INC0035836 - Suspected DDoS
Incident Report for amatisnetworks
Postmortem

Please see RFO : https://bit.ly/3dUyr7W

Posted Jul 08, 2021 - 15:55 BST

Resolved
This incident has been resolved.
Posted Jul 08, 2021 - 15:54 BST
Update
We have again been continuing to monitor this closely overnight and have seen no further attacks since 18:20 BST 21/06/21. Traffic patterns on the network appear normal and services should be operational. Any customers still seeing an issues please raise an incident with the Support team to investigate.
Posted Jun 23, 2021 - 08:14 BST
Update
We have been continuing to monitor this closely overnight and have seen no further attacks since 18:20 BST 21/06/21. Traffic patterns on the network appear normal this morning and services should be operational. Any customers still seeing an issues please raise an incident with the Support team to investigate.
Posted Jun 22, 2021 - 11:41 BST
Monitoring
Further mitigations were deployed and we saw traffic levels drop to normal levels at 18:20 BST. We are continuing to monitor for further waves of attack on the network.
Posted Jun 21, 2021 - 22:00 BST
Update
At approx 17:50 we started to experience another wave of attack. We are currently putting in place further mitigations against this traffic.
Posted Jun 21, 2021 - 18:14 BST
Update
We are continuing to work on this issue. Currently traffic levels are back down to normal levels and we have mitigations currently in place. Any customers still seeing DNS issues from this may want to temporarily try a public DNS server whilst this incident is ongoing.
Posted Jun 21, 2021 - 15:29 BST
Identified
We are seeing a large increase in DDoS traffic - we are working to mitigate this new wave
Posted Jun 21, 2021 - 12:00 BST
Update
We are seeing our mitigation working - and traffic levels have reduced significantly. We are continuing to monitor closely and work with our upstream transit providers to filter the traffic.
Posted Jun 21, 2021 - 09:44 BST
Update
We are seeing another DDOS wave and are blackholing traffic to affected IPs. We will provide another update shortly.
Posted Jun 21, 2021 - 08:41 BST
Update
We are continuing to monitor for any further issues.
Posted Jun 20, 2021 - 20:41 BST
Monitoring
We are seeing normal traffic levels continue and services remain stable since our upstream carriers applied the requested filters and blackhole routing.

We are keeping this under monitor
Posted Jun 20, 2021 - 20:39 BST
Identified
We have been liaising with our upstream carriers and they have applied some filters and blackhole routing to mitigate the attack. We are gradually seeing traffic levels drop and some services restore.
Posted Jun 20, 2021 - 18:45 BST
Investigating
We are currently experiencing major packet loss and interruptions due to a suspected DDoS attack on the amatis Network.
Posted Jun 20, 2021 - 17:57 BST
This incident affected: Connectivity (Ethernet Services (Fibre, EFM, GEA), LTE (4G) Services, xDSL Services (ADSL/FTTC), Colocation (Network Connectivity)), Cloud Services (Virtual Datacentre (VDC), Virtual Private Servers (VPS)), Core (Core Network Devices and Routing, Internet Transit, Public Internet Peering, Private Internet Peering), Customer Portals, Tools and Contact (Customer Graphing Tools, amatis Website), and Platform Services (DNS Services).