Ransom DDoS
Ransom DDoS joins an attack on availability to extortion. The attackers threaten to bring the service down, or first run a short demonstration attack, and then ask for money for the attack to stop or for a larger one not to happen.
Term
description · examples · notesRansom DDoS joins an attack on availability to extortion. The attackers threaten to bring the service down, or first run a short demonstration attack, and then ask for money for the attack to stop or for a larger one not to happen.
Description
The targets are organizations whose availability is directly tied to revenue, trust or public pressure: e-commerce, finance, online services, gaming, media, government services. The threat often arrives at the moment when downtime would hurt most — before a campaign, a deadline, an event or a selling season.
Paying does not solve the underlying problem. There is no guarantee the attack will stop, nor that the same gang or somebody else will not return. If an organization shows that it pays for availability, it becomes a more interesting target.
Examples
- An e-commerce platform receives a DDoS threat immediately before Black Friday.
- The attackers run a short attack as proof of capability and then ask for payment in cryptocurrency.
- A series of smaller attacks intensifies day by day, alongside messages that put pressure on management.
Notes
- With ransom DDoS, negotiation is not a defense plan. The defense plan is protection arranged in advance, contact with the providers, and a rehearsed incident response.
- If protection is sought only once the threat arrives, the organization negotiates from a poor position.
Techniques
carried out with 1Techniques used to carry it out. Select one to open its page.
Defenses
countered by 3How it is defended against. Select one to open its page.