Cyber Incident Victim: OTP Bank
Date:
Sep 2020
Location:
Hungary
Summary
A large-scale distributed-denial-of-service (DDoS) attack originating from servers in Russia, China, and Vietnam disrupted Hungarian banking and telecommunications services, including those of OTP Bank. The attack generated data traffic volumes ten times higher than typical DDoS incidents, causing temporary service lapses for financial institutions and network disruptions in parts of Budapest. Magyar Telekom, which described the event as one of Hungary's largest and most complex cyberattacks, collaborated with affected banks to repel the multi-wave assault, restoring normal operations by the same afternoon.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 3 actors | Available to members | Available to members |
Description
On September 24, 2020, Hungarian telecommunications provider Magyar Telekom detected a large-scale distributed-denial-of-service (DDoS) attack targeting both its infrastructure and Hungarian financial institutions. The attack originated from computer servers located in Russia, China, and Vietnam, with data traffic volumes reaching ten times higher than typical DDoS incidents observed previously. Magyar Telekom characterized this as one of the largest and most complex cyber attacks ever recorded in Hungary due to its unprecedented scale and technical sophistication. The assault occurred in multiple waves, temporarily disrupting banking services nationwide and causing intermittent service outages in parts of Budapest where Magyar Telekom provides connectivity. OTP Bank, Hungary's largest commercial bank, confirmed its systems were affected by the attack targeting telecommunications infrastructure supporting its banking operations.

Magyar Telekom's network defenses successfully repelled the attack through coordinated mitigation efforts, with service disruptions ending by Thursday afternoon according to OTP Bank's statement. Both organizations collaborated during the incident, with Magyar Telekom absorbing and neutralizing the abnormal traffic floods while OTP Bank worked to restore full banking service availability. The attack specifically attempted to overwhelm network capacity through massive data volume spikes characteristic of DDoS methodology, though no data breaches or system infiltrations were reported. Normal operations resumed within hours for both telecommunications and banking services following containment measures. No additional technical details regarding specific affected systems, customer impact duration, or forensic findings were disclosed publicly by either organization beyond confirming the attack's cross-border origin and mitigated status.
