RDoS: When DDoS Becomes Extortion
Ransom-DDoS gangs threaten attacks and demand a ransom. Here's how an RDoS campaign unfolds, why you shouldn't pay and how to prepare.
Last technical update:
RDoS (Ransom Denial of Service) is the extortion variant of the DDoS attack: criminals threaten a massive attack on your infrastructure and demand a payment - often in cryptocurrency - not to carry it out or to stop it.
How an RDoS extortion unfolds
- 1Threat: you receive an email announcing an attack and demanding a ransom by a deadline.
- 2Demo attack: to back it up, a short, targeted attack often follows as a 'taster'.
- 3Escalation: if you don't pay, the perpetrators threaten larger, longer attacks.
Should you pay?
No. A payment guarantees nothing - it marks you as willing to pay and invites further demands. Security authorities consistently advise against it. The effective answer is technical preparation, not ransom.
How to prepare
- Enable network-level mitigation, ideally with an always-on option.
- Keep an escalation and communication plan ready (who decides, who informs).
- Ensure capacity headroom and 24/7 support with your upstream.
- Document the threat and report the incident to the authorities.
Prepared with AS51202
Our DDoS-protected IP Transit filters attacks in the network before they reach your connection. In an emergency you reach real network engineers 24/7 who steer mitigation with you.
Conclusion
RDoS thrives on pressure and fear. Those who are technically prepared and can mitigate in the network remove the basis for extortion - and don't have to pay.