← Back to news

Service Incident - May 11, 2026 - Billing | All Pods

Zendesk

A third-party migration executed by Zendesk's billing provider Zuora introduced a critical vulnerability in subscription and billing operations across all pods between May 11 and May 13, 2026. The migration, intended to enable usage-rating functionality, performed unnecessary large-scale updates to historical billing-period data, creating a prolonged processing job that blocked API operations required for subscription changes and order placement. Customers attempting to modify their billing or subscription settings encountered "your order wasn't placed" errors, with the incident spanning two separate outage windows totalling approximately 32 hours of disruption. The root cause reveals a fundamental breakdown in change management: Zendesk received insufficient advance notice of the migration, hampering their ability to staff monitoring adequately or validate the changes before they cascaded through production systems.

The implications for CX teams are twofold. First, this incident exposes a critical dependency risk that extends beyond Zendesk's direct control—when third-party providers execute migrations without proper coordination, even feature-enhancement work can disable core transactional capabilities. For teams managing multi-tenant SaaS platforms or those relying on integrated billing systems, this raises an uncomfortable question: how visible is your own third-party change management, and what happens to your customers' ability to modify their accounts when upstream vendors prioritise feature velocity over operational readiness? Second, the manual analysis required to identify impacted transactions and the need for customers to manually resubmit changes suggests that observability into billing workflows remains a weak point even for mature platforms. Teams should audit whether their own incident response protocols can quickly surface which customers were affected by transactional failures, or whether they too would resort to broad customer communication and manual remediation.

Zendesk's remediation roadmap—tighter change management protocols with third parties, improved monitoring on critical billing flows, and enhanced logging for faster customer impact identification—addresses the symptoms rather than the structural issue. The real question for CX leaders is whether these preventative measures will actually prevent similar incidents, or whether they simply represent the standard post-incident commitments that often fade once operational pressure normalises. The incident also underscores that billing system reliability cannot be treated as a secondary concern; when subscription changes fail silently or with generic error messages, customer trust erodes faster than in any support interaction.