ProtonMail recovers from DDoS punch after being extorted

The well-intended encrypted email service encountered the worst people on the Web this week

The last few days have not been easy for ProtonMail, the Geneva-based encrypted email service that launched last year.

Earlier this week, the service was extorted by one group of attackers, then taken offline in a large distributed denial-of-service (DDoS) attack by a second group that it suspects may be state sponsored.

ProtonMail offers a full, end-to-end encrypted email service. It raised more than US$500,000 last year after a blockbuster crowdfunding campaign that sought just $100,000. 

Now, it bills itself as the largest secure email provider, with more than 500,000 users. Creating an account is free, although ProtonMail plans to eventually introduce a paid-for service with additional features.

Interest in encrypted email has risen sharply since 2013, when former U.S. National Security Agency contractor Edward Snowden leaked documents that showed vast data-collection operations by western spy agencies.

It's unclear why ProtonMail, whose motivations many would consider to be right and just, would be attacked. But its experience, if anything, shows that no service, no matter how noble, is off limits these days.

ProtonMail described the strange chain of events in a blog post on Thursday.

Late Tuesday, the company received an email asking for a ransom by group that was planning a distributed denial-of-service attack (DDoS).

The next day, ProtonMail fell under a brief, 15-minute attack. Then later that afternoon, a massive attack was launched against its ISP, other upstream providers and data centers.

The second, 100Gps-attack brought down the ISP, its routers and data center, causing problems for other companies.

"At this point, we were placed under a lot of pressure by third parties to just pay the ransom," it wrote. "We hoped that by paying, we could spare the other companies impacted by the attack against us, but the attacks continued nevertheless."

So ProtonMail paid the ransom, in bitcoin. Then things took an odd turn.

The group that was paid a ransom noticed the second, larger attack and felt bad.

That attack became "so serious that the criminals who extorted us previously even found it necessary to write us to deny responsibility for the second attack." 

Working with Swiss government agencies and other companies, ProtonMail concluded the first DDoS was just an assault on their IP address range. The second, however, was "technically much more sophisticated" and likely came from a different group.

The second group exhibited "capabilities more commonly possessed by state-sponsored actors. It also shows that the second attackers were not afraid of causing massive collateral damage in order to get at us."

ProtonMail has launched a donations campaign to raise money to put in place a better defense against DDoS attacks. Such systems can cost up to $100,000 a year, it said.

"Over the next several weeks, we will begin putting in place the sophisticated protections that are necessary to withstand large-scale attacks like this to ensure that online privacy can't be taken down."

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Father’s Day Gift Guide

Brand Post

PC World Evaluation Team Review - MSI GT75 TITAN

"I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it."

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?