Ransom DDoS Attack

Learn what a ransom DDoS attack is, how it works, and how to protect your business from extortion-based threats.

Search Numbers
20+
Years in Business
10,000+
Happy Customers
100+
Features Included
24/7
Expert Support
Ransom DDoS attack diagram illustrating how attack traffic is distributed across multiple sources to overwhelm a target

What Is a Ransom DDoS Attack?

A ransom DDoS (RDDoS) attack is when malicious parties attempt to extort money from an individual or organization by threatening them with a distributed denial-of-service (DDoS) attack. The malicious party may carry out a DDoS attack and then follow up with a ransom note demanding payment to stop the attack, or they may send the ransom note threatening a DDoS attack first. In the second case, the attacker may not actually be capable of carrying out the attack — although it is not wise to assume they are making an empty threat.

The best protection against DDoS ransom attacks is a strong DDoS mitigation service. It is never a good idea to pay the ransom to the person or group making the threats.

What Is a DDoS Attack?

A DDoS attack is an attempt to exhaust the resources of an application, website, or network so that legitimate users cannot receive service. DDoS attacks send a flood of junk network traffic to their targets — much like a traffic jam clogging up a freeway. DDoS attacks are “distributed,” meaning they send traffic from a variety of sources (often spoofed sources), making them more difficult to block than a denial-of-service (DoS) attack from a single source.

DDoS attackers use a number of different networking protocols. Read about different types of DDoS attacks here.

DDoS attacks can have a major impact on an organization’s operations. For many businesses, any downtime means a loss of revenue. Organizations may also lose credibility if they are offline for an extended period of time.

How Does a Ransom DDoS Attack Work?

Most DDoS ransom attacks start with a ransom note sent to the target in which the attacker threatens the business or organization. In some cases, an attacker may carry out a small demonstration attack to illustrate their seriousness before sending the ransom note. If the threat is genuine and the attacker decides to follow through, the attack unfolds as follows:

  1. Attack traffic begins. The attacker starts sending attack traffic to the target, using their own botnet, a hired DDoS service, or DDoS tools operated by multiple collaborators. Attack traffic can target layers 3, 4, or 7 in the OSI model.
  2. The target is overwhelmed. The targeted application or service becomes overwhelmed by the attack traffic, causing it to slow to a crawl or crash altogether.
  3. The attack continues until stopped. The attack persists until the attacker’s resources are exhausted, they shut it down for another reason, or the target successfully mitigates it. Mitigation methods include rate limiting, IP blocking, blackhole routing, or a dedicated DDoS protection service — the first three are difficult to implement against highly distributed attacks.
  4. Demands may escalate. The attacker may renew their demands for payment, carry out subsequent attacks, or both.

What Goes Into a Typical DDoS Ransom Note?

A DDoS ransom note is a message sent from a malicious party to a business demanding money — or else the malicious party will carry out a DDoS attack. These messages are often sent via email. Sometimes the attacker will send multiple messages, with each one revealing more details about their specific threats or demands. A typical ransom note contains some or all of the following elements:

The Threat

The threat contained in a DDoS ransom note can take a few different forms:

  • The malicious party may take credit for a previous DDoS attack and threaten another one.
  • They may take credit for a DDoS attack that is currently in progress against the target.
  • They may threaten a future DDoS attack, either at a specific time or at an undefined time.

Details of the Threatened Attack

To make the threat sound more dangerous, the attacker may claim to be capable of carrying out a DDoS attack of a certain size and duration. These claims are not necessarily true: just because someone claims to be capable of a 3 Tbps attack lasting 24 hours does not mean they actually have the resources to follow through with it.

Group Affiliation

To add credibility to their threats, the attacker may claim affiliation with well-known hacker groups such as Fancy Bear, Cozy Bear, the Lazarus Group, the Armada Collective, or others. These claims might be true but are difficult to verify — they may represent a bluff or a copycat attempt on the part of the attacker.

Demand for Payment and Delivery Instructions

The ransom note will demand payment in some form. Payment in Bitcoin is a common request, but the attacker may also ask for payment in another cryptocurrency or a state-sanctioned currency (dollars, euros, etc.). At a certain point they will typically ask for a specific amount and provide instructions for delivering it.

Time Limit or Deadline

To give their demand urgency and increase the likelihood that the targeted party will comply, the ransom note will typically include a hard deadline for delivering payment. This time pressure is a deliberate tactic to discourage victims from seeking professional help or notifying authorities before paying.

Key Takeaway: Never pay a DDoS ransom. Paying does not guarantee the attack will stop, marks you as a willing target for future extortion, and may fund further criminal activity. Work with a reputable DDoS mitigation provider and report the threat to law enforcement.

Simple, Transparent Plans

No contracts. No hidden fees. Cancel anytime.

Call Forwarding

$6.95/mo
per number

  • 1 toll-free number with your choice of prefix
  • 100 free inbound minutes per month
  • Additional minutes at 5.9¢/min
  • Auto attendant and voicemail included
  • Call recording and virtual fax
  • Interactive voice response (IVR)
  • AI receptionist — no monthly fee, just 15¢/min

Best Value

Business Phone Basic

$24.95/mo
per user

  • 1 toll-free number per user
  • Everything in eBizLine Lite
  • Call forwarding at 1.2¢/min
  • Email, SMS, and workflow automation
  • Microsoft Teams integration
  • Advanced call analytics and reporting
  • Priority support
  • AI receptionist — no monthly fee, just 10¢/min

Frequently Asked Questions

A ransom DDoS (RDDoS) attack is when malicious parties attempt to extort money from an individual or organization by threatening them with a distributed denial-of-service (DDoS) attack. The attacker may carry out a DDoS attack and then demand payment to stop it, or they may send a ransom note threatening a future attack.
The best protection against DDoS ransom attacks is a strong DDoS mitigation service. It is never a good idea to pay the ransom to the person or group making the threats.
A DDoS ransom note typically includes the threat itself, details about the claimed attack size and duration, a group affiliation claim, a demand for payment (often in Bitcoin or another cryptocurrency), and a deadline for delivering the payment.
No. It is never a good idea to pay the ransom. The attacker may not even be capable of carrying out the attack, and paying only encourages further extortion attempts.

Ready to Get Started?

Search available numbers, pick your plan, and your business phone is live in minutes.

Search Numbers
Call Us