166 terms · 75/46/45
Threat № 055 · class: availability

Ransom DDoS

Ransom DDoS joins an attack on availability to extortion. The attackers threaten to bring the service down, or first run a short demonstration attack, and then ask for money for the attack to stop or for a larger one not to happen.

Term

description · examples · notes

Ransom DDoS joins an attack on availability to extortion. The attackers threaten to bring the service down, or first run a short demonstration attack, and then ask for money for the attack to stop or for a larger one not to happen.

Description

The targets are organizations whose availability is directly tied to revenue, trust or public pressure: e-commerce, finance, online services, gaming, media, government services. The threat often arrives at the moment when downtime would hurt most — before a campaign, a deadline, an event or a selling season.

Paying does not solve the underlying problem. There is no guarantee the attack will stop, nor that the same gang or somebody else will not return. If an organization shows that it pays for availability, it becomes a more interesting target.

Examples

  • An e-commerce platform receives a DDoS threat immediately before Black Friday.
  • The attackers run a short attack as proof of capability and then ask for payment in cryptocurrency.
  • A series of smaller attacks intensifies day by day, alongside messages that put pressure on management.

Notes

  • With ransom DDoS, negotiation is not a defense plan. The defense plan is protection arranged in advance, contact with the providers, and a rehearsed incident response.
  • If protection is sought only once the threat arrives, the organization negotiates from a poor position.
Composite
Wikipedia

Techniques

carried out with 1

Techniques used to carry it out. Select one to open its page.

Defenses

countered by 3

How it is defended against. Select one to open its page.