An ongoing DDoS attack has crippled the Belgian government's IT network, affecting 200+ government orgs, a COVID-19 reservation app, tax filing services, more
Catalin Cimpanu / The Record :
Context & Ripple Effects
Belgium's centralised government IT backbone is under a sustained DDoS attack, and because more than 200 organisations ride on that shared network, the blast radius covers citizen-facing services at once: the COVID-19 vaccination reservation app and tax filing are down alongside internal systems. The incident lands in a well-documented pattern of state-facing denial-of-service campaigns — Ukrainian government sites were knocked offline in February 2022 in coordinated DDoS attacks paired with wiper malware, and the US later attributed its own record-setting attack on the Health and Human Services Department to a state-level actor.
What distinguishes Belgium's case is scale through consolidation rather than targeting of one agency: a single chokepoint means one attacker can degrade an entire national bureaucracy without breaching it.
First-order effects
- Over 200 Belgian government organisations lose connectivity simultaneously, taking the COVID-19 reservation app and tax filing services offline for citizens who have no alternative channel during those outages.
- Belgian authorities must divert response resources to mitigation while every dependent agency waits on the same fix — recovery is bottlenecked by whoever operates the shared network.
Second-order effects
- Agencies that assumed their services were independently available now face pressure to decouple from the central backbone or procure separate mitigation capacity, reshaping how government IT is procured and hosted.
- The outage hands other governments a reference case: Albania later shut down online public services entirely after a cyberattack hit its new portal, showing the fallback posture officials reach for when continuity planning fails.
Third-order effects
- If the pattern holds — from the US HHS attack through Ukraine to Belgium — DDoS becomes a standard instrument against state digital infrastructure, forcing governments to treat availability as a security requirement equal to confidentiality and to redesign around redundancy rather than a single network perimeter.
- Consolidated e-government platforms amplify this risk structurally: each service digitised onto shared infrastructure raises the cost of a single failure point until resilience investment becomes a political issue, not just a technical one.
The trend: Government digital services worldwide are converging on shared infrastructure that turns denial-of-service attacks into whole-of-state outages, making uptime itself a national security problem.