CSIDB logo
Incident

City of Boston

Incident posture

Attack window
Dec 2015
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-02-07 03:14

Linked entities

Victim
City of Boston
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeting the City of Boston caused a temporary, widespread internet outage affecting all municipal agencies, including police and fire departments, though emergency response systems remained operational. The incident involved a distributed denial of service attack that overwhelmed servers by flooding them with traffic from compromised global computers. Officials characterized the disruption as minor cybervandalism, resolving it within approximately 20 minutes by blocking malicious traffic sources. While motives remained unclear, experts suggested potential reconnaissance for future attacks or symbolic vandalism rather than data theft, noting the difficulty of attribution due to attackers’ use of infected third-party devices. The response was praised for its speed in mitigating the incident.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On December 16, 2015, the City of Boston experienced a distributed denial of service (DDoS) cyberattack that disrupted internet services across all municipal agencies for a brief period. The attack involved hackers manipulating computers globally to flood City Hall’s servers with excessive traffic, overwhelming their web connection capacity. Mayor Martin J. Walsh characterized the outage as “short, but widespread,” confirming that police and fire department internet services were also affected, though emergency response systems remained operational. City Chief Information Officer Jascha Franklin-Hodge described the incident as a “minor act of cybervandalism” and clarified it was unrelated to concurrent threats targeting Los Angeles and New York City. The disruption began during business hours, with attackers exploiting compromised systems to generate malicious traffic directed at Boston’s infrastructure.

City cybersecurity teams detected and neutralized the attack within approximately 20 minutes by identifying and blocking the flood of illegitimate requests to their servers. Franklin-Hodge emphasized the rapid containment, which restored full internet functionality without further operational interruptions. Security experts like Anthony Townsend of Iowa State University noted the response was “sharp” and effective given the timeframe. While no data exfiltration occurred, Townsend suggested potential motives included vandalism, reputation-seeking behavior, or reconnaissance to study Boston’s defensive protocols for future attacks. Anthony Roman of Roman & Associates highlighted broader vulnerabilities, stating municipalities often lag in countering evolving DDoS tactics. The incident underscored the challenges of attributing such attacks, as hackers frequently route traffic through infected third-party devices to obscure their origins. No permanent damage to systems or data breaches was reported following the restoration of services.

Sources

Sources available to members: 1 source.

CSIDB