Accidental Deletion of UniSuper’s $135 Billion Account
Due to a misconfiguration, Google mistakenly erased the $135 billion account of the Australian pension fund UniSuper, affecting over 600,000 members and preventing them from accessing their data for two weeks.
Cause of the Deletion
Due to a blank parameter that was left in place during UniSuper’s private cloud deployment, their account and backups were inadvertently deleted, necessitating a significant amount of work on the part of the Google and UniSuper teams to recover.
Resolution and Preventive Measures By Google
Since then, Google has fixed the issue, shifted the functionality to user-controlled interfaces, made sure that no other accounts are set incorrectly, and emphasized that this was an isolated occurrence.
“During the initial deployment of a Google Cloud VMware Engine (GCVE) Private Cloud for the customer using an internal tool, there was an inadvertent misconfiguration of the GCVE service by Google operators due to leaving a parameter blank. This had the unintended and then unknown consequence of defaulting the customer’s GCVE Private Cloud to a fixed term, with automatic deletion at the end of that period. The incident trigger and the downstream system behavior have both been corrected to ensure that this cannot happen again.”