How ProtonMail recovered from a second week-long DDoS attack after paying $6K ransom to stop the first
Exclusive: Inside the ProtonMail Siege: How Two Small Companies Fought Off One of Europe's Largest DDoS Attacks — What started as a simple digital ransom quickly escalated into a trans-continental networking battle. Thanks: @jasonhiner
Context & Ripple Effects
Days earlier, ProtonMail had ended its first siege by paying a $6K ransom in Bitcoin — and this exclusive shows what happened next: the attack resumed anyway, escalating into one of Europe's largest DDoS assaults and dragging two small companies into a trans-continental networking battle.
The episode is an early data point in an extortion economy the corpus tracks growing ever since — from CWT's $4.5M ransom payment, to data recovery firms quietly paying ransoms while charging victims for 'hi-tech' unlocks, to negotiators like Kurtis Minder making payment talks a profession.
First-order effects
- ProtonMail's $6K payment bought no lasting protection — the second, larger attack hit immediately after, leaving the young encrypted-email provider offline or degraded for another week while it scrambled upstream network help.
- The attackers demonstrated that DDoS ransoms are repeatable revenue: a target that pays once is marked as willing, inviting a bigger demand.
Second-order effects
- The failure hands ammunition to the don't-pay camp just as the corpus shows the pay-side professionalizing — recovery firms reselling ransom payments and dedicated negotiators monetizing capitulation — sharpening the industry split over whether extortion payments fund the next attack.
- Small providers like ProtonMail learn they cannot buy their way out at any price, pushing defense spending from ransom budgets toward mitigation infrastructure and upstream relationships.
Third-order effects
- If paying invites escalation rather than relief, the rational long-run posture shifts to engineered resilience — a path Proton itself later took, fielding roughly 25 engineers to keep its services reachable even against state-level blocking by Russia.
- As ransomware gangs scale to multi-million-dollar operations, the gap between what a startup can pay and what attackers demand widens until negotiation collapses entirely — leaving mitigation capacity, not payment, as the only durable defense.
The trend: Cyber extortion has scaled from four-figure DDoS ransoms to industrial ransomware, and each failed payment pushes targets from negotiation toward building resilience they control themselves.