/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Largest online DDoS service vDOS hacked, with details of customers and targets revealed; service earned $600K+ for 150K+ DDoS attacks over past two years

vDOS — a “booter” service that has earned in excess of $600,000 over the past two years helping customers coordinate more than 150,000 …

Krebs on Security Brian Krebs

Context & Ripple Effects

vDOS sits at the commercial end of a booter market that had already been normalized by Lizard Squad selling attacks from $6 to $500 in 2014 — subscription-priced DDoS with customer support. What changed with this breach is that the service's own ledgers are now public: over $600K in earnings, 150K+ attacks, and named customers and targets.

The leak matters because it converts an anonymous marketplace into evidence. It also lands on Brian Krebs' desk at a moment when his own site would soon absorb a record 620Gbps sustained attack, underscoring how personal the booter economy's antagonisms run.

First-order effects

  • vDOS customers who paid for attack subscriptions are now identifiable from leaked records, facing exposure to victims, researchers, and eventually law enforcement.
  • Organizations listed as targets gain concrete attribution data for attacks they previously experienced as anonymous traffic floods.

Second-order effects

Third-order effects

  • If leaks keep converting booter customer lists into prosecutions, DDoS-for-hire retreats from open web storefronts into invite-only underground channels, raising acquisition costs for buyers.
  • As cheap rented firepower persists regardless, the defensive side industrializes — the arms race visible in Cloudflare absorbing hyper-volumetric attacks past 71M rps becomes the durable market response.

The trend: DDoS-for-hire is being squeezed out of the open market by a leak-and-prosecute cycle, pushing attack capacity underground while mitigation vendors scale to meet ever-larger residual floods.