decrypted · 23 july 2026 · supply chain · uk policy and law · digital sovereignty

A capacity limit in Frankfurt, and the National Lottery it took offline

A single capacity limit inside one AWS availability zone in Frankfurt spent three and a half hours on 16 July doing something no attacker managed this week: it took the UK National Lottery offline, along with Hugging Face, and university coursework platforms Canvas and Blackboard, for good measure. Nobody broke in anywhere. A routine internal constraint in the fleet that manages connections for CloudFront's newer "VPC Origins" feature jammed, and because that control plane feeds edge locations globally, sites with nothing wrong in their own region started returning errors anyway. It is a useful reminder that resilience, like security, is a design decision, not a feature you can buy afterwards, and this week it is the National Lottery's turn to make the point.

What actually broke

CloudFront's VPC Origins lets a customer serve an application from a private backend without exposing it to the open internet, a sensible design in isolation. The problem sat one layer up: the fleet responsible for pushing routing configuration out to CloudFront's network processors hit an internal capacity limit in a single availability zone in AWS's Frankfurt region. That is a regional problem. But the mechanism it broke was not regional: it was the single control plane that every edge location worldwide relies on to know where to send traffic. Picture a single signal box outside Frankfurt jamming, and points failing at stations across a network that never lost a single length of track. Nothing in Ohio or London physically failed. The National Lottery's website still had every server it needed. It simply stopped being told how to reach them.

The design lesson

The specific fault will get patched. The pattern will not go away on its own, because it is structural: modern CDN convenience is increasingly built on control planes with no visible regional boundary from the customer's side, which means a single availability zone incident can have a global blast radius by design. Secure by Design, and its close relative resilience by design, means treating that as a defect to engineer around rather than a fact of life to absorb. For UK organisations that have quietly bet an exam platform, a booking system or a lottery draw on one hyperscaler's edge network, the practical questions are: what happens if this specific control plane fails, not just the region; do we have a second path out; and does our contract with the provider say anything about blast radius at all. "It's someone else's infrastructure" has never meant "it's not my risk."

Also this week

A supplier's login, not Stadler's network. Swiss train maker Stadler Rail refused a $12.3 million ransom demand from the Everest extortion gang this week, after Everest broke into a data-exchange platform belonging to one of Stadler's suppliers using stolen login credentials, rather than Stadler's own systems. Stadler says the stolen material was non-sensitive technical data and that its production lines were never touched. It is a clean illustration of a point UK manufacturers keep re-learning: your perimeter can be perfect and your suppliers' platforms can still hand an attacker a door into your data, which is exactly the gap the next item is trying to close.

Supplier risk becomes statutory. The Cyber Security and Resilience Bill, which cleared the Commons and entered the House of Lords in late June with its second reading this month, would pull managed service providers, large data centres and newly defined "critical suppliers" into UK regulation for the first time, alongside a tighter 24-hour early warning and 72-hour full incident report. Organisations already in scope would have to hold their suppliers to the same standard contractually, turning the Stadler lesson above into a legal obligation rather than good practice. Royal Assent is expected later this year, with implementation phased through 2028, so there is time to get ahead of it rather than discover it during an incident.

Sources

If you'd like to talk through where a single point of failure might be hiding in your own stack, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.