CSIDB logo
Incident

Coral Telecom

Incident posture

Attack window
Apr 2023
Location
Saint Martin
Status
Historical
CIA posture
Available to members
Updated
2026-01-07 02:28

Linked entities

Victim
Coral Telecom
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack disrupted services for Coral Telecom and another operator, impacting fixed and mobile internet connectivity due to a DDoS attack that flooded their network with malicious traffic. The incident required temporary service cuts to mitigate user impact, with full restoration achieved after implementing reinforced security solutions, while additional protective measures remained underway.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The cyber incident impacting Coral Telecom and Dauphin Telecom occurred during the Easter weekend of April 7-9, 2023, with disruptions becoming publicly evident on April 10. Both telecommunications operators experienced service interruptions affecting fixed and mobile internet connectivity for subscribers. The attack targeted critical infrastructure—specifically, the transport cable linking the French Antilles to the North American continent—through a distributed denial-of-service (DDoS) attack. This technique overwhelmed the network with malicious traffic to render it unavailable. Dauphin Telecom issued notifications to customers acknowledging technical problems requiring immediate mitigation efforts, including temporary service offloading or cuts to prevent broader user impact from ongoing piracy activities. Coral Telecom, identified as partially Dutch-owned, faced parallel disruptions but did not release independent public statements regarding its operational status during the initial phase.

Technical teams responded by implementing reinforced security solutions designed to protect data integrity while restoring availability. These measures enabled full service restoration by the evening of April 10. The operators characterized the attack as requiring proactive containment strategies to isolate compromised network segments. Dauphin Telecom confirmed ongoing deployment of additional security enhancements following the initial recovery and committed to providing a progress update by the end of April 10. No quantitative details regarding attack volume, subscriber impact statistics, or financial consequences were disclosed in available communications. The incident remained confined to service availability issues without cited evidence of data exfiltration or secondary attack vectors. Both entities treated the event as a resolved operational disruption with continued vigilance toward infrastructure hardening.

Sources

Sources available to members: 1 source.

CSIDB