Just look at the ADs to these sites that are super flashy and cool to cater to these teens
Edit: Example ADs: https://i.imgur.com/PjqG7dC.gif https://i.imgur.com/ebp4ERm.gif https://i.imgur.com/kTM3fAA.gif
Because of this, a lot of games companies will try to mask the actual IP of the other users now, and Steam has tooling for games they support for devs on their platform.
99% of ddos attacks aren't that serious
https://www.hackread.com/15-years-prison-for-man-who-hired-a...
Our small company's site got DDoSed a month ago and we just let it pass since we're not too convinced that the authorities will take us seriously. We don't even know where to start, just saved the logs with a few hundred random IPs from different countries hoping some day we can do something about it...
From my experience they will get back to you quickly (usually in <1-2 hour) and they can try helping out if you are still under attack / need some consultation.
Will we ever get compensated for the wasted engineering time to stop these attacks? probably not, but if the police ever finds them and they have extra logs of companies that reported issues, its likely an aggravation of the case.
Oh my, the attack caused so much wasted time and stress that it's still haunting me and the team, specially when thinking that it may not stop there and the attacker/s is just waiting for the next chance to hit us. The days after the attack the first thing I did after waking up was check the servers to see everything was safe. And our roadmap was severely affected too, prioritizing many security features we had in the backlog.
Thank you so much.
Regarding security features, if you are on a cloud such as GCP, AWS or Azure things are complicated since you can't easily route the traffic elsewhere(you can have BGP connections to DDoS mitigation inside GRE/L2TP tunnels only when attacks occur and it would be cheap to rent on a monthly/yearly basis). Voxility is an example that comes to mind and they are very affordable in general terms.
HTTP or HTTPs attacks are easier to handle with Cloudflare, however, there are other interesting solutions such as Stackpath.
I realize we were lucky that the attacker didn't find any of the soft spots (or at least none that hurt us). We do prioritize security though, always.
I hope all goes well for you and that in time this is just another learning experience. Maybe next time you'll smile when an attack is thwarted because of what you've all learned.
Both require tweaking and are far from being 1-click setup tools (despite some marketing attempts that try to make it seem that way), however, if you can manage them, they are very powerful and considerably cheaper than other alternatives.
It helps if you have a suspect, typically your local LE will have a cyber division that will know what the next steps are.
Thank you!