Massachusetts man sentenced to over 10 years in prison and ordered to pay ~$443K in restitution for a DDoS attack on Boston Children's Hospital in 2014
Context & Ripple Effects
This sentencing closes out one of the most consequential DDoS prosecutions of the decade: a 2014 attack that knocked Boston Children's Hospital offline, now answered with more than ten years in prison and roughly $443K in restitution. It lands in a run of DDoS cases where punishment has scaled sharply with the target — a hacker drew a 27-month sentence for attacks on gaming services, and a British man got just over two years for a hired attack that took down Liberia's internet connectivity.
Against those benchmarks, a decade-long term for hitting a children's hospital marks a clear line: courts are treating availability attacks on critical care infrastructure as a different category of crime than attacks on commercial or entertainment targets.
First-order effects
- The defendant begins a 10-plus-year sentence and owes ~$443K in restitution to Boston Children's Hospital, making victim-computed downtime costs a direct financial liability for the attacker.
- Hospitals and other critical-care operators gain a concrete precedent showing that a successful prosecution years after the attack can still yield both prison time and recoverable damages.
Second-order effects
- Prospective attackers weighing DDoS-for-hire work now face a visibly wider penalty spread — months for gaming targets versus a decade for healthcare — which raises the risk calculus for anyone renting botnet capacity without vetting the target.
- Prosecutors have a template for charging availability attacks on critical infrastructure at felony scale, which pressures DDoS marketplaces and booter operators whose customers may hit regulated sectors.
Third-order effects
- If the pattern holds, DDoS sentencing bifurcates by target class: critical-infrastructure attacks draw multi-year terms with restitution while commercial-target cases stay comparatively light, pushing professional attackers toward softer targets and leaving healthcare as the sector where deterrence is priced highest.
- Restitution awards tied to measured downtime could become a standard component of cybercrime judgments, giving victims like hospitals a financial claim that survives even when the attacker's assets are thin.
The trend: US courts are escalating DDoS penalties based on target criticality, with attacks on healthcare and public infrastructure drawing prison terms an order of magnitude beyond those for commercial or gaming targets.