Cyber Incident Victim: RiseUp
Date:
Oct 2021
Location:
United States of America
Summary
A coordinated DDoS extortion campaign targeted multiple privacy-focused email providers, including RiseUp, causing prolonged outages through attacks peaking at up to 256Gbps. The threat actor, identifying as the Cursed Patriarch, demanded 0.06 BTC ransoms and threatened escalated network disruptions if unpaid within three days, though impacted firms publicly refused compliance. This campaign specifically affected smaller security-centric email services, with attackers later referencing media coverage of their operations, distinguishing it from unrelated DDoS incidents against VoIP and gaming infrastructure. The events reflect ongoing DDoS-based extortion trends, following recent botnet-driven attacks against global ISPs and financial entities.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
The incident began on October 21, 2021, when a coordinated series of distributed denial of service (DDoS) attacks targeted at least eight email service providers specializing in privacy and security-focused offerings. The affected companies included Runbox, Posteo, Fastmail, TheXYZ, Guerilla Mail, Mailfence, Kolab Now, and RiseUp. Attacks persisted throughout the weekend and into Monday, October 25, causing prolonged service outages. The threat actor launched volumetric DDoS attacks against these providers, with some attacks reaching peak intensities of 50Gbps and 256Gbps according to subsequent statements from Runbox and TheXYZ. Following the initial disruption, the attacker sent ransom emails demanding payment of 0.06 Bitcoin (approximately $4,000 at the time), giving each company a three-day deadline before threatening escalated network disruption.

The extortion emails were attributed to a group identifying itself as the "Cursed Patriarch," which later incorporated links to media coverage about their campaign in subsequent communications. Multiple providers confirmed receiving identical threats, with Posteo publicly disclosing their refusal to pay in a blog post on October 22. Runbox and TheXYZ also acknowledged ransom demands after initial attacks. While the DDoS campaign caused operational disruptions across the targeted email services, no evidence indicated compliance with payment demands. The incident was distinct from contemporaneous DDoS attacks against UK VoIP provider Voipfone and gaming infrastructure company Sparked, which involved separate threat actors according to investigative sources. This campaign exemplified ongoing DDoS extortion activities separate from ransomware operations, occurring amid broader attacks against ISPs and financial institutions in multiple countries using emerging botnets like Meris during the same timeframe.
