
He also pointed out that the attackers’ Twitter feed included them having “called in a lot of fake bomb threats recently,” adding: “They are clearly bad actors and we will pass on any intelligence we gather to the appropriate authorities after we make our own investigation and research.”Ī little later today, and a little more comfortable about having got the attack under control - despite confirming the attackers are “still hitting us” - Yen said: “Throughout the day, we have gotten a lot better at blocking this type of attack so now things are stable. “It is multi-vector, and they are dynamically changing the type of attack traffic they are sending at us, so it’s a higher level of sophistication than the usual ones,” f ounder Andy Yen told us, in the midst of firefighting the attack earlier today. “While we don’t yet have our own measurement of the attack size, we have traced the attack back to a group that claims to have ties to Russia, and the attack is said to have been 500 Gbps, which would be among the largest DDoS’s on record.” “Radware is making adjustments to their DDoS protection systems to better mitigate against this type of attack in the future,” the company also writes on Reddit. We were actually a little slow this time. That said, while it’s claiming today’s attacks were orders of magnitude bigger than usual, its CTO Bart Butler also sounds less than pleased with how things went down today, tweeting in response to a user: “We will be evaluating this incident in the future, as it definitely should have been handled better.” Since then it’s had a good record with uptime, despite dealing with DDoS attacks on a daily basis. Although the experience also led ProtonMail to spend on upgrading its defenses. And felt compelled to pay a ransom to fend off the hackers - a decision which earned it criticism from some segments of the security industry, and is perhaps coming back to haunt it now.

The longest outage has been “on the order of 10 minutes,” according to ProtonMail.īack in 2015 the then fledgling startup suffered a major DDoS attack. In a statement on Reddit the company says the attack is “unlike the more ‘generic’ DDoS attacks that we deal with on a daily basis” - which in turn meant its upstream DDoS protection service (Radware) needed more time than usual to mitigate the attack. We are working with our upstream providers to mitigate the attack. Our network has been under sustained attack this morning.
