Business Wire

MA-NETSCOUT-SYSTEMS

Share
Cybercriminal Attacks Accelerate Global Cybersecurity Crisis According to 1H2021 NETSCOUT Threat Intelligence Report

NETSCOUT SYSTEMS, INC., (NASDAQ: NTCT) today announced findings from its bi-annual Threat Intelligence Report that underscore the dramatic impact cyberattacks continue to have on private and public organizations and governments worldwide. In the first half of 2021, cybercriminals launched approximately 5.4 million Distributed Denial of Services (DDoS) attacks, increasing 11% over 1H2020 figures. Additionally, data projections from NETSCOUT's Active Level Threat Analysis System (ATLAS™) Security Engineering and Response Team (ASERT) point to 2021 as another record-setting year on track to surpass 11 million global DDoS attacks. ASERT expects this long tail of attacker innovation to last, fueling a growing cybersecurity crisis that will continue to impact public and private organizations.

In the wake of Colonial Pipeline, JBS, Harris Federation, Australian broadcaster Channel Nine, CNA Financial, and several other high-profile attacks, the impact of DDoS and other cybersecurity attacks has been felt worldwide. As a result, leading governments are introducing new programs and policies to defend against attacks, and policing organizations are initiating unprecedented collaborative efforts to address the crisis.

During 1H2021, cybercriminals weaponized and exploited seven newer reflection/amplification DDoS attack vectors putting organizations at greater risk. This attack vector explosion spurred an increase in multivector DDoS attacks with a record-setting 31 attack vectors deployed in a single attack against one organization.

Other key findings from the NETSCOUT 1H2021 Threat Intelligence Report include:

  • New adaptive DDoS attack techniques evade traditional defenses. By customizing their strategies, cybercriminals evolved their attack efforts to bypass cloud-based and on-premise static DDoS defenses to target commercial banks and credit card processors.
  • Connectivity supply chain increasingly under attack. Bad actors looking to cause the most collateral damage focused their efforts on vital internet components, including DNS servers, virtual private network (VPN) concentrators, services, and internet exchanges, disrupting essential gateways.
  • Cybercriminals add DDoS to their toolkit to launch triple extortion campaigns. Ransomware has become big business, with extortionists adding DDoS to their attack regimen to ratchet up the pressure on victims and add stress to security teams. Triple extortion combines file encryption, data theft, and DDoS attacks, increasing the possibility that cyber criminals receive payment.
  • The fastest DDoS attack recorded a 16.17% year-over-year increase. A Brazilian wireline broadband internet user launched the attack, which was likely related to online gaming. Using DNS reflection/amplification, TCP ACK flood, TCP RST flood, and TCP SYN/ACK reflection/amplification vectors, the sophisticated attack recorded 675 Mpps.
  • The largest DDoS attack, 1.5 Tbps, represented a year-over-year increase of 169%. ASERT data identified this attack against a German ISP, deploying a DNS reflection/amplification vector. This attack represents a dramatic increase in size over any attacks recorded in 1H2020.
  • Botnets contribute to major DDoS activity - Tracked botnet clusters and high-density attack-source zones worldwide showcased how malicious adversaries abused these botnets to participate in more than 2.8 million DDoS attacks. In addition, well-known IoT botnets Gafgyt and Mirai continue to pose a severe threat contributing to more than half of the total number of DDoS attacks.

"Cybercriminals are making front-page news launching an unprecedented number of DDoS attacks to take advantage of the pandemic's remote work shift by undermining vital components of the connectivity supply chain," stated Richard Hummel, threat intelligence lead, NETSCOUT. "Ransomware gangs added triple-extortion DDoS tactics to their repertoire. Simultaneously, the Fancy Lazarus DDoS extortion campaign kicked into high gear threatening organizations in multiple industries with a focus on ISPs and specifically their authoritative DNS servers."

NETSCOUT's Threat Intelligence Report covers the latest trends and activities in the DDoS threat landscape. It covers data secured from NETSCOUT's Active Level Threat Analysis System (ATLAS™) coupled with NETSCOUT's ATLAS Security Engineering & Response Team (ASERT) insights.

The visibility and analysis represented in the Threat Intelligence Report and Omnis® Threat Horizon fuel the ATLAS Intelligence Feed used across NETSCOUT's Omnis security product portfolio to detect and block threat activity for enterprises and service providers worldwide.

For more information on NETSCOUT's semi-annual Threat Intelligence Report, please visit our interactive website . You can also find us on Facebook , LinkedIn, and Twitter for threat updates and the latest trends and insights.

About NETSCOUT

NETSCOUT SYSTEMS, INC. (NASDAQ: NTCT) helps assure digital business services against security, availability, and performance disruptions. Our market and technology leadership stems from combining our patented smart data technology with smart analytics. We provide real-time, pervasive visibility and insights customers need to accelerate and secure their digital transformation. Our Omnis® cybersecurity advanced threat detection and response platform offers comprehensive network visibility, threat detection, highly contextual investigation, and automated mitigation at the network edge. NETSCOUT nGenius™ service assurance solutions provide real-time, contextual analysis of service, network, and application performance. And Arbor Smart DDoS Protection by NETSCOUT products help protect against attacks that threaten availability and advanced threats that infiltrate networks to steal critical business assets. To learn more about improving service, network, and application performance in physical or virtual data centers or in the cloud, and how NETSCOUT's security and performance solutions can help you move forward with confidence, visit www.netscout.com or follow @NETSCOUT on Twitter, Facebook, or LinkedIn.

©2021 NETSCOUT SYSTEMS, INC. All rights reserved. NETSCOUT, the NETSCOUT logo, Guardians of the Connected World, Adaptive Service Intelligence, Arbor, ATLAS, Cyber Threat Horizon, InfiniStream, nGenius, nGeniusONE, and Omnis are registered trademarks or trademarks of NETSCOUT SYSTEMS, INC., and/or its subsidiaries and/or affiliates in the USA and/or other countries. Third-party trademarks mentioned are the property of their respective owners.

Link:

ClickThru

Social Media:

https://www.facebook.com/NETSCOUTinc

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

SecurityBridge Announces CEO Transition to Accelerate Global Expansion12.1.2026 15:15:00 CET | Press release

SecurityBridge, a leading provider of cybersecurity solutions for SAP, today announced the appointment of Jesper Zerlang as Chief Executive Officer, effective January 1, 2026. Zerlang transitions from his role as Chairman of the Board, a position he has held for the past 12 months, as the company enters its next phase of international expansion, backed by funds advised by BUBregal Unternehmerkapital (BU). This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260112824449/en/ Jesper Zerlang appointed Chief Executive Officer, SecurityBridge SecurityBridge protects SAP environments for large enterprises by reducing cyber risk across mission-critical SAP landscapes. The company is trusted by global customers to safeguard systems that power core operations, financial processes, supply chains, and digital transformation programs. “SecurityBridge is uniquely positioned at the intersection of cybersecurity and SAP – a domain I know deeply

New Clinical Study Publication Validates Respiratory Outcomes for the Onera Home-polysomnography System12.1.2026 14:30:00 CET | Press release

The results of this study provide further clinical evidence that patient-applied, patch-based PSG is a viable alternative to in-lab PSG, enabling broader access to gold-standard sleep testing. Onera Health, a leader in transforming sleep medicine, announces the recent publication of a multicenter validation study of its Onera Sleep Test System (STS) in the ERJ Open Research, a leading, fully open-access scientific journal published by the European Respiratory Society (ERS). This is the second publication from this study, and it demonstrates that the patch-based Onera STS home-polysomnography (hPSG) device accurately identifies respiratory events and distinguishes AHI severity when validated against simultaneous in-lab polysomnography and is a viable option for unattended home use. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260112821647/en/ Patient sleeps with the patient-applied Onera home Polysomnography (Onera hPSG) so

Riskified Analysis Reveals 1 in 4 Refund Dollars Is Abusive; Introduces "Dynamic Returns," a New Policy Protect Feature, to Safeguard Revenue While Increasing Customer Satisfaction12.1.2026 14:00:00 CET | Press release

Riskified (NYSE: RSKD) a leader in ecommerce fraud and risk intelligence, today released a research analysis highlighting a growing customer experience dilemma: As merchants tighten controls to fight a surge in return and refund abuse, they are inadvertently creating a more restrictive and frustrating experience for their best customers. To help retailers mitigate this challenge, Riskified has introduced a new feature in its Policy Protect solution, Dynamic Returns, AI-powered return decisions that adapt in real-time based on customer eligibility. Riskified's 2024 analysis of over a million refund claims found that 1-2% of total order value measured in sales dollars was requested back as refunds, with nearly 1 in 4 dollars claimed being abusive. In response to rising abuse, many retailers are implementing restrictive tactics like flat return fees, shorter return windows, and delaying refunds, often taking 10+ days for warehouse inspection. These measures frustrate good customers, as 68

Esri’s Custom Chart Builder Adopted by the Shom (French Hydrographic and Oceanographic Office) for Nautical Chart Production12.1.2026 14:00:00 CET | Press release

Geospatial Solution for Safety-Critical Maritime Use Sets Global Benchmark for Chart Automation Esri, the global leader in location intelligence, announced today that the Shom (French Hydrographic and Oceanographic Office) has officially adopted Custom Chart Builder (CCB) for automated production of all paper nautical charts. Following extensive testing and configuration, Shom confirmed that CCB-generated charts meet the stringent safety standards required by the French Navy, marking a pivotal advancement in automating maritime cartography and reinforcing its role as a pioneer in maritime digital transformation. “This adoption demonstrates that high-quality, regulation-compliant paper charts can now be produced without manual intervention, dramatically reducing production time and cost,” said Rafael Ponce, Esri principal maritime consultant. “Shom’s endorsement validates Esri’s CCB as a trusted solution for hydrographic offices worldwide, supporting the transition to digital-first work

Cellares Expands Global Smart Factory Network With European Headquarters in the Netherlands12.1.2026 13:30:00 CET | Press release

Cellares’ new IDMO Smart Factory in Leiden, Netherlands, expands commercial-scale manufacturing capacity for European cell therapy patient populations through a standardized, automated, and highly scalable facility model Cellares, the first Integrated Development and Manufacturing Organization (IDMO), today announced it has secured a site and signed a long-term lease for a new IDMO Smart Factory at Leiden Bio Science Park (LBSP) with Dura Vermeer Commercieel Vastgoed. The facility will serve as Cellares’ European headquarters and expand the company’s global manufacturing network with dedicated regional capacity. Cell therapy manufacturing is patient-specific and time-sensitive, making regional production capacity increasingly important as programs advance from clinical development toward commercial supply. The new Netherlands hub is designed to provide European drug developers with access to automated manufacturing infrastructure, while maintaining alignment to a common production stan

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye