Skip to main content
Cybersecurity9 min readLast reviewed Jun 2026

Ransom DDoS and Cyber Extortion: What a Small Business Should Actually Do

SE
Stefan Efros
CEO & Founder
|
Authored byStefan Efros, CEO & Founder

If your small business gets a ransom DDoS note, do not pay it, route your traffic through an upstream DDoS scrubbing service, and report the extortion to the FBI's Internet Crime Complaint Center. Paying does not stop the attack, and it marks you as a target who will pay again. The fix is mitigation plus a tested response plan, not a bitcoin wallet.

What a ransom DDoS attack actually looks like

I have sat with owners the morning a ransom DDoS note lands, and the pattern is almost always the same. An email shows up naming your company, your public IP ranges, sometimes your carrier. It demands payment in cryptocurrency by a deadline. To prove they are serious, the attackers often fire off a short demonstration flood, usually a few minutes of junk traffic that briefly knocks your website or customer portal offline. Then they wait.

This is extortion built on a denial-of-service attack. The criminal does not break into your systems or steal data. They simply threaten to bury your public-facing services under so much garbage traffic that real customers cannot reach you. For a trucking company, that can mean your load board, your driver portal, or your dispatch tools going dark during a shift. For a retailer it means checkout is down. The leverage is downtime, and the clock.

Why you should not pay the ransom

Paying is the wrong move, and every federal agency that touches this says so. CISA's guidance on responding to these attacks is direct: organizations should not pay, because payment does not guarantee the attacks stop and it encourages more demands. You can read it in CISA's own Understanding and Responding to Distributed Denial-of-Service Attacks guide.

Think about the incentives. The attacker has no contract with you and no reputation to protect. Once you pay, two things happen. First, your name moves onto a private list of businesses that paid, which gets sold and reused. Second, the same crew, or a copycat, comes back in a few months because you have proven you will reach for the checkbook. I have watched a company pay a modest first demand and face a larger one before the quarter was out.

There is also a practical truth here. A ransom DDoS threat is, in most cases, a bluff backed by rented capacity. The criminals are betting you have no real mitigation in place, so a flood will hurt. If you have upstream filtering ready, the attack arrives, gets absorbed, and the demand becomes irrelevant. You do not negotiate your way out. You out-engineer it.

What good DDoS protection for a small business looks like

Effective DDoS protection for a small business is not a box you buy and forget. It is a layered setup, and most of it lives upstream of your own network. The core idea is simple: malicious traffic should be filtered before it ever reaches your circuit, because once a 50 Gbps flood is sitting on a 1 Gbps line, nothing you do on your firewall matters.

Start with always-on filtering at the edge. Put your public web properties and portals behind a cloud-based scrubbing or content delivery service that can absorb volumetric floods and challenge suspicious requests. Hide your origin servers so the real IP addresses are not trivially discoverable. Then make sure your DNS provider is itself DDoS-resilient, because attackers love to hit DNS, which takes everything down at once even if your web servers are fine.

Below that, baseline your normal traffic so anomalies stand out, set rate limits on login and API endpoints, and keep your internet provider's contact and emergency mitigation options on file before you need them. None of this is exotic. It is the difference between a Tuesday and a crisis. CISA lays out the same defense-in-depth approach in the guide linked above, and it maps cleanly onto the Protect and Respond functions of the NIST Cybersecurity Framework 2.0.

The first hour: your response playbook

When a note arrives or an attack starts, the worst thing you can do is improvise. Have a written plan and run it. The first move is to confirm what you are actually seeing. A slow website could be a real flood or it could be a marketing campaign that went well. Pull traffic graphs, check your scrubbing dashboard, and get a clear read before you escalate.

Next, activate mitigation. If you have always-on filtering, this may be automatic; if you have on-demand scrubbing, this is the moment you trigger it and loop in your provider. Preserve the extortion message and any attack logs, because that is evidence. Communicate internally to the people who answer customer calls so they are not blindsided, and keep a timeline of every action with timestamps. That timeline matters later for insurance and for law enforcement.

Do not reply to the attacker, and do not pay. Engaging only confirms a live, attentive target. Your energy goes into absorbing the traffic and keeping operations running, not into a conversation with a criminal. CISA's #StopRansomware Guide covers data-extortion response checklists that are useful here too, since many of the same crews run both ransomware and DDoS extortion.

Report it, every time

Reporting feels pointless in the moment. It is not. File the extortion attempt with the FBI's Internet Crime Complaint Center at ic3.gov. Federal agencies use these reports to map the groups behind these campaigns, and your one note may connect to dozens of others. The scale is real: the IC3's 2024 Internet Crime Report logged 859,532 complaints and $16.6 billion in reported losses, a 33 percent jump in losses over the prior year. Extortion of various kinds is a recurring category in that data.

Reporting also protects you. If you carry cyber insurance, a filed IC3 complaint and a clean incident timeline strengthen your claim. And if the same group later does break something, your earlier report establishes a pattern that helps investigators and your own legal posture.

Why trucking and logistics get hit harder

I run a security practice focused on trucking and logistics, and these businesses are unusually exposed to ransom DDoS for two reasons. The first is time sensitivity. A flood that takes your TMS or load board offline for three hours costs a freight broker real money, missed pickups, and angry carriers. Attackers know downtime hurts more when your business runs on the clock, so the extortion pressure lands harder.

The second is the public attack surface. Driver portals, tracking pages, EDI endpoints, and customer-facing dispatch tools all sit on the open internet and all have to stay reachable. That is a lot of doors for a flood to knock on. Hardening these systems, hiding origins, and putting them behind scrubbing is exactly the kind of work that prevents a ransom note from having any teeth.

How EFROS handles this for clients

Our approach is to take the threat off the table before anyone sends a note. We put public services behind always-on filtering, baseline normal traffic so floods are obvious, and pre-stage the carrier and scrubbing contacts so mitigation is a phone call, not a scramble. When something does start, our 24/7 SOC sees it and our incident-response retainer kicks in with a guaranteed four-hour response SLA and a named incident commander, so an owner is never trying to read traffic graphs alone at 2 a.m.

We also run the boring parts that actually matter: tested response playbooks, quarterly reports mapped to NIST CSF 2.0, and tabletop exercises so your team has done this once before they do it for real. A ransom DDoS note is a stress test of preparation you did or did not do months earlier.

If you want a candid read on whether your public services would survive a volumetric attack and an extortion demand, take a look at the EFROS security services page and start there. The goal is simple: make the ransom note something you forward to the FBI, not something you lose sleep over.

Frequently Asked Questions

Should a small business ever pay a ransom DDoS demand?

No. CISA and the FBI both advise against paying, because payment does not guarantee the attack stops and it identifies you as a target willing to pay again. The reliable path is upstream DDoS mitigation plus a tested response plan, which makes the threatened flood survivable and the demand pointless.

What is the difference between ransom DDoS and ransomware?

Ransomware encrypts or steals your data and demands payment to restore or not leak it. Ransom DDoS does not touch your data at all; the attacker threatens to flood your public services with traffic until you cannot operate, then demands payment to call it off. Some criminal crews run both, and they exploit the same fear of downtime.

How do I know if a ransom DDoS threat is real or a bluff?

Many are bluffs backed by rented attack capacity, often accompanied by a short demonstration flood to seem credible. Rather than guess, assume it could be real and confirm what your traffic monitoring shows. If you have always-on filtering in place, a real attack gets absorbed and the question of bluff versus real stops mattering.

Where do I report a DDoS extortion note?

File it with the FBI's Internet Crime Complaint Center at ic3.gov, and preserve the original message and your attack logs as evidence. Reporting helps federal investigators connect campaigns across victims, and a filed complaint also strengthens any cyber insurance claim you may need to make.

Can DDoS protection be set up before an attack happens?

Yes, and it should be. Effective protection means routing public services through cloud-based scrubbing or a CDN, hiding your origin servers, using a DDoS-resilient DNS provider, and pre-staging your carrier's emergency mitigation contacts. Setting this up in advance turns a potential crisis into a non-event, which is far cheaper than reacting mid-attack.

About the author

Stefan Efros — CEO & Founder, EFROS, author of this article

Stefan Efros

CEO & Founder, EFROS

Stefan founded EFROS in 2009 after 15+ years in enterprise IT and cybersecurity. He sees how the pieces connect before others see the pieces themselves. Focus: security-first architecture, operational rigor, and SLA accountability.

CompTIA SecurityXCompTIA CySA+CompTIA Security+CompTIA PenTest+OSINTAWS Solutions Architect
Connect on LinkedIn

Related articles

More from the EFROS blog on cybersecurity and adjacent topics.