← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Nine.ch Details 500-600 Gbit/s DDoS Attack Affecting Customer and Internal Services

🔄 Updated 4d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • DDoS attack peaked at 500-600 Gbit/s across Nine.ch's network.
  • Attack initially targeted a customer, then broadened to Nine.ch's services.
  • Affected services included Deploio, website, Cockpit, and ticketing system.
  • Nokia Deepfield data confirmed CECbot and Katana botnet families were involved.

Large-Scale DDoS Incident

On August 11, 2026, Nine.ch's network was hit by a significant DDoS attack. The attack reached an estimated peak volume of 500 to 600 Gbit/s across all its links, with two upstream providers confirming 260 Gbit/s directly. This volume exceeded the capacity of Nine.ch's uplinks, regardless of internal defenses.

Attack Progression and Impact

The attack lasted approximately 42 hours, from Tuesday evening to Thursday afternoon, manifesting as a series of waves with shifting targets and intensity rather than a continuous outage. It first targeted a customer of Nine.ch, and roughly three hours later, broadened to include Nine.ch's own services. Affected applications included Deploio, the company's website, Cockpit, and its ticketing system. Customer data safety was not compromised, as it was an overload attack, not an intrusion.

Botnet Attribution and Confirmation

Independent telemetry from Nokia's Deepfield threat research team corroborated Nine.ch's observations. Deepfield's sensors, registered on the botnet command-and-control servers, logged the attack commands. This data confirmed the involvement of two botnet families, CECbot and Katana, and verified the attack sequence: initial targeting of the customer followed by an expansion to Nine.ch's infrastructure, consistent with Nine.ch providing the customer's internet connection.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Nine.ch experienced a large-scale distributed denial-of-service (DDoS) attack in August 2026, peaking at an estimated 500-600 Gbit/s, initially targeting a customer and subsequently impacting Nine's own services. This incident highlights the challenges internet service providers face when their infrastructure is used to connect targeted customers, leading to service disruptions for multiple internal applications.