Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The names in DDoS ransom emails did not prove who sent them. In a campaign reported in 2020, extortionists posed as Fancy Bear, Armada Collective, and Lazarus Group; CERT-EU assessed that Fancy Bear was highly unlikely to be behind the attacks. Treat such messages as serious threats to investigate, not reliable attribution.

Were the DDoS ransom emails really from Fancy Bear?

Not on the evidence cited in reporting about the 2020 campaign. Radware tracked extortion emails from actors claiming to be Fancy Bear, Armada Collective, and Lazarus Group. CERT-EU described the senders as cybercriminals using those names and assessed it was “highly unlikely” that Fancy Bear, also known as APT28, was responsible. It said the name was likely being abused to frighten recipients. CERT-EU’s Threat Landscape Report provides that assessment.

A sender’s claimed identity, a researcher’s label for an observed actor, and an independently supported attribution are different things. NETSCOUT ASERT named the actor it tracked “Lazarus Bear Armada” (LBA) because it impersonated recognizable groups. That label does not establish that Lazarus Group, Fancy Bear, and Armada Collective were one organization—or that any of those groups sent the demands. Cloudflare also describes the use of famous group names as a tactic to make DDoS extortion more intimidating. Cloudflare’s DDoS extortion guidance

How the reported campaign worked

Radware’s September 2020 account said the emails often named the recipient’s autonomous system number or IP addresses of services the sender claimed to have targeted. The messages threatened to disrupt online services unless the recipient paid Bitcoin by a deadline. Some were preceded by a demonstration DDoS attack. The reported targets included organizations in finance, travel, and e-commerce across APAC, EMEA, and North America. These are observations about that historical campaign, not evidence that it remains active.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Radware reported initial demands commonly set at 10 BTC, with some at 20 BTC, and described target-specific wallet addresses and threats to raise the demand after a missed deadline. Those figures describe demands reported in 2020; they are not current prices or a reliable guide to what a present-day email might request. Radware’s September 2020 campaign report

In its analysis of the LBA campaign, NETSCOUT reported observed attack volumes of 50–300 Gbps. The extortionists claimed capacity of up to 2 Tbps, but NETSCOUT said it observed no attack approaching that size. A threat actor’s advertised capability should not be confused with measured attack traffic.

What happened when targets did not pay?

Follow-through varied. NETSCOUT and Cloudflare reported cases where threatened follow-up attacks did not happen, as well as cases where targets were attacked and sometimes received renewed demands or later attacks. An unfulfilled threat is not evidence that every demand is harmless, and the reporting does not establish a success rate or how many victims paid.

NETSCOUT reported that adequately prepared targets in the campaign it analyzed experienced little or no significant negative impact. That is an observation from that campaign, not a guarantee that any particular defense will prevent disruption.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How a business should respond to a DDoS extortion email

  1. Preserve and report the message. Keep the original email and its headers, the ransom instructions, any Bitcoin address, deadlines, and related network alerts. Cloudflare advises against paying and recommends reporting the extortion to appropriate authorities.
  2. Check for evidence of an attack. Compare the named IP addresses and services with firewall, hosting, CDN, DNS, and network telemetry. Ask your internet service provider or DDoS mitigation provider to confirm whether traffic spikes or service degradation occurred. A message may include specific network details without proving that its sender is the group it claims to represent.
  3. Coordinate an operational response. Notify security, network, legal, and communications owners; contact upstream providers and mitigation partners; and prioritize services whose disruption would affect customers or business operations.
  4. Review protection across every exposed service. NETSCOUT recommends protecting all business-critical public-facing infrastructure and services, not just the main website, applying suitable network access policies, and periodically testing a realistic DDoS mitigation plan. When reviewing coverage, check both volumetric and application-layer protection, provider coordination, and who is responsible for response actions.

Cloudflare’s guidance recommends deploying DDoS protection as well as reporting extortion rather than paying. These steps reduce exposure and improve readiness; they cannot guarantee uninterrupted service.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about activity today?

The reporting discussed here chiefly documents activity from 2020–2021. It does not establish whether the same email pattern or use of the Armada Collective and Fancy Bear names is active in 2026. A new demand should be assessed using current telemetry and threat information, not treated as proof that the historical campaign has returned.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.