A series of high-profile cyberattacks hit the headlines in 2021. However, the latest threat is one that is specific to communication service providers (CSPs).Β
Recently weβve seen several distributed denial of service (DDoS) attacks targeting VoIP providers, causing voice outages. A DDoS attack isΒ a flood of fake requests andΒ traffic to a companyβs website or service. The requests can overwhelm a company, leading to users being unable to access its services.Β
One recent victim was US-based Bandwidth.com, which experienced disruption of its voice and messaging services. Alongside Bandwidth, other critical communications service providers such asΒ VoIP.ms,Β VoipΒ Unlimited andΒ VoipfoneΒ have been targeted as part of a βrollingβ DDoS attack.Β
Of course, VoIP providers donβt just provide voice services to businesses. They also provide a platform for many emergency services to handle call traffic. As such, these latest attacks have caught the attention of lawmakers, with the FBI now investigating the attack against Bandwidth.com. And in the UK, if the attacks have the ability to take down 999 services, they are classed as a terrorist threat.Β
The situation presents a particular challenge for channel partners that resell third-party VoIP services. If VoIP outages and quality-of-service (QoS) issues pop up, partners can do little except tell their customers that the issue is outside of their control.Β
βThereβs lots of instability at the moment because lots of partners and SIP providers are not able to defend against the attacks,β said Ian Rowan, Senior Channel Manager atΒ Wildix UK.Β
The goal of the attacks in many cases is to elicit payment from the companies. The perpetrators of the attack against Voip.ms demanded that the company pay 100 bitcoins, or around $4.2 million, to stop the DDoS attack.Β
OnceΒ attacked, there is also a high chance that the companies will be targeted again βΒ VoipfoneΒ also said it had been hit by βa further DDoS attackβ after its initial attack.Β
Open vs Closed Networks
βThe problem is some VoIP providers use open-faced platforms that can be accessed via the internet,β said Rowan, who added that Wildix isnβt in the same vulnerable position to attack.Β
βA standard SIP providerβs services have to be open to the outside world because they donβt know where customers are going to be. We are not susceptible to those same attacks because of the way our network is designed. On Wildix weβre only providing Wildix call termination to Wildix PBXs. So, we know where theyβre coming from, or we can accept traffic from Wildix customers and not from anyone else. Ours is a closed network, whereas everybody else is an open network.βΒ
While these DDoS attacks are currently causing great concern among CSPs, the worst may be to come.Β DDoS attacks rose by a staggering 233% in the first half of 2021.Β
Meanwhile, research has identifiedΒ βBlack Stormβ attacks that could further impact CSP networks. A report by cyber firmΒ NexusguardΒ says cybercriminals can launch a Black Storm attack more easily than other types of DDoS attacks. During a Black Storm attack, hackers can leverage any device internet-connected to cripple CSP networks and terminate medium to large-sized enterprises in a clean sweep.Β
As a partner, it is vital your VoIP provider is taking every measure to ensure it is as secure from attack as possible, or it could, unfortunately, find itself making headlines in the future.Β
Β
Β