Outage in Datto

Datto EDR - Reputation alerts on Ransomware Detection's "RWDWrapper.exe"

Resolved Minor
December 11, 2024 - Started 5 months ago - Lasted about 22 hours
Official incident page

Need to monitor Datto outages?
Stay on top of outages with IsDown. Monitor the official status pages of all your vendors, SaaS, and tools, including Datto, and never miss an outage again.
Start Free Trial

Outage Details

We recognize the increase in reputation alerts regarding the Ransomware rwdwrapper.exe file. This file has been incorrectly flagged by third party threat intelligence. At this time, we have successfully mitigated this issue. Old alerts for the file will remain in the alert list and should be acknowledged. New alerts for the file will not be raised after 10:30 AM ET / 3:30 PM GMT as agents work through any potential backlog. There is not action you need to take at this time.
Latest Updates ( sorted recent to last )
RESOLVED 5 months ago - at 12/12/2024 04:07PM

We are excited to confirm this issue has been fully resolved as of Dec 11th evening. All alerts completed processing and our monitoring confirms over the night and early today no additional events have been created. Please feel free to acknowledge all Reputation alerts for the rwdwrapper.exe event. No other action is required.

IDENTIFIED 5 months ago - at 12/11/2024 09:18PM

The updates made this morning are progressing across each tenant. We will continue to monitor and expect to see every tenant updated and resolved shortly.

IDENTIFIED 5 months ago - at 12/11/2024 09:00PM

The previous fix did not fully resolve the issue and some tenants are still getting false positive alerts for the "RWDWrapper.exe" file.
The R&D team have identified more areas to correct this behavior and are working to fix them.

MONITORING 5 months ago - at 12/11/2024 05:53PM

We recognize the increase in reputation alerts regarding the Ransomware rwdwrapper.exe file. This file has been incorrectly flagged by third party threat intelligence.

At this time, we have successfully mitigated this issue.

Old alerts for the file will remain in the alert list and should be acknowledged. New alerts for the file will not be raised after 10:30 AM ET / 3:30 PM GMT as agents work through any potential backlog. There is not action you need to take at this time.

Know the moment Datto and other vendors go down

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 4000 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook