Menu
Browse

Cyber Incident Victim: Federal Communications Commission

Date:

May 2017

Location:

United States of America

Summary

The Federal Communications Commission experienced multiple distributed denial-of-service attacks targeting its Electronic Comment Filing System, disrupting public access to submit feedback. The agency attributed the incident to external actors flooding its commercial cloud servers with high traffic volumes, which overwhelmed resources and impeded legitimate users from filing comments while keeping the system technically operational. Officials emphasized the attacks were deliberate attempts to obstruct public participation rather than genuine comment submissions, collaborating with cloud providers to mitigate the impact. Service degradation persisted as the bombardment tied up server capacity, though the comment platform remained online throughout the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On May 7, 2017, beginning at midnight, the Federal Communications Commission (FCC) experienced sustained disruptions to its Electronic Comment Filing System (ECFS), a platform enabling public submissions on regulatory matters. FCC Chief Information Officer Dr. David Bray attributed the outages to multiple distributed denial-of-service (DDoS) attacks targeting the system’s commercial cloud infrastructure. These attacks involved external actors bombarding the FCC’s servers with high volumes of traffic, deliberately overwhelming capacity. The assault did not involve attempts to submit fraudulent comments but instead aimed to obstruct legitimate users from accessing or filing comments through the ECFS. Despite the disruption, the system remained technically operational throughout the incident, though server resources were exhausted, preventing responsive interactions with genuine users. The FCC’s initial analysis confirmed the malicious traffic patterns as coordinated DDoS events rather than organic surges in public engagement.

Cyber Incident Image

The incident coincided with heightened public attention on net neutrality rulemaking following a televised segment by comedian John Oliver urging viewers to submit comments to the FCC, though the agency explicitly denied any connection between the broadcast and the disruptions. Operational impacts included extended delays and accessibility barriers for individuals attempting to participate in the regulatory comment process during the attack window. In response, the FCC collaborated with its commercial cloud hosting providers to analyze traffic patterns, mitigate the attacks, and restore normal system functionality. No data breaches or unauthorized access to filed comments were reported. The FCC characterized the events as deliberate attempts to undermine public participation but did not disclose technical specifics of the attacks, attribution details, or the total duration of service degradation beyond the initial Sunday-night onset.

Sources
Sources available to members
1 source