A series of high-profile cyberattacks hit the headlines in 2021. However, the latest threat is one that is specific to communication service providers (CSPs).
Recently we’ve seen several distributed denial of service (DDoS) attacks targeting VoIP providers, causing voice outages. A DDoS attack is a flood of fake requests and traffic to a company’s website or service. The requests can overwhelm a company, leading to users being unable to access its services.
One recent victim was US-based Bandwidth.com, which experienced disruption of its voice and messaging services. Alongside Bandwidth, other critical communications service providers such as VoIP.ms, Voip Unlimited and Voipfone have been targeted as part of a “rolling” DDoS attack.
Of course, VoIP providers don’t just provide voice services to businesses. They also provide a platform for many emergency services to handle call traffic. As such, these latest attacks have caught the attention of lawmakers, with the FBI now investigating the attack against Bandwidth.com. And in the UK, if the attacks have the ability to take down 999 services, they are classed as a terrorist threat.
The situation presents a particular challenge for channel partners that resell third-party VoIP services. If VoIP outages and quality-of-service (QoS) issues pop up, partners can do little except tell their customers that the issue is outside of their control.
“There’s lots of instability at the moment because lots of partners and SIP providers are not able to defend against the attacks,” said Ian Rowan, Senior Channel Manager at Wildix UK.
The goal of the attacks in many cases is to elicit payment from the companies. The perpetrators of the attack against Voip.ms demanded that the company pay 100 bitcoins, or around $4.2 million, to stop the DDoS attack.
Once attacked, there is also a high chance that the companies will be targeted again – Voipfone also said it had been hit by “a further DDoS attack” after its initial attack.




