Companies running critical Internet infrastructure are observing recent probe-like DDoS attacks at a scale that points to state actors, likely China or Russia
Over the past year or two, someone has been probing the defenses of the companies that run critical pieces of the Internet.
Context & Ripple Effects
In 2016, Lawfare flagged something operators had been quietly reporting: probe-like DDoS attacks against the companies running core Internet plumbing, at a scale and pattern pointing to state actors rather than criminal botnets. At the time it read as reconnaissance — someone mapping where the defenses are thin.
The years since have validated that read and escalated it. Microsoft's 2023 disclosure of Chinese state-sponsored hackers inside critical infrastructure organizations across US industries, followed by the 2024 Salt Typhoon intrusions into US ISPs, turned what looked like probing into persistent presence. The 2016 story matters as the earliest data point in that arc.
First-order effects
- Operators of critical Internet infrastructure must reclassify large-scale DDoS from a service-availability nuisance to intelligence collection — each attack reveals which defenses hold and which routes are soft.
Second-order effects
- Attribution pressure lands on China and Russia, pushing infrastructure providers toward deeper threat-intelligence sharing with government agencies and raising the cost of doing business with equipment vendors from those countries.
Third-order effects
- If probing precedes intrusion — as the later ISP breaches suggest — the industry's structural shift is from defending uptime to assuming adversary presence inside the network, making critical Internet infrastructure a permanently contested strategic terrain.
The trend: State cyber operations against critical Internet infrastructure are escalating from external probing of defenses to sustained internal access, with the 2016 DDoS observations marking the reconnaissance phase.