Cyber Incident Victim: Mad Mimi
Timeline
Summary
Mad Mimi, an email marketing service, experienced a DDoS attack accompanied by a Bitcoin ransom demand. The company refused to pay, mitigated the attack, and reported intermittent service disruptions due to security upgrades and network provider issues while emphasizing data safety. They contacted law enforcement and aligned their response with other targeted firms like Meetup and Basecamp, collectively rejecting extortion to deter future criminal attempts.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On March 30, 2014, email marketing service Mad Mimi experienced a distributed denial-of-service (DDoS) attack that disrupted its network connectivity. Shortly after the attack began, the company received an extortion email from an individual identifying as Mark Nsd, demanding 1.8 Bitcoin (approximately $830 at the time) to cease the assault. The attacker's message explicitly stated, "I don’t have to explain myself. I will stop the attack for 1.8 Bitcoin (~$830). Your network will be safe from further attacks, think twice before making your decision." Mad Mimi immediately implemented mitigation measures against the ongoing attack, prompting the perpetrator to send a follow-up email claiming, "I stopped the flood at the moment, and I’ll wait for your response for 24 hours." The company publicly explained through a blog post that the DDoS attack targeted their network infrastructure, severing connectivity between their servers and the internet while emphasizing customer data remained secure though inaccessible during outages. By March 31 at 5PM, Mad Mimi reported intermittent service disruptions resulting from both ongoing security upgrades and downtime affecting their network provider GNAX.

Mad Mimi refused the extortion demand and contacted law enforcement agencies in response to the attack. Company representatives stated their decision stemmed from a belief that acquiescence would encourage further attacks, declaring, "Blackmail and extortion don’t stop with acquiescence – it only encourages further attacks. As such, we’ve decided to not play along." They contextualized their stance alongside similar refusals by Meetup and Basecamp, both of which had faced comparable DDoS extortion attempts earlier in March 2014. Basecamp's founder David Heinemeier Hansson confirmed their March 24 attack involved extortion attempts that were rejected while working with network providers to mitigate impacts. Mad Mimi framed their resistance as part of a broader stand against cybercriminals targeting internet-dependent businesses, asserting, "We won’t take this lying down and we won’t negotiate with criminals." The article noted no confirmed instances of companies complying with such extortion demands, while acknowledging the possibility that paying entities might avoid public disclosure unlike Mad Mimi, Basecamp, and Meetup.
