Tag Archives: legal action after ddos attack

Legal Action After a DDOS Attack: A UK Playbook

Legal Action After a DDOS Attack: A UK Playbook

When a flood of junk traffic takes a UK company offline for six hours on a trading day, the questions arrive in a familiar order: what is happening, when does it stop, who did this, and can we do anything about it afterwards. Legal action after a DDoS attack is usually the last of those to be asked and the first to be quietly dropped. Not because the attack was lawful. It plainly was not. The problem is that by the time anyone asks the question properly, the flow records that would have supported a claim have already rotated out of a buffer, and the only surviving artefact is a screenshot of a dashboard with no timezone on it.

This piece is written from the target’s side of the incident. It covers what UK law actually offers a victim, what to preserve in the first day, who to notify, how ransom demands change the calculation, and why the contract you signed with your mitigation provider usually determines your legal position far more than the Computer Misuse Act does.

What UK law says about a distributed denial-of-service (DDoS) attack on your business

Three provisions matter. Section 3 of the Computer Misuse Act 1990 covers unauthorised acts with intent to impair the operation of a computer, which is the standard charge for knocking a service offline; it carries up to 10 years’ imprisonment on indictment. Section 3A covers making, supplying or obtaining articles for use in such offences, and it is the provision that catches booter and stresser services and the people who buy them, with a maximum of two years. Section 3ZA, inserted by the Serious Crime Act 2015, covers unauthorised acts causing or creating a significant risk of serious damage, and carries up to 14 years, rising to life where the damage touches human welfare or national security.

So the sentencing range is real. What it is not is a remedy. A conviction, when one happens, arrives months or years later, usually against a teenager who bought 30 minutes of attack traffic for the price of a takeaway, and it returns nothing to your balance sheet. UK courts can make compensation orders, but they are limited by what the defendant can actually pay, and booter customers are rarely solvent.

Criminal offence, civil wrong, contract breach: pick your fight

These are three separate tracks and they behave differently. A criminal prosecution is brought by the state, needs a suspect, and is not yours to control. A civil claim is yours to bring, but you must identify a defendant, serve them and enforce against assets. A contract claim is against a party you already know, usually your hosting, content delivery or scrubbing provider, and it is governed entirely by the words in the agreement you signed. Most organisations that talk about “taking legal action”are describing track one and end up, if anything happens at all, on track three.

Attribution, not illegality, is the obstacle

Nobody disputes that flooding a UK business is unlawful. The difficulty is naming who did it to the civil standard. Reflection and amplification attacks arrive from thousands of innocent third-party servers whose owners have no idea they are participating. Source addresses are routinely spoofed. Attack capacity is rented from a marketplace that takes cryptocurrency and hides behind its own proxy layer. As we have noted before, websites have long struggled to find meaningful legal recourse for denial of service attacks, and the reason is almost always evidential rather than doctrinal.

The first 24 hours: the evidence that keeps your options open

Everything below needs preserving before the next log rotation, not after the post-mortem meeting.

  • NetFlow, sFlow or IPFIX records from your edge routers, exported and copied off the collector;
  • Edge and origin web server access logs, plus firewall, load balancer and WAF counters for the attack window and for a comparable quiet period;
  • Monitoring and synthetic check alerts, status page updates, and the timestamps on each;
  • A full packet capture sample if one was taken, even a few seconds of it;
  • Internal records of who was notified, at what time, on which channel, and what decisions they took.

Log everything in UTC from NTP-synchronised systems. Mismatched clocks are the first thing an opponent challenges, and a two-minute drift between your load balancer and your provider’s scrubbing centre is enough to muddy a time-to-mitigate argument permanently.

Ask for the written attack report, not a screenshot

The single most useful document you will ever hold after an incident is your provider’s post-incident attack report: named vectors, peak bit rate and peak packet rate, source distribution by geography and autonomous system, and precise start and stop timestamps. If your traffic passes through a third-party proxy or scrubbing centre, that provider holds the only complete record of the flood. Your own logs show the hole, not the thing that made it.

Yet a great many contracts never promise that report. Make it a named deliverable with a delivery deadline before you sign, not a favour you request in week three while the account manager is on leave. The same applies to raw evidence requests: ask during procurement whose scrubbing capacity you are actually buying, because plenty of UK offerings are resold capacity on another operator’s network. Where that is the case, your SLA counterparty may have to go and ask an upstream party that has no contract with you at all. That chain is worth mapping alongside the rest of your vendor claim checks.

Ransom notes are exhibits

Keep the original email with full headers. Keep the chat transcript, the wallet address, the sample attack timing and any subsequent messages. Do not forward the note around the business and delete the original, which is what happens roughly every time, because a forwarded copy strips the headers that make it worth anything.

Who to report a DDoS attack to in the UK, and in what order

Start with Action Fraud, the reporting centre for fraud and cybercrime in England, Wales and Northern Ireland; in Scotland, report to Police Scotland on 101. What you get back is a crime reference number, and its value is administrative rather than investigative: insurers ask for it, regulators expect it, and customers asking awkward questions are reassured by it. Feeding into the National Crime Agency’s picture matters too, even when nobody investigates your individual case, because the pattern data is what supports booter takedowns.

The NCSC’s denial of service guidance is the sensible reference point for building a defensible response plan, and pointing to it in a board paper is more persuasive than an internal opinion.

Then work through the duties that carry deadlines:

  • NIS Regulations 2018: operators of essential services and relevant digital service providers have incident notification duties to their competent authority, and availability incidents count;
  • FCA operational resilience expectations: financial firms are expected to report operational incidents and to be able to show whether an important business service breached its impact tolerance;
  • UK GDPR: Article 32 treats availability as part of security, so loss of access to personal data can be a personal data breach, and Article 33 gives you 72 hours from becoming aware to assess and, where there is a risk to individuals, notify the ICO. Document the assessment even when you conclude no notification is needed;
  • Contractual notice clauses: customer and partner agreements often require notification within a small number of days, and those clauses bite long before any regulator does.

Ransom DDoS attack: what to do before anyone discusses paying

The reflex payment is the worst available option. It buys no guarantee the traffic stops, it marks you as a payer, and extortion groups have a documented habit of returning to previously compliant targets with a larger number. Before any of that, there are UK legal problems sitting behind the transaction.

Payments to a sanctioned person or entity breach financial sanctions, which carry strict civil liability and can attract monetary penalties from the Office of Financial Sanctions Implementation. Any payment also needs assessing against the money laundering offences in the Proceeds of Crime Act 2002. Screening the recipient is not optional diligence; it is the thing that determines whether the payment is lawful. Note also that in July 2022 the NCSC and the Information Commissioner wrote jointly to the Law Society making clear that paying does not reduce the risk to individuals, is not required by data protection law, and will not be treated by the ICO as a mitigating factor. Separately, the Home Office consulted in early 2025 on restricting ransom payments by public sector and critical national infrastructure bodies; check the current legal position before relying on anything written here.

Practical sequence: notify your insurer and broker before acting, because most cyber policies condition cover on prior consent and on using panel responders. Then follow a decision chain you wrote in advance, naming a director who owns the call, the lawyer who signs it off and the law enforcement contact who is told. Writing that chain during an attack, at 02:00, with the phones ringing, is how organisations make decisions they later cannot defend.

Suing the attacker versus claiming against your provider

Civil claims against attackers work in a narrow band of cases: identifiable commercial booter operations with reachable assets, domains or payment processors. Ubisoft’s 2021 action against a stresser operation is the usual illustration, reported as producing an award of just over $153,000 alongside site takedowns. The useful lesson is not the sum. It is that the defendant was a business with a website and a payment flow, not an anonymous customer. Against individual botnet users overseas, the cost of identification, service and enforcement will exceed anything you recover.

Claims against your hosting, CDN or scrubbing provider look more promising and usually deliver less than expected. SLA credits are typically a percentage of one month’s fee, claimable only inside a notice window of around 30 days, and sit beneath a liability cap tied to annual charges, with consequential loss excluded outright. Downtime, lost sales and reputational harm are exactly what those exclusions remove. Credits and damages are different animals; treating a credit as compensation is a category error that has cost boards a lot of wasted legal spend.

Which leaves insurance doing most of the real work. Business interruption and cyber policies commonly apply a waiting period measured in hours, so a four-hour outage may recover nothing while an eleven-hour one recovers a great deal. Loss adjusters want a defensible figure: hourly revenue derived from comparable trading periods, staff time at loaded cost, recovery and third-party response fees, and contractual penalties triggered by the outage.

Why the contract you signed decides how strong your position is

Four clauses do most of the damage, and they are all checkable before you buy.

What “managed”actually includes. Managed should mean onboarding and rule tuning records, a named escalation path, an engineer empowered to change policy during an attack without waiting for your sign-off, and a committed written attack report. Absent those, you have bought monitoring, not management.

When the clock starts. On-demand cover almost always measures time-to-mitigate from your notification, which turns your own out-of-band notification trail into evidence: timestamped emails from a mailbox that is not on the affected domain, call logs, ticket IDs. Teams forget this while firefighting. If you are weighing always-on against on-demand cover, understand that the difference is partly evidential, and read the small print on what those SLA seconds measure.

Three surfaces, not one. Network and transport, application layer, and authoritative DNS. The third is frequently outside the DDoS contract entirely, which means an outage at that layer can fall into nobody’s SLA while still being the reason customers saw an error page. Establish who covers authoritative DNS, under what commitment, and what report you receive if it fails.

Origin IP leakage. This is the claim-killer. A stale A record on an old subdomain, a mail host sharing the origin address, a staging environment nobody decommissioned: any of these lets the flood reach your origin directly, outside the protected path. When that happens the provider will say so in writing, correctly, and the SLA never applied. Origin leakage, rather than raw attack volume, is the most common reason a proxy gets bypassed and the most common reason a claim against the vendor collapses. Audit your DNS zone for it while things are calm.

Frequently Asked Questions

Is a DDoS attack a criminal offence in the UK?

Yes. Section 3 of the Computer Misuse Act 1990 covers unauthorised acts intended to impair the operation of a computer, with a maximum of 10 years on indictment. Buying or supplying a booter or stresser service falls under section 3A, and section 3ZA covers attacks causing serious damage, carrying up to 14 years or life in the most severe cases.

Can you sue someone for a DDoS attack?

You can, provided you can identify and serve a defendant with assets worth pursuing. Civil action has succeeded against commercial booter operators, as in Ubisoft’s 2021 case reported at just over $153,000 plus takedowns. Against anonymous or overseas individuals, the cost of attribution and enforcement generally outweighs anything recoverable.

Who should you report a DDoS attack to in the UK?

Report to Action Fraud for a crime reference number, or to Police Scotland on 101 if you are in Scotland. Then work through sector duties: NIS Regulations notification if you are an operator of essential services or a relevant digital service provider, FCA reporting for financial firms, and an Article 33 assessment for the ICO where personal data availability was affected.

Does a DDoS attack have to be reported to the ICO?

Not automatically, but it can be reportable. UK GDPR Article 32 treats availability as part of security, so if people lost access to personal data and there is a risk to their rights and freedoms, Article 33 requires notification within 72 hours of becoming aware. Record the assessment and its reasoning even where you decide notification is not required.

Should you pay a ransom DDoS demand?

Paying is the weakest option and carries its own legal exposure, including financial sanctions liability and the money laundering offences in the Proceeds of Crime Act 2002. It guarantees nothing and marks you as a payer. Notify your insurer and law enforcement first, and make the decision through a chain you agreed in writing before the attack rather than during it.