Case file · CODE SPACES 2014

How the Code Spaces hack happened: one cloud login deleted a company in 12 hours

Published 2026-09-29 · 4 min read · Missing control: MFA on the cloud admin console

In June 2014, a code-hosting company that advertised full redundancy and real-time backups to multiple off-site locations went out of business in about 12 hours.[1][2] This case file covers how one stolen cloud login let an extortionist delete the company's servers and its backups together, and the control that would have kept the key out of his hands.

What happened

Code Spaces sold hosted source-code storage and project tools to software teams. Its website said more than 200 companies a week used the service, and it promised customers high availability, real-time off-site backups and a proven recovery plan.[2] The whole business ran on Amazon Web Services, the cloud platform where companies rent servers and storage and manage them through a web control panel.[1]

In mid-June 2014, Code Spaces was hit with a denial-of-service attack, a flood of junk traffic meant to knock a site offline. At the same time, someone had gotten into the company's Amazon control panel and left messages demanding money, along with a free email address to reply to.[1]

Staff tried to take back control by changing the control panel passwords. It did not work. The intruder had already created extra logins for himself, and when he saw the company fighting back, he began deleting.[1] Machine images, storage volumes, database files, snapshots, storage buckets and backups disappeared. Only a few old code repositories survived.[1]

Code Spaces then posted a statement saying most of its data, backups, machine configurations and off-site backups had been partly or completely deleted. It said it could not keep operating, would help customers export whatever data was left, and would cease trading.[1][2]

How they got in

The company did not publicly explain how the attacker got its control panel login.[1] What is clear is what that login could do. One account had the power to create new users, to run and remove servers, and to delete every copy of the data, including the ones the company thought of as backups.[1]

That is the core problem. Code Spaces' backups were real, and they were in more than one place, but all of them could be reached and erased from the same cloud account. To the attacker, the backups were just more things to delete.[1][2]

How it was caught

This attack announced itself. The attacker wanted to be paid, so he made sure the company knew he was inside.[1] The problem was not detection but what came after. Changing passwords did not remove the extra logins the intruder had already set up, so the company's attempt to lock him out only prompted him to act.[1]

Security specialists quoted after the attack said it showed the need for stronger sign-in than passwords alone for cloud control panels, frequent rotation of access keys, and monitoring that flags unexpected changes such as new accounts being created.[2]

What it cost

Everything. Within about 12 hours of the first attack, the company said it had lost most of its data and could not continue.[1][2] The loss was financial and also a matter of trust: a business that sold safe storage could not survive losing its customers' code.[2] Customers who had relied on Code Spaces as their only copy of their work lost that too.

The missing control

The missing control: multi-factor authentication on the cloud admin console, backed by backups that the same admin login cannot delete.

With a second sign-in step, such as a code from a phone app or a hardware key, a stolen password alone would not have opened the control panel. And if the backups had lived in a separate account, or in storage set up so that copies cannot be erased for a set time, the attacker could have caused a bad day instead of ending the company. The redundancy Code Spaces advertised was real for hardware failures. It offered no protection against one person with the master key.

What to do in your business

Watch the case
The cloud hack that deleted a company in twelve hoursDrops 2026-12-30
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Threatpost: Hacker puts hosting service Code Spaces out of business
  2. PCWorld: Hacker puts 'full redundancy' code-hosting firm out of business