ProtonMail pays hackers ransom of $6K in Bitcoin to end DDoS attack
Thomas Fox-Brewster / Forbes :
Context & Ripple Effects
ProtonMail's decision to hand over $6,000 in Bitcoin reads as a small transaction, but it was one of the early public instances of a company paying cryptocurrency extortion directly to end an attack — and it did not work. The second week-long DDoS wave hit days later, forcing the encrypted-mail provider back into mitigation rather than closing the incident out.
That failure-to-stop dynamic is what makes this a useful baseline against the corpus' later cases: by the time of the CWT thread documenting a $4.5M BTC payment negotiated over email, and Colonial's reportedly rapid ~$5M cryptocurrency ransom in 2021, paying had scaled three orders of magnitude and become a standard, if contested, response.
First-order effects
- ProtonMail stops the initial DDoS but immediately signals to its attackers that payment is on the table — and the follow-up week-long attack shows the $6K bought no durable protection for users of the encrypted email service.
Second-order effects
- Each publicized successful payment raises the expected payoff for attackers targeting other availability-critical services, pushing victims toward larger demands and better-resourced mitigation contracts rather than settlement.
Third-order effects
- If the pattern holds from $6K in 2015 to multi-million-dollar ransoms at CWT, Colonial Pipeline, and Brenntag, cryptocurrency extortion becomes a structural cost of operating internet infrastructure — with each payment funding attacker capacity and fueling pressure on regulators to scrutinize both the payments and the rails they run on.
The trend: Crypto-denominated extortion has grown from small DDoS shakedowns like ProtonMail's into a normalized, multi-million-dollar line item for major companies.