We are seeing continued DDoS attacks against our infrastructure
status.fastmail.com
status.fastmail.com
"Victims were targeted with a DDoS attack, and an email was later sent to the organizations, asking for a 0.06 BTC (~$4,000) ransom demand."
Four thousand dollars. I guess they were trying to shoot low in hopes of a quick payment?
Also, Runbox posted a copy of the ransom email: https://blog.runbox.com/2021/10/runbox-is-under-attack-by-ex...
"Give me $50 or I break the windows in this place!"
Next week:
"Give me $75 or I break the windows in this place!"
https://capitalgram.com/posts/how-to-money-launder-bitcoin/
For example, the REVil author is known
https://threatpost.com/revil-ransomware-core-member/175863/
It is all about geopolitics, privateering and for Russia and China to see incompetent Western companies to suffer.
edit: not a crypto fan personally.
Bitcoin makes it easier.
(nothing personal, plenty of people use it but it is so illogical that it wild be unethical not to protest)
Warm them up to the idea of capitulation?
So it's sent prior to the attack.
According to the article, this is targeting multiple "privacy and security-centric email services". What are the odds this is a coordinated attempt to drive folks to less secure, or bigger corporate services?
Cloud email providers were a dream come true to the world's intelligence agencies and law enforcement.
And, as a customer, I’ll stand by their efforts not to capitulate.
Fastmail, Runbox, and Posteo under DDoS extortion attack - https://news.ycombinator.com/item?id=28968046 - Oct 2021 (123 comments)
Fastmail is having problems again - https://news.ycombinator.com/item?id=28963609 - Oct 2021 (132 comments)
We're seeing an ongoing attack against our primary network provider - https://news.ycombinator.com/item?id=28952954 - Oct 2021 (87 comments)
Can't really blame them, though, not much you can do with cannons pointed at you. I'm sure they'll be back up soon.
https://protonmail.com/support/knowledge-base/email-ddos-pro...
It's not bottom of the barrel outsourced "customer service" designed to point people to FAQ articles. It's professionals who work as professionals.
I'm sticking with Fastmail for now.
And in times like today, it's so nice to be able to say "hey, $person_working_now, could you deal with fastmailstatus.com and Twitter please?" and the engineering staff don't even have to think about it!
https://protonmail.com/support/knowledge-base/email-ddos-pro...
People want money. Motivation is as old as time.
> As a user this is extremely inconvenient.
Lol well yes that’s the aim!
Among the reasons cybercriminals love DDoS:
2) It gives them a convenient smokescreen. Cybercriminals like to create confusion - and they sometimes turn to DDoS attacks to distract and misdirect resource-deprived organizations from their primary goal: to pillage sensitive data. DDoS attacks are optimal subterfuge because they create noise and chaos that will attract the brunt of attention from your IT staff, leaving wide open the opportunity for your foes to simultaneously infiltrate your network and mask data exfiltration.
3) It can be the digital pretext to a physical attack. Sometimes a DDoS attack is merely a means to an end. Earlier this week our SpiderLabs team revealed a web-based vulnerability in a popular brand of printers that could result in denial-of-service attacks. Our researchers theorized that attackers could launch the printer attack and show up at the target organization pretending to be the "technician" called to fix the problem. This impersonation could net them direct physical access to IT resources that they might never have been able to access remotely.
A week ago, there was a post titled “Fastmail is having problems again”, so today, “yet again” seemed adequate:
Edit: Spoke too soon. Getting errors now.