, 2026 4:38 PM PDT and Jul 28, 2026 10:34 AM PDT, some users may have experienced delays or failures when uploading files or saving edits that create new file versions. The impact was limited to cases with a high number of concurrent uploads or edits on the same file.\n\nDuring this period, concurrent upload and edit traffic contended on shared database locks while creating new file versions. Under load, an overly conservative insert locking strategy acquired locks, creating a bottleneck in the database. The contention was amplified by background processes that post-process the uploaded file and attach additional information to every new version, competing for the same locks.\n\n# Analysis\n\nThis incident highlighted several opportunities for improvement:\n\n* Lock-wait failures do not appear in our usual change-stream / mutation telemetry, which delayed our investigation. \n* Background processes can contend with upload and edit paths that create new versions. Our development environments did not fully test this particular interaction under load.\n\nRemediation combined an immediate reduction in non-essential background scan load with a code change that relaxed the overly conservative locking behavior, while preserving the intended isolation guarantees.\n\n# Corrective Actions\n\nBox has initiated the following corrective actions:\n\n* Deploy and validate the insert-behavior fix across all live clusters \\(completed and confirmed\\).\n* Improve observability for lock-wait and timeout-driven load so contention sources are visible.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-07-27T21:57:55.766-07:00",
"resolved_inferred": false,
"started_at": "2026-07-27T19:58:26.496-07:00",
"state": "postmortem",
"title": "[Minor] Issues with Uploads",
"updated_at": "2026-08-12T16:06:02.323-07:00",
"url": "https://stspg.io/p6nj49jzsjbs"
},
{
"body": "We recently addressed an issue affecting Box Hubs. We\u2019d like to take this opportunity to explain what happened and the steps we\u2019ve taken to prevent it from happening again. \n\nBetween 06:50 AM PDT to 07:26 AM PDT on July 23, 2026, some users may have experienced difficulties while working in Box. During this time, users attempting to access Box Hubs were unable to load the Hubs gallery and instead encountered a \"Not Found\" page. The issue occurred as a result of a recent frontend dependency update, which introduced a package version conflict that prevented the Hubs module from loading correctly. We were able to resolve the issue by rolling back the frontend application to the previous stable version, which fully restored access to Box Hubs. In addition, we are working to improve our automated pre-release testing processes to ensure that dependency updates are validated across all affected modules before reaching production, and we are enhancing our monitoring and alerting capabilities to detect and surface similar issues more quickly, to prevent similar issues from occurring in the future.\n\n# **Analysis** \n\nAt the technical level, a shared package used by the core web application and the Hubs page module fell out of version alignment when the core application upgraded the dependency without a corresponding update in the Hubs module. This caused the Hubs page to crash at load time. The regression was not caught before reaching production because pre-release automated tests were scoped to core application features and did not cover dependent page modules. Once in production, detection was slowed by monitoring gaps, meaning the incident was ultimately surfaced by synthetic monitoring rather than production observability tooling.\n\n# **Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Improving frontend error monitoring to clearly attribute client-side errors to specific pages, enabling faster detection of page-level failures in production.\n\n* Enhancing module-level observability and alerting to detect load-time failures for modules. This will ensure we are fully aware of any issues in the integration of sub-modules \\(such as Hubs\\) with the core web app as early as possible.\n* Expanding pre-release automated smoke tests to cover all page modules dependent on the core web application, ensuring that package version conflicts are caught in the release pipeline before reaching production.\n* Improving staging environment alerting to surface potential regressions earlier in the release process, before changes are promoted to production.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-07-23T07:30:22.894-07:00",
"resolved_inferred": false,
"started_at": "2026-07-23T07:14:47.603-07:00",
"state": "postmortem",
"title": "[Medium] Issues with Box Hubs",
"updated_at": "2026-08-10T19:51:06.990-07:00",
"url": "https://stspg.io/vh4zgdtq8z4x"
},
{
"body": "We recently addressed an issue affecting metadata updates using File Request in Box. We would like to take the opportunity to further explain the issue and the steps we have taken to keep similar issues from happening in the future.\n\nBetween 09:10 AM PDT on July 22, 2026 and 03:36 PM PDT on July 23, 2026, some users may have experienced delays in metadata updates while uploading files using File Request. The issue occurred when repeated attempts to process a subset of unsuccessful metadata events reduced available processing capacity and delayed other events. We restored the metadata functionality of File Requests by limiting unnecessary retries, reducing processing idle time, and improving the handling of failures that would not succeed when retried. In addition, we are improving retry behavior, monitoring, and response procedures for similar asynchronous processes.\n\n# Analysis\n\nAt the time of the issue, the system automatically retried failed file processing. During an extended period of failures, these retries consumed most of the system's capacity, causing files to pile up in a queue. As processing slowed, more files encountered issues that retries could not resolve, further increasing the delay.\n\nWe restored normal processing by temporarily reducing retry attempts, removing redundant retries, and allowing permanent failures to fail without being repeatedly processed. We continued monitoring the service before confirming that full functionality had been restored.\n\n# Corrective Actions\n\nThe following corrective actions have been completed or are planned:\n\n* Completed changes to limit retries and stop repeatedly processing failures that cannot be resolved through retries.\n* Applying the same, improved retry handling to other asynchronous processes, preventing similar occurrences from happening to other File Request features.\n* Improving alerting and response procedures for processing backlogs and retained unsuccessful events to ensure that temporary issues can later be retried safely.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-07-23T04:42:10.645-07:00",
"resolved_inferred": false,
"started_at": "2026-07-23T02:45:51.100-07:00",
"state": "postmortem",
"title": "[Medium] Issues with File Requests",
"updated_at": "2026-08-09T19:24:45.738-07:00",
"url": "https://stspg.io/tt41whfy05bc"
},
{
"body": "We recently addressed issues affecting Open With integrations within Box. We would like to take this opportunity to further explain these issues and the steps we have taken to prevent them from reoccurring.\n\nBetween 1:00 PM PDT and 2:40 PM PDT on July 16, 2026, some customers may have been unable to open or edit files using any Open With integration in the Box web application. During this period, affected files may have appeared unavailable or grayed out, and users may have encountered permission-related errors when launching an integration. Microsoft Office workflows, including Office Online in the browser and desktop editing through Box Edit, were among those impacted.\n\nThe issue occurred after a recent service update unintentionally changed how integration workflows were handled, causing the product to return an empty set of available integration actions for affected files. We resolved the issue by reverting the service to the previously deployed version, after which service metrics and customer confirmations recovered. In addition, we are taking steps to reduce reoccurrence by improving testing, monitoring, and release practices for integration paths.\n\n# Analysis\n\nThis incident highlighted opportunities to improve end-to-end testing for integration workflows and our automated detection process.\n\nThe failure mode returned an empty action list rather than hard errors, which kept broad service-level signals near baseline and made the impact visible primarily through customer reports.\n\n# Corrective Actions\n\nBox has initiated the following corrective actions:\n\n* Expanded lower-environment end-to-end tests to validate Open With / Office Online behaviors after changes to integration-related code.\n* Added targeted monitoring and alerting for integration action and permission-check failures so regressions surface automatically.\n* Documented and formalized release and rollback runbooks for integration-related changes, including clear validation and rollback steps to reduce time-to-recovery.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-07-16T14:48:30.000-07:00",
"resolved_inferred": false,
"started_at": "2026-07-16T14:30:27.000-07:00",
"state": "postmortem",
"title": "[Medium] Issues with Box Edit and Microsoft Office Online",
"updated_at": "2026-08-04T15:58:32.342-07:00",
"url": "https://stspg.io/kltqnqmpzbh9"
},
{
"body": "We recently addressed issues affecting Box Relay. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\nBetween 1:10 AM and 11:33 PM PT on July 14, 2026, some users may have experienced difficulties while working in Box. During this time, some users may have experienced degradation of Box Relay workflows that include a task outcome. The issue occurred as a result of a recent code change intended to improve how task assignments are handled in workflows. We were able to resolve the issue by reverting that change and restoring the previous behavior. In addition, we are improving our automated testing, monitoring, and deployment safeguards to prevent similar issues from occurring in the future.\u00a0\n\n\u200c\n\n**Analysis** \n\nA Box Relay workflow can include a task outcome, which assigns a task to one or more people. As part of that outcome, the workflow also attempts to give each assignee access to the relevant file. A recent change caused the entire task outcome to fail whenever that access-granting operation was rejected. Such a rejection is an expected condition in some configurations \\(_e.g._, when the person who owns the workflow does not have sufficient permission to share the file, or when sharing restrictions are in place\\) and it can occur even when the assignee already has access to the file. Previously these rejections were tolerated and the task was still created. After the change, they caused the task outcome to fail, so affected workflows stopped completing.\n\n\u200c\n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Adding automated test coverage for this scenario to prevent similar regressions.\n* Adding monitoring and alerting for workflow-processing failures, so this class of issue is detected proactively rather than through customer reports.\n* Refining the task-assignment logic to avoid unnecessary access-granting operations when an assignee already has access to the file.\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-07-14T23:43:22.021-07:00",
"resolved_inferred": false,
"started_at": "2026-07-14T21:14:09.557-07:00",
"state": "postmortem",
"title": "[Medium] Issues with Box Relay",
"updated_at": "2026-07-29T12:49:45.348-07:00",
"url": "https://stspg.io/dskd65lxnyh9"
},
{
"body": "We recently addressed an issue that affected Box Search and related Query functionality, including the Public APIs and Box Apps features that rely on them. We would like to take the opportunity to explain what happened and the steps we have taken to prevent it from happening again.\n\nOn July 7, 2026 between 06:22 AM and 08:53 AM PT, some customers may have experienced elevated latencies and intermittent errors when using the Box Search and Query functionality. Public APIs for these features, Box Apps, Web App Search, and other functionalities that depends on Search and Query APIs were also impacted. This incident was caused by a sudden surge in indexing traffic that overwhelmed services in one of our subsystems, before they could be scaled up or rate limiting could kick in. We were able to remediate the issue by isolating the offending traffic and allowing the surge of indexing work to finish processing and drain. Regular traffic routing was restored once the affected infrastructure was healthy again.\n\n# **Analysis**\n\nThis incident revealed an opportunity to improve how we protect our search indexing subsystem from sudden~~,~~ and concentrated surges of load. While our stateless services can quickly autoscale horizontally, our stateful systems cannot be scaled as quickly to handle sudden surges in load. We\u2019ve historically focused on query traffic driven load and over-provisioned to handle any increases in internally generated indexing load. This incident revealed that sudden and large indexing surges can impact stability more than we anticipated. Our safeguards did not sufficiently slow or throttle a large burst of re-indexing traffic, and a temporary configuration change in place at the time of this incident caused files to be re-indexed in full even when only non-content attributes had changed, amplifying the load. \n\n# **Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Add per source rate limiting to the indexing pipeline so a large burst of work cannot overwhelm the subsystem.\n* Optimize indexing load, so files are only re-indexed when their content has actually changed.\n* Set safer limits on how much work the pipeline will accept at once.\n* Improve monitoring and alerting to detect unusual spikes in processing earlier and respond before customers are impacted.\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope this provides clarity on what occurred and the steps we are taking. We would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,   \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-07-07T09:19:34.145-07:00",
"resolved_inferred": false,
"started_at": "2026-07-07T07:11:14.153-07:00",
"state": "postmortem",
"title": "[Medium] Issues with Search service, Box Sign Templates and Metadata queries",
"updated_at": "2026-07-31T14:03:14.661-07:00",
"url": "https://stspg.io/q6y0bmwy00qq"
},
{
"body": "Between 10:40 AM PDT and 12:33 PM PDT on June 25, 2026, some users may have experienced difficulties while working in Box. During this time, users routed through one particular US region may have seen failures or delays when attempting to download folders as ZIP files.\n\nThe issue occurred after a recent network component update impacted a backend service in that region. We restored the feature availability by reverting the change. In addition, we are updating configuration and monitoring practices for such changes to reduce the likelihood of recurrence.\n\n# Analysis\n\nAs part of our continuous and ongoing service improvement efforts, we recently rolled out a change to our internal compute platform. In one of our US regions, this change resulted in a resource problem within our service mesh layers. This incident highlighted opportunities to improve how platform updates and service configuration changes are propogated across Box compute regions.\n\n# Corrective Actions\n\nBox has initiated the following corrective actions:\n\n* Improved our multi-region roll out monitoring and alerting\n* Audited resource configurations for multi-region services\n* Improved ongoing monitoring and alerting of multi-region services\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-06-25T14:47:38.161-07:00",
"resolved_inferred": false,
"started_at": "2026-06-25T12:29:04.063-07:00",
"state": "postmortem",
"title": "[Medium] Issues with Zip Downloads",
"updated_at": "2026-08-06T09:18:06.946-07:00",
"url": "https://stspg.io/gr2zt4rcp4c5"
},
{
"body": "We recently addressed issues affecting file uploads in Box. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\nBetween 4:47 AM PDT and 5:28 AM PDT on June 24, 2026, some users may have experienced difficulties uploading larger files to Box. During this time, chunked uploads of large files may have failed or timed out, while smaller file uploads continued to work normally. The issue occurred when an internal system that temporarily tracks the progress of large, chunked uploads experienced an unexpected failover and lost the in-progress upload information it was holding. The issue resolved once those connections were reset. In addition, we are hardening how our upload service detects and recovers from this kind of interruption to prevent similar issues in the future.\n\n# Analysis\n\nLarge file uploads in Box are split into multiple parts and rely on a shared internal caching system to track the progress of each upload while it is in flight. During this incident, that caching system underwent an unexpected failover, and the newly promoted instance did not contain all of the in-progress upload state. As a result, affected sessions could not continue and returned errors. Recovery was further delayed because the upload service continued to use a connection that was no longer valid. Standard file uploads do not depend on this system and were not affected.\n\n## Corrective Actions\n\nBox has initiated the following corrective actions:\n\n* Adding dedicated monitoring and alerting for this caching system so that similar failures are detected and corrected more quickly.\n* Improving how the upload service detects a lost connection and reconnects automatically, so that recovery is faster and does not require manual intervention.\n* Strengthening the resilience of large-upload session storage so that a failure of this caching system has reduced impact on in-progress uploads.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely, \n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-06-24T05:33:15.191-07:00",
"resolved_inferred": false,
"started_at": "2026-06-24T05:18:40.053-07:00",
"state": "postmortem",
"title": "[Minor] Issues with Uploads",
"updated_at": "2026-08-06T16:55:15.908-07:00",
"url": "https://stspg.io/75fz2vnd0czq"
},
{
"body": "We recently addressed issues affecting the Box API, All Files, and Box AI. We would like to take the opportunity to further explain what happened and the steps we have taken to prevent reoccurrence.\n\nBetween 12:06 PM PDT and 12:39 PM PDT on June 17, 2026, some users may have experienced difficulties while working in Box. During this time, some customers were unable to access content, browse folders, or complete uploads and other file operations, and error rates for affected features were elevated.\n\n**What Happened**\n\nThe issue occurred after a recent rollout of a new traffic-routing change for the All Files experience reached full traffic volume. This routing change directed file-browsing requests through a newer service path that, under full production load, generated a significantly higher volume of calls to an underlying data-access component than had been observed during earlier, partial rollouts. The increased call volume saturated a capacity-limited thread pool within our file service. Once that threshold was crossed, automated health checks detected the degraded state and began restarting affected service instances \u2014 which, combined with retry traffic from dependent services, amplified the load and caused a cascading degradation affecting the API, All Files browsing, and Box AI.\n\n**How We Restored Service**\n\nWe restored service by:\n\n* Disabling the recent traffic-routing rollout, returning file-browsing requests to the prior service path\n* Increasing the capacity of the affected file service to absorb the load\n* Reverting a separate, unrelated deployment as a precautionary measure\n\nMonitoring confirmed that availability and error rates returned to normal by 12:39 PM PDT, approximately 33 minutes after impact began.\n\n**Analysis**\n\nThis incident highlighted opportunities to evaluate how a new traffic-routing change is validated at production scale and how dependent components behave when exposed to that traffic pattern for the first time. Specifically, the new routing path generated a more resource-intensive class of data queries than the partial rollout had revealed, and the affected service lacked sufficient capacity headroom to absorb the full traffic volume. It also showed the value of rapid rollback capability and coordinated monitoring across feature rollouts and service capacity limits.\n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* **Increase and harden service capacity and autoscaling:** We have increased the capacity of the affected file service and are improving autoscaling thresholds so the service can respond dynamically to traffic spikes.\n* **Improve pre-rollout validation:** We are strengthening load testing and validation of traffic-routing changes under realistic, production-like conditions before full deployment.\n* **Tighten rollout safeguards and monitoring:** We are improving rollout gates, alerting, and automated rollback capabilities to enable faster detection and response when changes cause elevated error rates.\n* **Decouple health probes from capacity saturation:** We are updating how service health checks interact with capacity limits to avoid crash-loop scenarios that can amplify failures during high-load events.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope this provides clarity on what occurred and the steps we are taking. We would be happy to answer any questions you may still have regarding this matter.\n\nSincerely, The Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-06-17T13:28:10.568-07:00",
"resolved_inferred": false,
"started_at": "2026-06-17T12:34:08.934-07:00",
"state": "postmortem",
"title": "[Medium] Issue with Multiple Box Services",
"updated_at": "2026-08-06T16:58:20.025-07:00",
"url": "https://stspg.io/xq7198krgbqd"
},
{
"body": "We recently addressed issues affecting Box Public API. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future. \n\nBetween 5:10 PM PDT and 6:40 PM PDT on June 10, 2026, some users may have experienced difficulties accessing or working within Box. During this period, there was a noticeable degradation affecting Public API request processing. This issue occurred as a result of a recent software change to our authentication infrastructure in our ongoing effort to improve performance and stability of Public API service. We were able to resolve the issue by scaling up the service, correcting its resource allocation, and rolling back the change. In addition, we are working to improve our resource provisioning to prevent similar issues from occurring in the future.  \n\n**Analysis** \n\nWe recently began rolling out an update to our authentication infrastructure designed to improve performance and stability of Public API service. Following the gradual rollout, an increase in resource utilization during peak traffic led to unexpected resource utilization on our authentication infrastructure. As a result, those servers became unresponsive, preventing them from processing Public API requests. We were able to resolve the issue by temporarily scaling up and adjusting the resource allocations of the authentication service.   \n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Rebalancing the resource allocations of the authentication service to accommodate higher traffic volumes\n* Tuning server timeouts across Public API components to ensure consistent, predictable API response times\n* Establishing processes and automation to reduce time to mitigation  \n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-06-10T19:01:00.142-07:00",
"resolved_inferred": false,
"started_at": "2026-06-10T17:34:13.920-07:00",
"state": "postmortem",
"title": "[Medium] Issue with Multiple Box Services",
"updated_at": "2026-06-24T15:10:17.837-07:00",
"url": "https://stspg.io/w10c0j6bntt4"
},
{
"body": "We recently addressed issues affecting Authentication, File Access, Notes, Uploads, and Public API. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\nOn June 3, 2026 between 10:53 PM and 10:58 PM PDT, some customers may have experienced issues when attempting to sign in to Box and when accessing files, notes, uploads, and our public API. The issue was caused by a temporary fluctuation in a database shard due to elevated disk activity, which led to connection saturation and service errors for a subset of users. Service returned to normal by 10:58 PM PDT and monitoring remains in place to watch for recurrence. \n\n# Analysis\n\nAs part of our routine system maintenance, we deployed standard software updates to our infrastructure. Following these updates, a scheduled background system scan processed a larger-than-normal volume of files. This background activity led to temporary resource contention on the database tier, resulting in brief latency and connection saturation for a subset of users.\n\nWhile Box utilizes redundant database replicas to ensure high availability, our automated monitoring and failover systems did not immediately redirect traffic because the database remained partially responsive. \n\n# Corrective Actions\n\nBox has initiated the following corrective actions:\n\n* Implemented strict I/O resource limits on background maintenance processes to ensure they cannot impact active user traffic.\n* Upgraded our database monitoring and health checks to immediately detect and alert on localized resource contention, ensuring faster automated failover response.\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-06-03T10:53:00.000-07:00",
"resolved_inferred": false,
"started_at": "2026-06-03T10:30:00.000-07:00",
"state": "postmortem",
"title": "[Critical] Issues with Multiple Box Services",
"updated_at": "2026-07-29T12:55:08.450-07:00",
"url": "https://stspg.io/kj8bsh076nb0"
},
{
"body": "_Notice and disclaimer: Box is providing this preliminary information subject to further review and analysis. To the best of our knowledge, this is the current state and we may update as more information is confirmed._\n\nOn May 31, 2026 between 5:00pm PDT and 6:41pm PDT, some customers may have experienced errors or degraded performance when using Box AI features, including failures to generate AI responses or slower-than-expected behavior.  The issue affected only AI-related capabilities and did not impact general file access.\n\nThe disruption was caused by an outage with a third-party AI provider that led to failed AI requests. Service was restored once the provider issue was resolved and normal AI request processing resumed.\n\nWe are reviewing our third-party dependencies and operational practices to reduce the risk of similar interruptions in the future.\n\nWe are conducting a full engineering postmortem and our overview is subject to change with further analysis and findings. In the event our continuing investigation yields further substantive findings, we may publish additional analysis after the conclusion of the full engineering postmortem.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-05-31T19:25:47.434-07:00",
"resolved_inferred": false,
"started_at": "2026-05-31T17:58:40.111-07:00",
"state": "postmortem",
"title": "[Medium] Issues with Box AI",
"updated_at": "2026-08-06T17:00:40.194-07:00",
"url": "https://stspg.io/xdf1rh8zpqpj"
},
{
"body": "We recently addressed issues affecting Box Drive login and Single Sign-On \\(SSO\\) configuration. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\nBetween 10:56 PM PDT on May 21, 2026 and 2:07 AM PDT on May 22, 2026, some users may have experienced difficulties while working in Box. During this time, enterprise customers with Intune Mobile Application Management \\(MAM\\) enabled experienced SSO login failures when attempting to access Box Drive, and administrators were unable to view, update, or manage SSO configurations in the Admin Console. The issue occurred as a result of an unintended configuration change where our primary, active identity provider administration console region was inadvertently flipped to passive mode. We were able to resolve the issue by restoring the primary administration console region back to active status, which immediately restored normal API and login flows. In addition, we are making updates to improve monitoring and alerting for related operational workflows to prevent similar issues from occurring in the future.\u00a0\n\n**Analysis** \n\nThe active and standby regions were unintentionally reversed, causing the live production region to be switched into standby mode. As a result, the administrative API, which was used in for Intune MAM login flow, began rejecting requests for customers using Intune MAM-protected accounts and temporarily blocked certain SSO management actions in the Admin Console. End users affected by this saw login errors until the regions were restored to their correct state. We have since added safeguards to prevent unintended region switches and improved how our login flow handles this type of upstream failure.\n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Add monitoring to catch certain configuration mismatches that could lead to unintended changes in service routing\n* Implement additional restrictions for administrative console region-flip\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0 \n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-05-22T02:18:22.378-07:00",
"resolved_inferred": false,
"started_at": "2026-05-22T01:46:15.327-07:00",
"state": "postmortem",
"title": "[Medium] Issues with Box Drive",
"updated_at": "2026-06-25T17:04:09.367-07:00",
"url": "https://stspg.io/xgwnfbj03kd9"
},
{
"body": "We recently addressed issues affecting **Enterprise Events API**. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\n\u200c\n\nBetween 2:31am and 4:45pm PDT on May 14, 2026, some users may have experienced difficulties while working in Box. During this time, customers using the streaming Enterprise Events API experienced delivery delays of up to 6.5 hours. The issue occurred when an internal indexing service unexpectedly generated events at an unconstrained rate, which caused a significant concentrated spike in the total events volume. We were able to resolve the issue by redirecting those events from our streaming enterprise events pipeline for later processing. In addition, we will exclude events originating from internal services from our enterprise events processing pipelines and proactively deprioritize unexpected surges in events to prevent similar issues from occurring in the future.\n\n\u200c\n\n**Analysis** \n\n\u200c\n\nThere were a number of contributing factors leading to this incident and a reoccurrence on May 18, 2026 between 11:52am and 2:03pm PDT with delivery delays of up to 1.1 hours:\n\n\u200c\n\nOur internal search indexing service produced events, which should not have been created, at a rate significantly exceeding enterprise usage. These events were published to a queue to be written to the persistent datastore. Also, these events were concentrated in certain access patterns causing hot spotting in some database partitions. The significantly reduced throughput of these partitions caused the subscriber to fall behind. Once these access patterns were identified and the corresponding events removed, service was resolved promptly. Moving forward, these events will not be published.\n\n\u200c\n\n**Corrective Actions**\n\n\u200c\n\nThe following corrective actions have been completed or are planned:\n\n\u200c\n\n* **Disable Event Publishing for Search Services** - We are disabling enterprise events from being produced and processed from Box internal services.\n* **Deprioritize Surge Workloads** - We will monitor for workloads generating significant volumes of event data and deprioritize those events from the primary pipeline.\n* **Update Incident Response Procedures** - We are updating our runbooks to account for these conditions and related actions.\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\n \n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-05-14T12:30:00.000-07:00",
"resolved_inferred": false,
"started_at": "2026-05-14T12:30:00.000-07:00",
"state": "postmortem",
"title": "[Medium] Degradation of Enterprise Events API",
"updated_at": "2026-06-03T23:42:52.281-07:00",
"url": "https://stspg.io/w68h5wm82kll"
},
{
"body": "We recently addressed issues affecting folder and collection browsing, and related APIs. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\nBetween 05:22 PM PDT and 07:04 PM PDT on May 6, 2026, some users may have experienced difficulties while working in Box. During this time, users reported failures and elevated errors when loading folders and collections, intermittent service errors, and degraded AI-related functionality.\n\nThe issue was caused by runtime saturation in a backend API service that had been gradually approaching its capacity limits over several weeks. During peak traffic hours, multiple service instances simultaneously became unable to respond to internal health checks within the configured timeout. As those instances were restarted, traffic shifted to the remaining instances, increasing load on them and creating a cascading failure. We mitigated the issue by stopping the restart cycle, routing traffic to alternate paths, and increasing service capacity.\n\n\u200c\n\n**Analysis**\n\nThis incident revealed several contributing causes:\n\n* Insufficient scaling signals \u2014 autoscaling was primarily configured around CPU utilization. For this service, CPU utilization did not accurately reflect runtime saturation, so the fleet did not scale early enough in response to the actual bottleneck.\n* Health check sensitivity under load \u2014 health checks were configured with timeouts that did not account for the service\u2019s behavior under sustained runtime saturation. Once instances became slow to respond, restarts amplified the problem by shifting more traffic to the remaining instances.\n* Gradual capacity erosion without alerting \u2014 the service had shown intermittent health check failures during prior peak traffic periods. Those earlier events were narrow enough to self-recover, but they were not surfaced as a clear trend requiring action.\n* Retry amplification \u2014 as service instances became unavailable, upstream retry behavior added additional load to the remaining healthy instances, accelerating the cascade.\n\nThis incident highlighted opportunities for improvement in how we detect and respond to runtime saturation that is not always visible from CPU metrics alone. It also reinforced the need for stronger end-to-end observability, clearer health-check visibility, and validated mitigation paths for service instability.\n\n\u200c\n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Improved runtime monitoring and alerting \u2014 we added alerts for runtime saturation metrics that detect this class of failure independently of CPU utilization, providing earlier warning before customer impact occurs.\n* Revised autoscaling strategy \u2014 we reconfigured autoscaling to trigger on signals that reflect actual service capacity and validate that the fleet scales correctly under realistic load conditions.\n* Health check and resilience tuning \u2014 we are reviewing health check configurations and retry behavior to reduce the risk that transient runtime saturation can turn into cascading restarts.\n* Capacity validation and load testing \u2014 we are establishing load testing against production-representative traffic patterns and maintaining capacity headroom until the service's efficiency improvements are validated.\n* Runtime performance improvements \u2014 we identified and are implementing changes to the service framework that significantly reduce per-request overhead, providing more headroom against future saturation.\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-05-06T20:07:43.297-07:00",
"resolved_inferred": false,
"started_at": "2026-05-06T18:20:15.000-07:00",
"state": "postmortem",
"title": "[Critical] Issues with Multiple Box Services",
"updated_at": "2026-05-22T14:12:35.849-07:00",
"url": "https://stspg.io/3zrg1zp5fdvw"
},
{
"body": "After further monitoring, this incident is now considered resolved. Search with metadata has been restored to full functionality. If you continue to experience any issues, please contact Box Support at https://support.box.com.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-04-27T12:11:39.555-07:00",
"resolved_inferred": false,
"started_at": "2026-04-27T10:36:40.630-07:00",
"state": "resolved",
"title": "[Medium] Issues with Box Search",
"updated_at": "2026-04-27T12:11:39.572-07:00",
"url": "https://stspg.io/h03kn85y4kf3"
},
{
"body": "On April 2, 2026 between 8:19 PM PDT and 11:56 PM PDT, some users may have experienced difficulties while working in Box. During this time, Box Sign users might have experienced errors while creating new signature requests, accessing existing signature requests, or attempting ~~been unable~~ to access the service. The issue occurred as a result of an erroneous change made by a third-party infrastructure provider. We were able to resolve the issue by escalating it to the provider. In addition, we are working to improve the reliability of the Box Sign service by enhancing our disaster recovery processes to prevent similar issues from occurring in the future.\u00a0\n\n\u200c\n\nWe are conducting a full engineering postmortem and our overview is subject to change with further analysis and findings. In the event our continuing investigation yields further substantive findings, we may publish additional analysis after the conclusion of the full engineering postmortem.\n\n \n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\n \n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-04-03T01:09:36.925-07:00",
"resolved_inferred": false,
"started_at": "2026-04-02T21:04:31.122-07:00",
"state": "postmortem",
"title": "[Critical] Issues with Box Sign",
"updated_at": "2026-04-10T09:36:17.084-07:00",
"url": "https://stspg.io/48gkty34w2x0"
},
{
"body": "After further monitoring, this incident is now considered resolved. The Admin console service has been restored to full functionality. If you continue to experience any issues, please contact Box Support at https://support.box.com.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-03-25T07:03:53.516-07:00",
"resolved_inferred": false,
"started_at": "2026-03-25T04:44:45.799-07:00",
"state": "resolved",
"title": "[Medium] Issues Accessing the Admin Console Dashboard",
"updated_at": "2026-04-27T10:38:12.201-07:00",
"url": "https://stspg.io/wb4z37ykflcq"
},
{
"body": "We recently addressed issues affecting Shuttle \\(migration service\\). We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\n\u200c\n\nBetween 03/24/2026 08:00 PM PDT and 03/25/2026 11:40 AM PDT on Mar 24\u201325, 2026 \u2014 some users may have experienced difficulties while working in Box. During this time, users reported blank pages, timeouts, and failures when configuring or running migration jobs in the Shuttle interface.\n\n\u200c\n\nThe issue occurred after a vendor-managed database maintenance update that included an operating system and security library change, which caused the affected database clusters to enter a read-only or degraded state and prevented normal job configuration and history access. We were able to resolve the issue after the vendor reverted the change on the affected clusters and our teams restarted the dependent services, after which we verified normal operation. In addition, we will take steps to reduce the likelihood of recurrence by improving coordination and testing for vendor-managed upgrades and strengthening our operational safeguards.\n\n\u200c\n\n# Analysis\n\n\u200c\n\nThis incident highlighted risks in relying on vendor-managed platform updates without staged validation across environments, and showed gaps in how quickly we could detect and isolate read-only database states. Response required close vendor collaboration to identify and revert the change; internal mitigations \\(service restarts and connection management\\) were insufficient until the vendor rollback completed. We will improve pre-upgrade controls, monitoring for early signs of degraded database state, and runbook guidance for faster mitigation.\n\n\u200c\n\n# Corrective Actions\n\nBox has initiated the following corrective actions:\n\n\u200c\n\n* Require staged validation of vendor-managed platform upgrades \\(dev \u2192 staging \u2192 production\\) before production rollout.\n* Establish a coordinated upgrade/runbook with the vendor that defines pre-checks, rollback steps, and escalation pathways.\n* Enhance monitoring and alerts for read-only database states, failed elections, and connection saturation to detect similar issues earlier.\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\n\u200c\n\nSincerely,\n\n\u200c\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-03-25T10:00:26.223-07:00",
"resolved_inferred": false,
"started_at": "2026-03-24T22:52:05.462-07:00",
"state": "postmortem",
"title": "[Critical] Issue with Box Shuttle",
"updated_at": "2026-07-29T15:34:44.305-07:00",
"url": "https://stspg.io/dfdrjbn5r53n"
},
{
"body": "We recently addressed issues affecting the \u201cAll Files\u201d page in Box. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\nBetween **3:00 PM PDT** and **9:34 PM PDT** on **March 19, 2026**, some users may have experienced difficulties while working in Box. During this time, users accessing Box through the web application may have encountered blank pages when navigating into folders on the \u201cAll Files\u201d page or when opening certain shared links. The issue occurred as a result of a recent code change, made in our ongoing effort to improve performance and stability. We were able to resolve the issue by reverting the web application to the previous stable version. In addition, we are strengthening safeguards in our deployment and rollback processes to prevent similar issues from occurring in the future.\u00a0\n\n**Analysis** \n\nThe incident revealed areas for improvement in automation reliability, validation controls, and the consistency of rollout and rollback mechanisms, which contributed to an unintended artifact version being promoted to the production environment. \n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* **Strengthen deployment validation and gating mechanisms**: We are implementing stricter automated checks to verify artifact integrity, version correctness, and configuration alignment at each stage of the pipeline, ensuring only validated and approved builds can be promoted to production.\n* **Standardize and reinforce rollout and rollback procedures**: We are establishing consistent, well-documented deployment and rollback workflows with automated safeguards and audit trails to ensure reliable reversibility and prevent incorrect artifact promotion during release operations.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-03-19T22:08:54.099-07:00",
"resolved_inferred": false,
"started_at": "2026-03-19T20:37:48.892-07:00",
"state": "postmortem",
"title": "[Medium] Issues with Logins, Folder and File Preview, and Shared Links",
"updated_at": "2026-04-15T14:20:06.535-07:00",
"url": "https://stspg.io/yfyj5d25wmnk"
},
{
"body": "Between 10:56am PST to 11:42am PST on March 18th, 2026 some users may have experienced difficulties previewing files. No further impact has been observed and we are considering this issue to be resolved. If you are still experiencing any issues, please let us know at https://support.box.com.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-03-18T11:00:00.000-07:00",
"resolved_inferred": false,
"started_at": "2026-03-18T09:00:00.000-07:00",
"state": "resolved",
"title": "[Medium] Customers may experience issues previewing files",
"updated_at": "2026-03-18T12:18:06.411-07:00",
"url": "https://stspg.io/q0mdmlwrlp2b"
},
{
"body": "We recently addressed an issue affecting logins to Box. We would like to take the opportunity to further explain this issue and the steps we have taken to keep it from happening in the future.\n\nBetween **4:46 PM PDT** and **5:32 PM PDT** on **March 9, 2026**, some users may have experienced difficulties logging in to Box leading to disruptions when using some Box features. This issue occurred when a service involved in the login process did not have sufficient resources to handle an uneven spike in traffic, which caused a portion of login-related requests to time out. We resolved this by increasing resources for the affected service and expanding its capacity. We also took additional steps to reduce the likelihood that this type of issue could affect the login experience in the future.\n\n## **Analysis**\n\nThe incident surfaced opportunities to further refine how we size and distribute capacity across services that support login-related traffic. It also underscored the value of strengthening earlier detection of traffic imbalances and simplifying dependencies within critical login flows.\n\n## **Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* **Strengthen resource allocation and scaling:** We are tuning resource allocation and scaling behavior so services can better absorb unusual traffic patterns without degradation.\n* **Improve traffic distribution and monitoring:** We are refining how traffic is distributed across service instances and strengthening monitoring so we can identify and address unhealthy capacity patterns sooner.\n* **Reduce login path dependencies:** We are simplifying the login flow so fewer background checks are required for most users, reducing the potential impact of issues in supporting services.\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-03-09T18:14:03.518-07:00",
"resolved_inferred": false,
"started_at": "2026-03-09T17:30:24.333-07:00",
"state": "postmortem",
"title": "[Minor] Issue affecting Logins",
"updated_at": "2026-05-11T14:49:17.440-07:00",
"url": "https://stspg.io/d4ch5k47flv5"
},
{
"body": "We recently addressed issues affecting Box FTP and SFTP services. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\n \n\nFrom February 25th, 2026 at 9:20 AM PST to February 27th at 4:10 PM PST, some users may have experienced difficulties while working in Box. During this time, Box FTP and SFTP users may have seen CAPTCHA messages while logging in through FTP. The issue occurred due to a change in internal traffic routing which affected the Box FTP and SFTP services. We were able to resolve the issue by reverting the internal routing change and clearing CAPTCHAs for affected users. We are now working to harden the system against internal rate limiting going forward to prevent similar issues from occurring in the future.\u00a0\n\n\u200c\n\n**Analysis** \n\nOn February 23rd at 8:20 AM PST, a change was made to send a subset of login traffic through a new route. After this change, no issues were observed and no customer issues were reported.  On February 25th at 8:20 AM PST, a subsequent change was made to send more of the same login traffic through the new route. Roughly one hour after this change was completed, the Box FTP service started to receive an increased rate of CAPTCHA failures, blocking users from logging in. The second routing change was identified as the root cause and reverted on February 27th at 12:49 PM PST. After revert, a number of Box FTP users needed to clear an additional CAPTCHA. Box Support assisted in clearing the CAPTCHAs manually and by 4:10 PM PST, all Box FTP and SFTP login errors were resolved.\n\n\u200c\n\nOur analysis determined that the root cause of this issue was a service that was added to the call stack in the new route. The service in question did not properly communicate rate limiting information sent by the Box FTP service. This led to Box FTP being internally rate limited, which prompted users to improperly complete a CAPTCHA when logging in to Box FTP. \n\n\u200c\n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* The service in question has been fixed to properly forward required rate limiting information.\n* We are implementing enhanced monitoring to enable faster responses in the case of similar occurrences.\n* A comprehensive review is being performed to find any instances of missing rate limiting information within the stack.\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\n \n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-02-27T15:51:54.322-08:00",
"resolved_inferred": false,
"started_at": "2026-02-27T12:02:45.000-08:00",
"state": "postmortem",
"title": "[Medium] Increased FTP 530 Captcha errors",
"updated_at": "2026-03-05T14:43:31.258-08:00",
"url": "https://stspg.io/bg105kt5d4xd"
},
{
"body": "_Notice and disclaimer: Box is providing this preliminary information subject to further review and analysis. To the best of our knowledge, this is the current state and we may update as more information is confirmed._\n\n \n\nOn February 25, 2026 between 4:45 am PST and 5:40 am PST, some users may have experienced difficulties while working in Box. During this time, customers of Box Zones UK may have had issues with uploading, downloading, and previewing files.\n\n\u200c\n\nThe issue occurred when some instances of a backend service in the impacted region ran into memory pressure. We resolved the issue by temporarily redirecting certain compute processes from the impacted region to the US region. Of note, even during the period of temporary traffic redirection, all Box Zones customer content continued to be stored in the correct Box Zones region. \n\n\u200c\n\nWe are conducting a full engineering postmortem and our overview is subject to change with further analysis. In the event our continuing investigation yields further substantive findings, we may publish additional analysis after the conclusion of the full engineering postmortem.\n\n \n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\n \n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-02-25T06:16:45.788-08:00",
"resolved_inferred": false,
"started_at": "2026-02-25T05:00:14.000-08:00",
"state": "postmortem",
"title": "[Medium] Customers may experience issues with Uploads and Downloads for the UK zone",
"updated_at": "2026-03-05T14:49:33.383-08:00",
"url": "https://stspg.io/z3lhst0cdmcr"
},
{
"body": "_Notice and disclaimer: Box is providing this preliminary information subject to further review and analysis. To the best of our knowledge, this is the current state and we may update as more information is confirmed._\n\n \n\nOn February 24, 2026 between 1:15 PM PST and 3:59 PM PST, some users may have experienced difficulties while working in Box. The most significant impact occurred from 1:42 PM PST to 1:59 PM PST, when Uploads, Downloads, Logins, APIs, and Notes saw elevated latency and errors. A small subset of functionality continued to experience some degradation through 3:59 PM PST. The issue occurred due to our cache cluster becoming temporarily overloaded due to a traffic spike concentrated on a single hot key. We were able to resolve the majority of the impact by rate limiting peripheral workloads and fully resolve the issue by stopping the offending traffic source. We are now implementing automated hot key detection and introducing dynamic rate limiting at the caching layer to prevent similar issues from occurring in the future.\n\n\u200c\n\nWe are conducting a full engineering postmortem and our overview is subject to change with further analysis and findings. In the event our continuing investigation yields further substantive findings, we may publish additional analysis after the conclusion of the full engineering postmortem.\n\n \n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\n \n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-02-24T16:15:38.617-08:00",
"resolved_inferred": false,
"started_at": "2026-02-24T15:32:12.938-08:00",
"state": "postmortem",
"title": "[Critical] Issue with Box API",
"updated_at": "2026-03-05T14:32:06.989-08:00",
"url": "https://stspg.io/knn8pbctd7qc"
},
{
"body": "_Notice and disclaimer: Box is providing this preliminary information subject to further review and analysis. To the best of our knowledge, this is the current state and we may update as more information is confirmed._ \n\n\u200c\n\nOn February 24th, 2026 between 6:11 AM PST and 6:40 AM PST, some users may have experienced difficulties while while attempting to log into Box. Users already logged into Box were not impacted by this issue. The issue occurred due to a recent configuration change related to device security that prevented users from logging in to Box. We were able to resolve the issue by quickly reverting the change. We are also working to improve our release strategy and testing processes to prevent similar issues from occurring in the future.\n\n\u200c\n\nWe are conducting a full engineering postmortem and our overview is subject to change with further analysis and findings. In the event our continuing investigation yields further substantive findings, we may publish additional analysis after the conclusion of the full engineering postmortem.\n\n \n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\n \n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-02-24T08:07:33.718-08:00",
"resolved_inferred": false,
"started_at": "2026-02-24T06:59:00.418-08:00",
"state": "postmortem",
"title": "[Critical] Issues with Multiple Box Services",
"updated_at": "2026-03-10T10:55:26.008-07:00",
"url": "https://stspg.io/bb6zfh7xn8b8"
},
{
"body": "We recently addressed issues affecting Box web access. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\nBetween 10:50 AM PST and 11:25 AM PST on February 20, 2026, some users may have experienced difficulties accessing Box via web browser, including failed page loads and intermittent connectivity. During this time, requests to our site that relied on a third-party network service did not route reliably for affected networks, causing DNS resolution and connectivity failures for that hostname. We were able to restore service after the third-party re-advertised the affected network prefixes, at which point we safely re-enabled the dependent routing configuration, restoring normal service behavior. In addition, we are working with the third-party provider and updating our procedures and monitoring to reduce the risk of recurrence and improve detection and recovery.\n\n# Analysis\n\nThis incident highlighted a dependency risk on third-party network prefix advertisement and revealed opportunities to improve early detection and customer-facing communication. It also reinforced the importance of clear playbooks for safely changing routing configurations during third-party outages and ensuring monitoring captures customer-impacting DNS and connectivity failures quickly.\n\n# Corrective Actions\n\nBox has initiated the following corrective actions:\n\n* Work with the third-party provider to complete follow-up and incorporate their post-incident findings\n* Update our routing and operational runbooks to clarify safe, pre-approved steps for toggling routing configurations during third-party network incidents\n* Enhance external-facing monitoring and alert thresholds for DNS and site availability to detect and communicate customer impact more quickly\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-02-20T12:37:30.000-08:00",
"resolved_inferred": false,
"started_at": "2026-02-20T11:11:55.000-08:00",
"state": "postmortem",
"title": "[Minor] User May Encounter Issues Accessing Marketing Page box.com",
"updated_at": "2026-07-09T12:16:22.100-07:00",
"url": "https://stspg.io/vqg38x7hn6z6"
},
{
"body": "From approximately 9:52 PM to 10:00 PM US Pacific time, we observed an issue impacting Logins, Notes and API. There is no current impact and no further updates will be provided here. If you continue to experience any issues, please contact Box Support at https://support.box.com.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-01-08T22:00:00.000-08:00",
"resolved_inferred": false,
"started_at": "2026-01-08T22:00:00.000-08:00",
"state": "resolved",
"title": "[Critical] Issues with Logins, Notes and API",
"updated_at": "2026-01-08T23:15:13.325-08:00",
"url": "https://stspg.io/dfz5vc0l8gmj"
},
{
"body": "We recently addressed issues affecting Box. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\n\u200c\n\nOn January 7th, 2026 between 5:10 PM and 5:50 PM PST, some customers experienced elevated errors and timeouts across multiple Box experiences, including Login, Uploads/Downloads, Box Notes, and the Public API. These issues were caused by a series of changes that triggered a request storm that overloaded our caching fleet. We resolved this by initially rate limiting background traffic and then rolling back the changes.\n\n\u200c\n\n**Analysis** \n\nOn January 6th, a new feature was deployed that increased the utilization of one of our cache backends. That feature, in isolation, did not cause any problem. On January 7th, at 3:30 PM PST, another application change was rolled out that increased the traffic on the same system. Combined, these two changes significantly decreased our capacity buffer on some of our cache systems.\n\n\u200c\n\nOn January 7th at 5:00 PM PT, another unrelated application change was released which created a short traffic spike in the cache system. This spike would have been handled without problems in a normal situation, but the reduced capacity buffer in our cache system created some temporary slowness and retries. Unfortunately, one critical code path that had been migrated to a newer infrastructure had a more aggressive retry policy than the old one. As a result, a retry storm increased the traffic progressively to our caching infrastructure. This traffic increase was not evenly balanced, as it was mostly targeting the few servers that were suffering under the load. The peak impact window was felt between 5:30PM and 5:50PM.\n\n\u200c\n\nTo resume normal operations, we deprioritized some background traffic to increase the capacity of our cache system, and rolled back the changes that were causing the elevated traffic.\n\n\u200c\n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Implemented a more conservative retry control policy \\(to prevent retry amplification during partial failures\\)\n* Improved handling of cache-related failures to reduce cascading effects\n* Enhanced monitoring and alerting of our capacity buffers to identify the impact of sudden traffic spikes on our cache systems\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\n\u200c\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-01-07T18:37:45.040-08:00",
"resolved_inferred": false,
"started_at": "2026-01-07T17:39:31.724-08:00",
"state": "postmortem",
"title": "[Critical] Issues with Multiple Box Services",
"updated_at": "2026-01-28T15:58:40.149-08:00",
"url": "https://stspg.io/mf1wl9gkr2lt"
},
{
"body": "We recently addressed issues affecting the Enterprise Report feature. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\n \n\nOn January 2, 2026 between 5:30 AM and 2:33 PM PST, some users may have experienced difficulties while working in Box. During this time, users were unable to generate some types of Enterprise Reports, and Enterprise Reports scheduled during this time interval may have failed. We were able to resolve the issue by rolling back a configuration change that caused the issues for the reporting engine.\n\n\u200c\n\n**Analysis** \n\nBox Enterprise Reports relies on a definition of the schemas that describe the underlying database tables that the engine will consume to generate the reports. As we deliver new products, these schemas may occasionally need to be updated, and we have a standard process and pipeline to deploy these schema. As part of a project to upgrade our pipeline infrastructure, the schema deployment pipeline migrated to a new infrastructure. During the migration process, an external library version upgrade introduced a new default behavior that was not compatible with the existing pipeline. As a result, the Enterprise Reports service could not access the underlying tables in some cases, resulting in a temporary degradation of the service. Additionally, the migration process exposed some observability and guardrails gaps in the pipeline that would have prevented this issue from happening and that extended the impact for a longer period of time.\n\n\u200c\n\nOnce identified, the incompatible library was reverted to the previous version and the system went back to normal.\n\n\u200c\n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Introduce a schema validation step in the deployment pipeline so that incompatible schemas cannot be deployed\n* Enforce the environment promotion process as part of the schema deployment pipeline\n* Uplift the observability of the pipeline to enable more visibility around the different phases of the deployment process\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\n \n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-01-02T05:30:00.000-08:00",
"resolved_inferred": false,
"started_at": "2026-01-02T05:30:00.000-08:00",
"state": "postmortem",
"title": "[Medium] Issue with Enterprise Reporting",
"updated_at": "2026-03-03T09:51:17.415-08:00",
"url": "https://stspg.io/x1yq403gshls"
},
{
"body": "We recently addressed issues affecting several features of Box. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\n\u200c\n\nOn December 17, 2025, from 11:15 AM PST to 4:46 PM PST, some users may have experienced difficulties while working in Box Sign, Box AI, and Box Doc Gen. During this time, users may have noticed service degradation and delayed email delivery. The issue was caused by a missing schema, which was itself caused by a corrupted schema deployment. We were able to resolve the issue by rolling back the change that temporarily created issues.\n\n\u200c\n\n**Analysis** \n\nBox Sign, Box AI, and Box Doc Gen rely on a definition of the schemas that describe the events that they need to process. As we deliver new products, these schemas may occasionally need to be updated, and we have a standard process and pipeline to deploy these schema. As part of a project to upgrade our pipeline infrastructure, the schema deployment pipeline migrated to a new infrastructure. During the migration process, an external library version upgrade introduced a new default behavior that was not compatible with the existing pipeline. This resulted in a temporary degradation of the service. Additionally, the migration process exposed some observability and guardrail gaps in the pipeline that would have prevented this issue from happening and that extended the impact for a longer period of time.\n\nOnce identified, the incompatible library was reverted to the previous version and the system resumed to normal.\n\n\u200c\n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Introduce a schema validation step in the deployment pipeline so that incompatible schemas cannot be deployed\n* Enforce the environment promotion process as part of the schema deployment pipeline\n* Uplift the observability of the pipeline to enable more visibility around the different phases of the deployment process\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\n\u200c\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-12-17T16:45:12.213-08:00",
"resolved_inferred": false,
"started_at": "2025-12-17T16:21:38.894-08:00",
"state": "postmortem",
"title": "[Major] Issues with Box Sign",
"updated_at": "2026-02-23T17:11:35.218-08:00",
"url": "https://stspg.io/trgrrb6z0p62"
},
{
"body": "We recently addressed issues affecting Box services**.** We would like to take the opportunity to further explain these issues and the steps we have taken to prevent them from happening in the future.\n\nOn December 16, 2025 between 4:25 PM PST and 7:23 PM PST, some users may have experienced slowness and temporary unavailability while working in Box. The issue occurred when we attempted to roll back a diagnostic change that was suspected of causing a minor degradation. The rollback unintentionally resulted in decreased capacity in our middleware service, leading to a degraded site experience. It also introduced a distributed deadlock condition that prolonged our incident response and mitigation efforts. Ultimately, we were able to resolve the deadlock and return to normal operations by temporarily throttling inbound traffic.\n\nWe have implemented measures to increase system capacity and minimize the possibility of a similar deadlock occurring in the future. We are also working on adding safeguards to avoid the rollback failure that served as the proximate cause of this incident.\n\n**Analysis**\n\nBetween 11:11 AM PST and 1:38 PM PST, there was a production deployment of code that was aimed at gathering diagnostic information from our middleware service, in our ongoing efforts to improve system performance and resilience.\n\nAt 3:30 PM PST, we observed a brief, mostly imperceptible degradation and decided to roll back the change as a precaution. Due to failure in the rollback procedure, we observed a significantly reduced capacity in our middleware service that eventually led to a distributed deadlock condition between critical databases.\n\nBox has made significant investments in reliability and mitigation measures. In this case, the issue was regional in scope and cross-region recovery capabilities are still in development. We therefore completed recovery by remediating the impacted region directly rather than executing a regional failover.\n\nWe restored middleware service capacity by 5:21 PM PST, but the deadlock condition persisted. After several lower-impact attempts to dislodge the deadlock were unsuccessful, we took a broader mitigation step and throttled all traffic at 6:54 PM PST. This resulted in a 26-minute full outage, after which systems stabilized and gradually recovered, with the site returning to full functionality at 7:23 PM PST.\n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Complete the planned capacity increase to reduce the chance of similar deadlocks and shorten recovery time if they occur\n* Strengthen rollback safeguards so changes can be safely and reliably reverted, preventing a repeat of the rollback failure that triggered this incident\n\nThank you again for being a valued Box customer.  We are continuously working to improve Box and want to make sure we are delivering the best in class product and user experience. Should you have any additional questions please do not hesitate to contact us.\n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-12-16T20:31:45.457-08:00",
"resolved_inferred": false,
"started_at": "2025-12-16T16:57:51.000-08:00",
"state": "postmortem",
"title": "[Critical] Issues with multiple Box services",
"updated_at": "2025-12-19T19:06:56.444-08:00",
"url": "https://stspg.io/6q49d8qwrq6b"
},
{
"body": "Notice and disclaimer: Box is providing this preliminary information subject to further review and analysis. To the best of our knowledge, this is the current state and we may update as more information is confirmed.\n\nOn November 10, 2025 between 5:00 pm PST and 5:26 pm PST, some users may have experienced slowness or temporary unavailability while working in Box. The issue occurred due to a sudden, large traffic spike on one database, which caused connection saturation on other databases, making them temporarily inaccessible. The issue was automatically resolved as our middleware service detected the problem and backed off. We are working on ways to prevent sudden traffic spikes from cascading to other systems and accelerating our middleware service\u2019s auto-remediation process to prevent similar issues from occurring in the future.\n\nWe are conducting a full engineering postmortem and our overview is subject to change with further analysis and findings. In the event our continuing investigation yields further substantive findings, we may publish additional analysis after the conclusion of the full engineering postmortem.\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\n\nSincerely,\n\nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-11-10T17:00:00.000-08:00",
"resolved_inferred": false,
"started_at": "2025-11-10T17:00:00.000-08:00",
"state": "postmortem",
"title": "[Critical] Issues with Multiple Box Services",
"updated_at": "2025-11-19T15:47:25.921-08:00",
"url": "https://stspg.io/lfvj53yp5yh7"
},
{
"body": "We recently addressed issues affecting downloads, preview, and Box Notes. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\nBetween 10:07 PM PDT and 11:16 PM PDT on October 29, 2025, some users may have experienced difficulties while working in Box. During this time, users may have encountered problems downloading or previewing files and using Box Notes. The issue was caused by a disruption with one of our third-party cloud partners. We resolved the issue by restarting and scaling up the impacted backend services. In addition, we are examining how to improve our resiliency in these scenarios to prevent similar issues from occurring in the future.\n\n\u200c\n\n**Analysis** \n\nThis issue was triggered by a maintenance operation at one of our third-party cloud providers. During this operation, we encountered increased latency between several components in our US cloud regions. Because impact during this issue was limited to US cloud regions, Box Zones customers were not impacted. With the corrective actions outlined below, we strive to prevent or greatly minimize impact to customers from future similar incidents.\n\n\u200c\n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Updated our client timeouts to be more fault-tolerant in the face of third party disruptions\n* Improved our regional resiliency through increased geo-redundancy for external dependencies\n* Updated our internal incident response processes to improve our response time\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-10-29T23:51:21.357-07:00",
"resolved_inferred": false,
"started_at": "2025-10-29T22:29:42.000-07:00",
"state": "postmortem",
"title": "[Major] Issues with Downloads, Preview, Box Notes and Box Sign",
"updated_at": "2025-11-19T11:25:01.449-08:00",
"url": "https://stspg.io/pygm9gnshwkz"
},
{
"body": "After further monitoring, this incident is now considered resolved. The SMS Service has been restored to full functionality. If you continue to experience any issues, please contact Box Support at https://support.box.com.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-10-20T03:08:40.965-07:00",
"resolved_inferred": false,
"started_at": "2025-10-20T02:01:18.247-07:00",
"state": "resolved",
"title": "[Major] Issues to receive SMS",
"updated_at": "2025-10-20T03:08:40.988-07:00",
"url": "https://stspg.io/skr0m40bfnkc"
},
{
"body": "We recently addressed issues affecting availability of the Box All Files page. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\nBetween 5:42 AM PDT and 6:30 AM PDT on October 17th, some users may have experienced difficulties while working in Box. During this time, there was a degradation in availability of the All Files page. The issue occurred due to a bug in our code promotion pipeline, which promoted a disruptive change beyond the canary stage, causing wider impact. We were able to resolve the issue by rolling back the change. In addition, we are working to improve our release strategy and testing processes to prevent similar issues from occurring in the future.\u00a0\n\n\u200c\n\n**Analysis** \n\nThe code that was promoted beyond the canary stage introduced an unintended change in the behavior of our feature flagging mechanism. The code change was intended to improve application performance by implementing a filtering-based approach. However, the feature flagging system was not yet fully compatible with this implementation, which resulted in a malfunction on the All Files page.\n\n\u200c\n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Strengthened the canary deployment validation criteria in our release strategy.\n* Updated internal documentation to reflect feature-flag system dependencies and operational constraints.\n* Provided engineers clear guidance for safely integrating changes with the feature-flag system.\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-10-17T08:07:53.740-07:00",
"resolved_inferred": false,
"started_at": "2025-10-17T06:36:15.736-07:00",
"state": "postmortem",
"title": "[Major] Some Users May See Errors Accessing The All Files Page",
"updated_at": "2025-11-19T11:28:55.402-08:00",
"url": "https://stspg.io/t5729j0dvzm0"
},
{
"body": "From approximately 2:25 PM to 03:01 PM US Pacific time, we observed an issue impacting Box Preview and Shared Links. Our systems automatically detected and corrected the underlying issue. There is no current impact and no further updates will be provided here. If you continue to experience any issues, please contact Box Support at https://support.box.com.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-10-01T12:00:00.000-07:00",
"resolved_inferred": false,
"started_at": "2025-10-01T12:00:00.000-07:00",
"state": "resolved",
"title": "[Major] Issues with Multiple Box Services",
"updated_at": "2025-10-01T15:33:23.677-07:00",
"url": "https://stspg.io/sq2j27z2ns9k"
},
{
"body": "We recently addressed issues affecting Box. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\nBetween 2:14 PM PDT and 10:12 PM PDT on September 22nd, 2025, some users may have experienced difficulties while working in Box. During this time, users may have encountered intermittent errors while using Box AI in Box Hubs. The issue occurred as a result of a code change aimed at improving the reliability of our Box AI service. We were able to resolve the issue by reverting the problematic code change. In addition, we are improving our internal testing and validation procedures to prevent similar issues from occurring in the future. \n\n**Analysis**\n\nThe code change that led to this incident unintentionally switched the underlying LLM that provides vector embeddings for Box AI in Hubs to a different model. That model did not have sufficient capacity to take production traffic and as a result, users experienced errors while interacting with Box AI in Box Hubs during this time.\n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Improve internal testing and validation procedures for changes going to production\n* Improve observability processes for changes being deployed to production\n* Increase traffic in pre-production environments to exercise high traffic loads\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-09-22T22:31:50.409-07:00",
"resolved_inferred": false,
"started_at": "2025-09-22T21:41:54.231-07:00",
"state": "postmortem",
"title": "[Critical] Issues with Box AI within Box Hubs",
"updated_at": "2025-12-11T00:22:58.912-08:00",
"url": "https://stspg.io/kzmhf740jhdz"
},
{
"body": "We recently addressed issues affecting the Box service. We would like to take the opportunity to further explain these issues and the steps we have taken to keep them from happening in the future.\n\nBetween September 17, 2025 at 11:17 PM and September 18, 2025 at 2:21PM PDT, some users may have experienced difficulties while working in Box. During this time, when attempting to access Box, some users may have seen an unbranded error message which cleared after their browser established a new connection to Box. The issue occurred as a result of a change made by one of Box\u2019s cloud infrastructure providers, and was resolved when the vendor reverted the change. In addition, Box is working closely with our vendor\u2019s engineering team to minimize the likelihood of similar issues occurring in the future.\u00a0\n\n\u200c\n\n**Analysis** \n\nBox\u2019s cloud provider experienced an issue that caused global load balancer services to incorrectly return HTTP 502 responses for a small percentage of user requests during the following three time periods:\n\n1. September 17, 2025 from 11:17 PM to 2025-09-18 1:30 AM Pacific\n2. September 18, 2025 from 8:50 AM to 2025-09-18 9:30 AM Pacific\n3. September 18, 2025 from 12:50 PM to 2025-09-18 2:21 PM Pacific\n\nThese appear to have been linked to a load balancer software release. Upon discovery, the third-party vendor subsequently performed a rollback at 2:00 PM PT on September 18 to recover the issue. The provider has fixed the bug in their code and will include the fix in future builds.\n\n\u200c\n\n**Corrective Actions**\n\nBox has initiated the following corrective actions:\n\n* Implementation of specific improvements to our alerting system for cloud provider load balancer errors\n* Improved observability to better enable correlation of cloud provider load balancer errors with other conditions\n* Added measures for these particular load balancer conditions as a new Service Level Indicator\n* Increased communication with the cloud provider to detect and resolve this class of issue more quickly\n\n\u200c\n\nWe are continuously working to improve Box and want to make sure we are delivering the best product and user experience we can. We hope we have provided some clarity here and we would be happy to answer any questions you may still have regarding this matter.\u00a0\n\nSincerely,  \nThe Box Team",
"first_seen": "2026-09-09T12:30:34Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-09-18T17:12:34.325-07:00",
"resolved_inferred": false,
"started_at": "2025-09-18T13:50:37.063-07:00",
"state": "postmortem",
"title": "[Critical] Issue with Multiple Box Services",
"updated_at": "2025-10-07T11:34:40.315-07:00",
"url": "https://stspg.io/t49hgjcr47n0"
}
]
}