FBI DDoS file, 2015–2022: a named threat with no named suspects

The Chronology of Warnings

The FBI’s public record on distributed denial-of-service attacks runs from 2015 through late 2022, accumulating across a series of notices before arriving at a targeted warning. The final document names a concrete threat, assesses its actual damage, and then stops short of identifying anyone responsible.

The paper trail opens on November 18, 2015, when the FBI’s Internet Crime Complaint Center published a Public Service Announcement concerning hacktivist threats directed at law enforcement personnel and public officials, treating distributed denial-of-service (DDoS) attacks in broad terms: a server or website is overwhelmed with incoming requests until legitimate users can no longer reach it.

On October 17, 2017, the FBI returned to the subject with a PSA focused on commercial “Booter” and “Stresser” services, subscription platforms that allow an operator to direct large volumes of traffic at a chosen target without maintaining any technical infrastructure of their own. The 2017 notice identified these services as a mechanism for increasing both the scale and the frequency of DDoS attacks.

On September 30, 2020, a third PSA addressed a narrower concern: the possibility that DDoS attacks could disrupt public access to voting information ahead of a federal election. The notice specified that such attacks would not prevent voting itself, only impede access to information about it.

Activity then accelerated. On October 28, 2022, CISA (the Cybersecurity and Infrastructure Security Agency, a component of the Department of Homeland Security), the FBI, and the Multi-State Information Sharing and Analysis Center (MS-ISAC) jointly published a guide titled “Understanding and Responding to Distributed Denial-of-Service Attacks.” On November 4, 2022, the FBI’s Cyber Division issued Private Industry Notification 20221104-001, coordinated with DHS/CISA. Marked TLP:CLEAR, meaning no restrictions on further distribution, it is available on the FBI’s Internet Crime Complaint Center website and has been archived by the National Security Archive at The George Washington University.

The November Escalation

PIN 20221104-001 places the activity it describes inside a specific context: pro-Russian hacktivist groups acting in connection with the Russian invasion of Ukraine. Hacktivism, the notification explains, refers to collectives motivated by ideological, social, or political causes who conduct cyber operations in pursuit of those goals.

Targeted infrastructure categories include financial institutions, health and medical facilities, emergency services, airports, and government facilities. Public-facing websites and social media profiles are also identified as targets for defacement, the unauthorized alteration of content visible to the public. No attack duration, traffic volume, or specific event date appears in the text; the record operates at the sector level throughout.

Methodology and Artifice

PIN 20221104-001 characterizes DDoS attacks as, in the document’s own phrasing, “an unsophisticated cyber-attack.” Carrying one out requires little technical knowledge, because operators can rely on open-source tools or on the commercial Booter and Stresser services identified in the 2017 PSA.

A secondary layer of the threat is also identified. Hacktivist groups, the notification states, routinely use social media to publicize their actions, claim responsibility, and amplify perceived severity. More specifically, actors recirculate previously stolen or publicly available data to create the impression of a more sophisticated intrusion than actually occurred; and media coverage, the document notes, can encourage follow-on or copycat activity.

Read together, these two elements, low technical threshold and deliberate amplification, suggest the document treats the performance of capability as a tactic alongside, and sometimes independent of, whatever disruption the underlying attack actually produced. Both features are presented as defining characteristics of the threat category, not incidental observations about it.

The Operational Verdict

The FBI’s assessment is direct. For organizations that had implemented mitigation steps, the notification states that attacks of the type described caused minimal operational impact. The FBI states in the notification that the psychological impact was often disproportionate to the actual interruption of service, attributing this to attackers’ deliberate use of social media to inflate the apparent scale of events.

Recommended steps include enrolling in a denial-of-service protection service capable of detecting and redirecting abnormal traffic, establishing a prior relationship with a local internet service provider to enable traffic management during an incident, preparing a disaster recovery plan covering communication and restoration, and monitoring other network assets during and after an attack for signs of secondary intrusion. PIN 20221104-001 was addressed to cybersecurity professionals and system administrators in private industry, and its recommendations are procedural rather than alarming in register.

The Omissions

Two gaps in the record deserve attention as facts about the paperwork, not the events it describes.

Throughout the notification, the responsible parties appear only as “pro-Russian hacktivist groups”, a collective label, never a proper name. Whether this reflects the limits of attribution at the time of drafting, a decision to protect sources and methods, or some other consideration is not stated anywhere in the text.

Equally, no specific target appears anywhere in the document. No company name, facility, or individual infrastructure asset is identified; the sector-level categories, airports, financial institutions, medical centers, emergency services, government facilities, are the only granularity the record provides.

Those two gaps mark the point at which the available documentation stops. PIN 20221104-001, issued TLP:CLEAR and freely distributable, was the FBI’s unrestricted account of the threat as of November 4, 2022. The specific actors behind the described activity and the specific organizations they targeted are not part of this record.