For more information about our Incident Response and Communications please read this support article.

We also maintain a list of Known Product Issues separate from this site here.

[Critical] Issues with multiple Box services

Incident Report for Box

Postmortem

We recently addressed issues affecting Box services. We would like to take the opportunity to further explain these issues and the steps we have taken to prevent them from happening in the future.

On December 16, 2025 between 4:25 PM PST and 7:23 PM PST, some users may have experienced slowness and temporary unavailability while working in Box. The issue occurred when we attempted to roll back a diagnostic change that was suspected of causing a minor degradation. The rollback unintentionally resulted in decreased capacity in our middleware service, leading to a degraded site experience. It also introduced a distributed deadlock condition that prolonged our incident response and mitigation efforts. Ultimately, we were able to resolve the deadlock and return to normal operations by temporarily throttling inbound traffic.

We have implemented measures to increase system capacity and minimize the possibility of a similar deadlock occurring in the future. We are also working on adding safeguards to avoid the rollback failure that served as the proximate cause of this incident.

Analysis

Between 11:11 AM PST and 1:38 PM PST, there was a production deployment of code that was aimed at gathering diagnostic information from our middleware service, in our ongoing efforts to improve system performance and resilience.

At 3:30 PM PST, we observed a brief, mostly imperceptible degradation and decided to roll back the change as a precaution. Due to failure in the rollback procedure, we observed a significantly reduced capacity in our middleware service that eventually led to a distributed deadlock condition between critical databases.

Box has made significant investments in reliability and mitigation measures. In this case, the issue was regional in scope and cross-region recovery capabilities are still in development. We therefore completed recovery by remediating the impacted region directly rather than executing a regional failover.

We restored middleware service capacity by 5:21 PM PST, but the deadlock condition persisted. After several lower-impact attempts to dislodge the deadlock were unsuccessful, we took a broader mitigation step and throttled all traffic at 6:54 PM PST. This resulted in a 26-minute full outage, after which systems stabilized and gradually recovered, with the site returning to full functionality at 7:23 PM PST.

Corrective Actions

Box has initiated the following corrective actions:

  • Complete the planned capacity increase to reduce the chance of similar deadlocks and shorten recovery time if they occur
  • Strengthen rollback safeguards so changes can be safely and reliably reverted, preventing a repeat of the rollback failure that triggered this incident

Thank you again for being a valued Box customer. We are continuously working to improve Box and want to make sure we are delivering the best in class product and user experience. Should you have any additional questions please do not hesitate to contact us.

Sincerely,

The Box Team

Posted Dec 17, 2025 - 18:01 PST

Resolved

After further monitoring, this incident is now considered resolved. Our teams have validated that all affected services are restored to full functionality. Please contact Box Support at https://support.box.com/ if you continue to experience any issues.
Posted Dec 16, 2025 - 20:31 PST

Monitoring

Our team has taken steps to remediate this issue and is seeing improvement for multiple Box services. We are continuing to monitor for any additional impact.
Posted Dec 16, 2025 - 19:42 PST

Update

We are continuing to work on a fix for this issue.
Posted Dec 16, 2025 - 19:17 PST

Update

We are continuing to work on a fix for this issue.
Posted Dec 16, 2025 - 18:36 PST

Update

We are continuing to work on a fix for this issue.
Posted Dec 16, 2025 - 17:42 PST

Identified

Our team has identified the underlying cause of this issue and is working to take remediating steps. We will provide additional updates as they become available.
Posted Dec 16, 2025 - 17:19 PST

Investigating

We are investigating an ongoing issue affecting Logins/SSO, API and Box Notes. We will provide more information as soon as it is available.
Posted Dec 16, 2025 - 16:57 PST
This incident affected: Box Platform / API (Content API, Content Preview, Authentication (OAuth 2.0 / JWT), Search, Uploads/Downloads, Webhooks, Box Embed Widget, Box Sign, Box Canvas, Workflows and Automations, Box Shuttle, Box AI, Box Doc Gen, Box Apps), Box Web Application (Login/SSO), Box Notes (Web Application), and Desktop Applications (Box Drive).