FIRSTBranch Partial Interruption in Service

Incident Report for Kasasa

Postmortem

On June 24, 2025, Kasasa’s FIRSTBranch team inadvertently deployed an incomplete Content Security Policy (CSP) update, causing an outage that affected some third-party scripts, including online banking logins, on FIRSTBranch sites. A CSP is a security feature that helps protect against cross-site scripting (XSS) attacks by controlling which scripts are allowed to run. This update used a nonce attribute - a unique, server-generated code - to allow only approved scripts. The premature deployment caused legitimate third-party scripts to be flagged and blocked.

Although the issue was quickly identified, delays in reverting the code extended the outage. A brief recurrence happened on June 25 due to an accidental merge, which was promptly reverted. The CSP implementation is now being thoroughly tested before any future rollout.

Some users may have noticed persistent caching issues even after the problem was addressed; clearing browser cache resolved any lingering issues.

We apologize for the disruption and appreciate your patience. Thank you for your understanding.

Posted Jun 30, 2025 - 12:51 CDT

Resolved

This incident has been resolved.
Posted Jun 30, 2025 - 10:11 CDT

Update

Please note: We remain in a monitoring phase of this incident at this time. If you are still experiencing intermittent issues - it is recommended that you take your browser through a hard refresh exercise.

Quick Hard Refresh Instructions by Browser:

Windows:
Chrome / Edge / Firefox:
Press Ctrl + F5

Mac:
Chrome / Firefox:
Press Command (⌘) + Shift + R
Safari:
Press Option + Command (⌘) + E to clear cache, then reload the page
Posted Jun 25, 2025 - 19:05 CDT

Update

We are continuing to monitor for any further issues.
Posted Jun 25, 2025 - 10:26 CDT

Monitoring

A fix has been implemented and we are monitoring the results.
Posted Jun 25, 2025 - 10:26 CDT

Investigating

Please note: FIRSTBranch websites are currently experiencing partial interruptions in service. We are currently investigating and will update as we have more information.
Posted Jun 25, 2025 - 09:52 CDT
This incident affected: FIRSTBranch.