Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FBI’s November 2022 warning described pro-Russian hacktivist distributed denial-of-service (DDoS) attacks against critical-infrastructure companies as having limited success. With mitigation in place, these attacks generally caused minimal operational disruption—but “limited” does not mean harmless. A website outage can disrupt access and attract attention, while poorly secured operational technology (OT) can expose physical processes to a different kind of risk.

What the FBI warned about

In a Private Industry Notification issued November 4, 2022, the FBI defined hacktivism as cyber activity by criminals pursuing an ideological, social, or political cause. The agency said pro-Russian hacktivist groups had used DDoS attacks against critical-infrastructure companies after Russia’s invasion of Ukraine, with limited success. It also warned that groups shared attack tools and guidance with people willing to act in support of their cause. Read the FBI notification (PIN 20221104-001).

A DDoS attack sends a large volume of requests from multiple sources toward a public-facing server or service. If the service cannot handle the traffic, users may find a website slow or unavailable. The FBI characterized hacktivist DDoS and website-defacement attacks as generally opportunistic; with mitigation, they usually had minimal operational impact. Attackers could nevertheless publicize and exaggerate the apparent severity, making the psychological and reputational effects greater than the service disruption. SecurityWeek’s November 7, 2022 report summarized the alert and its advice to organizations.

What “limited impact” does—and does not—mean

A visible outage is not, by itself, evidence that attackers accessed internal networks, stole or changed data, or disrupted physical operations. DDoS primarily targets availability: people cannot reliably reach a service while it is overloaded. The scale of inconvenience can vary with the target and the quality of its defenses, and an outage can still interrupt communications or deny users information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

The FBI’s assessment was about the operational effects observed in the attacks it described, not a guarantee that every attack will be minor. Hacktivists may select high-profile financial, government, health, or transportation organizations for symbolic value, then amplify claims about an incident online. Organizations should distinguish a confirmed service interruption from claims about broader compromise.

Website DDoS and exposed operational technology are different risks

A public website outage and an intrusion into operational technology should not be treated as equivalent. A later joint fact sheet, published May 1, 2024, said pro-Russia hacktivist activity against OT was mostly unsophisticated and caused limited disruption overall. But it documented U.S. water-and-wastewater cases in which attackers remotely manipulated human-machine interfaces (HMIs), raised pump and blower settings, disabled alarms, changed administrative passwords, and caused minor tank overflows. Most victims quickly switched to manual controls and restored operations. Read the joint OT fact sheet.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Risk area Public-facing website DDoS Exposed OT or HMI compromise
Primary effect Disrupted availability or access to a website or online service Potential manipulation of physical processes or interference with operator access
Examples in agency guidance Service effects were generally minimal when DDoS mitigation was in place Documented pump and blower changes, disabled alarms, password changes, and minor overflows
Relevant controls DDoS protection, ISP coordination, recovery planning, and network monitoring Network isolation, protected remote access, MFA, patching, backups, and manual-operation capability
Key communication risk Exaggerated claims can make an availability incident appear broader than it is Treating weakly protected access as merely a nuisance can overlook physical consequences

The OT cases involved access paths such as internet-exposed connections, outdated VNC software, default or weak passwords, and missing multifactor authentication (MFA). Those are different weaknesses from simply overwhelming a public website, and they call for controls designed to protect systems that operate physical equipment.

Can a DDoS attack change votes or stop people from voting?

A DDoS attack against election infrastructure can make voter-information websites, voter look-up tools, or unofficial election-night reporting unavailable. That can frustrate people seeking information, but it is not the same as changing a ballot or compromising election systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

In a July 31, 2024 public service announcement, the FBI and CISA said they had no reporting that a DDoS attack had prevented an eligible voter from casting a ballot, compromised ballot integrity, or disrupted timely vote tabulation or transmission of results. The agencies advise voters to rely on official election offices and use alternative communication channels if a website is unavailable. Read the FBI and CISA election-infrastructure PSA.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How organizations can prepare

Reduce the impact of a website DDoS

  1. Arrange DDoS protection in advance. Enroll in a service that detects abnormal traffic and redirects it away from the organization’s network.
  2. Coordinate with the internet service provider (ISP). Establish a relationship before an incident and agree on how traffic can be controlled during an attack.
  3. Maintain a recovery plan. Document who communicates, how mitigation is initiated, and how services are restored.
  4. Monitor other network assets. Continue monitoring during and after the incident for anomalous activity that could signal a secondary attack.

Protect OT and preserve the ability to operate

  • Disconnect HMIs and programmable logic controllers (PLCs) from the public internet.
  • If remote access is necessary, protect it with a firewall or VPN, a strong password, and MFA.
  • Replace default passwords, patch VNC and other software, and log remote access.
  • Keep manual-operation capability available so staff can maintain control if remote systems are unavailable or compromised.
  • Back up engineering logic, configurations, and firmware so systems can be restored.

These OT safeguards address the exposure and access weaknesses described in the joint agency guidance; they complement, rather than replace, DDoS defenses for public-facing services.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.