On August 11, 2026, Nine.ch's network was hit by a significant DDoS attack. The attack reached an estimated peak volume of 500 to 600 Gbit/s across all its links, with two upstream providers confirming 260 Gbit/s directly. This volume exceeded the capacity of Nine.ch's uplinks, regardless of internal defenses.
The attack lasted approximately 42 hours, from Tuesday evening to Thursday afternoon, manifesting as a series of waves with shifting targets and intensity rather than a continuous outage. It first targeted a customer of Nine.ch, and roughly three hours later, broadened to include Nine.ch's own services. Affected applications included Deploio, the company's website, Cockpit, and its ticketing system. Customer data safety was not compromised, as it was an overload attack, not an intrusion.
Independent telemetry from Nokia's Deepfield threat research team corroborated Nine.ch's observations. Deepfield's sensors, registered on the botnet command-and-control servers, logged the attack commands. This data confirmed the involvement of two botnet families, CECbot and Katana, and verified the attack sequence: initial targeting of the customer followed by an expansion to Nine.ch's infrastructure, consistent with Nine.ch providing the customer's internet connection.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Nine.ch experienced a large-scale distributed denial-of-service (DDoS) attack in August 2026, peaking at an estimated 500-600 Gbit/s, initially targeting a customer and subsequently impacting Nine's own services. This incident highlights the challenges internet service providers face when their infrastructure is used to connect targeted customers, leading to service disruptions for multiple internal applications.