Skip to content
Availability

DDoS attack: your site is down and the traffic keeps coming

The site is unreachable, monitoring is red, and traffic graphs are vertical. Mitigation lives upstream — and sometimes the flood is cover for something quieter.

DDoS attack: your site is down and the traffic keeps coming — Response Red advisory illustration

The essentials

  • Volumetric attacks are absorbed upstream — your hosting provider, CDN, or a DDoS-protection service — not by rebooting your servers.
  • If an extortion email arrived with the flood ("pay or it continues"), do not pay; payment reliably invites the next demand.
  • Watch authentication and admin logs during the noise — DDoS is sometimes a smokescreen for intrusion attempts.
  • Honest status updates to customers beat silence; outages are forgiven, stonewalling is not.
  • Capture traffic graphs and provider tickets as you go; they are the incident record and the insurance evidence.

A distributed denial-of-service attack is a firehose of junk traffic from thousands of sources, aimed at exhausting your bandwidth, connections, or application. It does not breach anything by itself — but it takes you offline, costs real money, and occasionally serves as the loud distraction while something subtler is tried.

The response is mostly about engaging the right layer fast and refusing the panic decisions the attacker is hoping for.

Do this now

  1. Engage the upstream layer. Call or ticket your host, CDN, or DDoS-protection provider and activate their mitigation. If you have no protection layer, several providers can front your site within hours.
  2. Apply what you control. Rate limiting, geo-filtering if the attack is regional, caching static content aggressively, and temporarily disabling the expensive endpoints being hammered.
  3. Check for the ransom note. Search inboxes (including spam) for an extortion demand tied to the attack. Its existence changes the incident from vandalism to extortion — preserve it and do not reply.
  4. Watch behind the noise. Have someone eyeball authentication logs, admin panels, and firewall alerts during the attack. If credential stuffing or exploitation is riding under the flood, you want to see it live.
  5. Tell your customers. A short status note — degraded service, being mitigated, next update at a stated time — protects trust and cuts support load.
  6. Record everything. Traffic graphs, attack vectors your provider identifies, timeline, and costs. Useful for insurance, law enforcement, and hardening afterward.

What not to do

  • Do not pay a DDoS ransom — it marks you as a payer and funds the next attack.
  • Do not reboot servers in a loop; the traffic is external and the reboots add self-inflicted downtime.
  • Do not assume outage is the whole story without checking the logs underneath.
  • Do not improvise DNS changes under fire without your provider's guidance — a mistake extends the outage beyond the attack.
  • Do not go silent publicly while the site is down.

Preserve the evidence

Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:

  • Traffic graphs before, during, and after.
  • The extortion email with headers, if any, and the payment address.
  • Provider tickets, mitigation reports, and identified attack vectors.
  • Your timeline of impact and actions, plus costs incurred.

Keep a clear head

Watching your site fail publicly is stressful in a way that invites theatrical action — mass reboots, live DNS surgery, paying to make it stop. The discipline is the opposite: escalate upstream, communicate calmly, and let mitigation absorb what it is built to absorb.

Most attacks end within hours once real mitigation is in front of you; the attacker's economics rarely support a long siege against a protected target.

Questions victims ask

How long will this last?

Unmitigated: anywhere from minutes to days, at the attacker's whim. With proper upstream mitigation active, most attacks lose effect quickly and the attacker moves to easier targets — their bandwidth costs money too.

If we pay, will it stop?

Sometimes briefly — and then you are on the list of targets that pay. Extortion-driven DDoS depends on that list. Mitigation solves the problem; payment renews it.

How would we know if it's a smokescreen?

The tell is activity that doesn't belong: login attempts spiking, new admin sessions, exploit signatures in application logs during the flood. That is why someone watches the quiet systems while everyone else watches the loud one.

When the first hour is over, we take it from there.

Scoping, containment, forensics, and recovery — expert-led and evidence-safe, with AI removing the waiting. Engage a responder or talk to us about readiness.