CSIDB logo
Incident

Business Wire

Incident posture

Attack window
Jan 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-30 00:00

Linked entities

Victim
Business Wire
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jan 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Business Wire, a press release distribution service owned by Berkshire Hathaway, experienced a sustained distributed denial-of-service (DDoS) attack targeting its service portal, causing intermittent slowness for clients accessing its website. The attack involved overwhelming traffic from multiple sources but did not disrupt content dissemination capabilities or compromise internal systems or client information. The company's operational teams collaborated with external partners to mitigate the attack and stabilize services, emphasizing that core functionality remained intact despite the disruption. This incident highlighted broader cybersecurity challenges faced by organizations, as DDoS attacks increasingly leverage high-volume bandwidth to create prolonged service interruptions while potentially diverting attention from other threats.

Motives

Detailed motive labels are available to members.

4 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 31, 2018, Business Wire, a press release distribution service owned by Berkshire Hathaway, experienced a distributed denial-of-service (DDoS) attack targeting its online service portal. The attack continued for at least one week, as confirmed in a February 7 internal memo from Chief Operating Officer Richard DeLeo. Attackers attempted to overwhelm BusinessWire.com with malicious traffic from multiple sources, aiming to render the website unavailable. Clients reported intermittent slowness when accessing the portal during this period, though the company emphasized its core content dissemination services remained fully operational throughout the incident. Business Wire confirmed no evidence of data compromise or unauthorized access to client information systems, indicating the attack solely targeted availability rather than confidentiality or integrity.

Business Wire's security team collaborated with external partners to implement mitigation measures against the sustained attack, working to stabilize their web infrastructure. The company maintained transparency with clients through direct communications while continuing normal press release distribution operations. Industry context provided by security vendors indicated such attacks averaged 15 incidents annually per organization, typically causing 17 hours of downtime ranging from performance degradation to complete service outages. Contemporary DDoS attacks frequently reached bandwidth peaks of 30-40 Gbps, with some exceeding these volumes. Cybersecurity experts contemporaneously noted the growing challenge of IoT device exploitation in amplifying attacks, while also cautioning that visible DDoS incidents could potentially distract security teams from concurrent stealthier intrusions. Business Wire's public communications focused exclusively on service impact and remediation efforts without attributing motives or identifying perpetrators.

Sources

Sources available to members: 1 source.

CSIDB