A DDoS Attack Hit Our Own Network, Not Just a Customer's

Three Days in August: What a DDoS Attack Exposed in Our Network

A DDoS Attack Hit Our Own Network, Not Just a Customer's

In August 2026, Nine faced a large-scale DDoS attack that targeted both a customer and the company's own infrastructure. This postmortem details what happened over three days, how the team responded, and what the incident exposed about the network's resilience and weaknesses.

In August 2026, a large DDoS attack hit a customer and our own network directly.
  1. cube00

    > There was no unauthorised access and no compromised systems. This was an overload attack, not an intrusion.

    Hopefully your logging infra is rock solid and nothing has been dropped in the flood. It wouldn't be the first time a DOS was used to mask the actual attack by overwhelming the monitoring infra.

    > Use a CNAME or ALIAS record instead of an A record. An A record ties your domain to one specific IP address on our platform. That fixed binding was exactly the problem during the attack: wherever we could change the address on short notice, availability could be restored, wherever we could not, only the blunt measure remained.

    I don't understand how this helps. CNAMES have TTLs like A records and they eventually have to terminate at an A record somewhere so why pay for an extra hop?

  2. tshanmu

    "We found three concrete gaps during this incident, and we would rather be upfront about them than gloss over them." claudism?

  3. jareklupinski

    > There was no unauthorised access and no compromised systems. This was an overload attack, not an intrusion.

    "AI said it's all good. There are no attackers within our walls."

More from this day

2026-09-28