Three Days in August: What a DDoS Attack Exposed in Our Network
5 hours ago
- On 11 August 2026, Nine experienced a major DDoS attack peaking at 500–600 Gbit/s, using UDP amplification from two botnet families (CECbot, Katana).
- The attack initially targeted a customer and then broadened to Nine's own services, including Deploio, the website, Cockpit, and the ticketing system, in recurring waves over 42 hours.
- Mitigation relied on blackholing (making targeted IPs unreachable) and later moving applications behind bunny.net CDN with built-in DDoS protection.
- Three critical gaps were identified: automated detection did not cover customer-announced networks; blackhole signals did not take effect on all peer paths; and shared platform addresses caused unrelated services to be affected.
- Gaps were addressed: fixed detection for all announced networks, services remain behind bunny.net, and platform resilience is being improved to reduce dependency on shared IPs.
- Recommendations for customers include using CNAME/ALIAS records instead of A records and deploying a CDN with DDoS protection for their applications.
- No unauthorized access or data compromise occurred; the attack was a pure overload assault, not an intrusion.