“The incident occurred due to human error and insufficient validation safeguards during a routine abuse remediation for a report about a phishing site hosted on R2.”
One person handling a phishing report disabled the entire R2 gateway instead of one bucket. Every R2 request failed for 59 minutes, and Stream, Images, and Workers deploys went down with it. The fix is two-person approval. Until now, one click could take down production.