CSIDB logo
Incident

SFR

Incident posture

Attack window
Aug 2020
Location
Netherlands
Status
Historical
CIA posture
Available to members
Updated
2025-10-29 00:00

Linked entities

Victim
SFR
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Multiple European ISPs in Belgium, France, and the Netherlands experienced distributed denial-of-service attacks targeting their DNS infrastructure, causing temporary service disruptions. The attacks, which included DNS amplification and LDAP vectors reaching up to 300Gbit/s, were mitigated within a day but coincided with unrelated DDoS extortion campaigns against financial institutions. Some affected providers received Bitcoin ransom demands, though no direct connection to the ISP incidents was confirmed. A separate outage at another provider occurred due to misconfigured DDoS mitigation rules during these events.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In late August 2020, multiple internet service providers across Belgium, France, and the Netherlands experienced distributed denial-of-service (DDoS) attacks targeting their DNS infrastructure. The incidents affected EDPnet in Belgium, Bouygues Télécom and K-net in France, and Caiway and Delta in the Netherlands, among other providers. Attacks typically lasted under 24 hours but caused temporary service disruptions for customers during active periods. The Dutch Association of Internet Providers (NBIP) identified the attacks as combining DNS amplification and LDAP-based vectors, with peak traffic volumes reaching 300 gigabits per second. ISPs successfully mitigated the attacks using standard defensive measures, though the disruptions highlighted vulnerabilities in critical DNS systems. The timing coincided with separate reports of DDoS extortion campaigns against financial institutions, though no direct connection was established between these events at the time of initial reporting.

On September 4, 2020, the Dutch National Cyber Security Centre (NCSC) confirmed that some DDoS incidents involved extortion demands requesting Bitcoin payments, though attribution remained unverified. Separately, a misconfigured Flowspec rule implemented during a DDoS mitigation effort caused an unrelated outage at CenturyLink, demonstrating secondary operational risks during attack responses. No specific threat actor group or motive was conclusively linked to the ISP attacks beyond the general extortion pattern observed in some cases. Service providers restored normal operations through traffic filtering and infrastructure hardening without reporting permanent damage or data breaches. The coordinated timing across multiple countries suggested a targeted campaign against telecommunications infrastructure, though technical evidence tying all incidents remained circumstantial.

Sources

Sources available to members: 1 source.

CSIDB