December 2021 has brought with it holiday cheer and an uptick in distributed denial of service attacks (DDOS) attacks. DDOS attacks are fast becoming a new tool in the extortionist threat actor’s toolkit. DDOS attacks are attractive because they don’t require attackers to actually hack into a company’s systems. Instead, a DDOS attack targets a website or other online service. The attacker attempts to flood a targeted service with traffic by using numerous compromised computer systems, including IoT devices, as sources of attack traffic. Think of a DDOS attack like your home phone from the 1980s. If multiple callers are constantly calling your number, legitimate callers will get a constant busy signal. The goal, of course, is to get a company to pay the threat actors to stop the attack and resume normal operations.

GT has seen this increase in two primary ways. First, as an add-on to a ransomware attack. Ransomware attacks have evolved over the past several years beyond simply encrypting a company’s servers and endpoints, to increasingly exfiltrating and threatening to publicly post or sell company data, to now threatening and/or committing DDOS attacks. Second, certain threat actors are skipping the ransomware attack and heading straight to the threat of a DDOS attack.

Fortunately, some of these threat actors are bluffing and lack the resources to conduct a full-blown attack. They may instead hit a company’s network with a short burst of traffic, and then will use that burst to suggest they have much more firepower behind them. Others, however, are conducting full-blown attacks.

If you are concerned about DDOS attacks, Greenberg Traurig has a 24/7 data breach hotline at 855.3BREACH, where you can speak with a data security attorney about options for prevention and response.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Jena M. Valdetero Jena M. Valdetero

Jena M. Valdetero serves as Co-Chair of the firm’s U.S. Data Privacy and Cybersecurity Practice, and is a trusted advisor to clients facing complex and high-stakes data privacy and security challenges. With a track record of leading thousands of data breach investigations for…

Jena M. Valdetero serves as Co-Chair of the firm’s U.S. Data Privacy and Cybersecurity Practice, and is a trusted advisor to clients facing complex and high-stakes data privacy and security challenges. With a track record of leading thousands of data breach investigations for more than 20 years, Jena combines her broad litigation experience with a deep understanding of the evolving privacy landscape to protect her clients’ interests. She is highly skilled in defending companies in privacy and data breach litigation, particularly class actions, and is proactive in helping clients prepare for incidents by designing and facilitating customized tabletop exercises.

Jena offers practical, results-driven counsel on data privacy and security compliance programs and guides clients through privacy and cyber risk considerations in mergers, acquisitions, venture capital, and securities transactions. Her experience spans a wide range of privacy laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Gramm Leach Bliley Act (GLBA), and the Health Insurance Portability and Accountability Act (HIPAA). Certified as a privacy professional through the International Association of Privacy Professionals (CIPP/US),  Jena provides clients with actionable insights on both current and emerging privacy regulations. She previously served as KnowledgeNet Co-Chair for the International Association of Privacy Professionals, further reflecting her leadership in the field. Jena is a founding board member of the Chicago Compassion Project, a nonprofit supporting low-income families in Chicago.

Jena has been recognized by Chambers USA as a leading privacy and data security lawyer, with clients praising her “very deep knowledge of subject matter” and calling her “extremely responsive and business-minded.” She is trusted for her “great strategic advice” and practical approach to complex data privacy issues, with one client saying, “I’d unequivocally recommend her to anybody with any kind of privacy or data breach concerns.”