CSIDB logo
Incident

Direct Communications

Incident posture

Attack window
Sep 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-22 23:48

Linked entities

Victim
Direct Communications
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2026
Discovered
Sep 2026
Disclosed
Sep 2026
Resolved
Pending

Summary

Direct Communications reported a cyberattack that generated unusually high traffic consistent with a distributed denial‑of‑service attack, causing internet outages and service disruptions for customers in Eagle Mountain. The attack also impacted the company’s upstream network providers, leading to slow speeds, packet loss and complete service losses for many users. After an upstream provider applied a fix, service briefly stabilized but continued to fluctuate as the company responded to the ongoing attack, prompting the temporary closure of its Eagle Mountain office and the unavailability of customer service and phone lines. The company advised affected customers to power‑cycle their routers and noted that those who performed a factory reset would need to reconfigure their devices.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 19, 2026, Direct Communications reported that its network experienced unusually high traffic consistent with a distributed denial-of-service attack, which caused internet outages and service disruptions for customers throughout Eagle Mountain, Utah. The company stated that the attack began on that date and quickly led to degraded performance, including slow speeds, packet loss, and complete service outages for many subscribers. The disruption extended beyond Direct Communications’ own infrastructure, affecting its upstream network providers and amplifying the impact on end‑user connectivity. Customers reported loss of internet access and intermittent connectivity as the attack traffic saturated the company’s links. The company characterized the event as a cyberattack that prompted immediate investigation into the source and volume of the malicious traffic.

In response, Direct Communications coordinated with its upstream providers, and one of those providers implemented a fix that restored stability to the network, according to the company’s later statement. Despite the fix, Direct Communications warned that some customers might continue to experience slower-than-normal speeds or other performance issues as the network stabilized. The company advised affected customers to power‑cycle their residential routers by unplugging them for approximately thirty seconds before reconnecting, and noted that any routers that had been factory reset during the outage would require reconfiguration. Direct Communications also said it would continue monitoring its network for further anomalous traffic and would provide updates as the situation evolved. A Sunday evening update indicated that service had briefly stabilized but continued to fluctuate throughout the day as the company remained engaged in mitigating the ongoing cyberattack.

Because the outage disrupted both internet and phone service at its Eagle Mountain office, Direct Communications announced that the office would be temporarily closed to the public until normal service was restored. Customer service and technical support telephone lines were likewise unavailable during the outage, as they relied on the same compromised connectivity. The company stated that its business office and tech support lines would resume operations once the network was fully stable and service had been restored for all affected customers. Direct Communications emphasized that it would keep customers informed of any further developments and would work to prevent similar incidents in the future.

Sources

Sources available to members: 1 source.

CSIDB