I’ll modify that - the ransomware operator may have worked with Ransomhub in the recent past.
Azure services not impacted, just some private cloud. Obviously they have multiple DCs. There is apparently DR and backups.. but, well, the proof is in DR working.
There’s a webpage for the security incident but it hasn’t been updated in 3 days and isn’t linked on the website. https://blueyonder.com/customer-update