Nine's DDoS postmortem is a practical lesson in where filtering has to happen
The Swiss provider says an August attack hit a customer first, then its own services, exposing gaps in detection scope, blackhole coverage, and shared platform blast radius.
What happened
Nine says a large DDoS attack began on the evening of August 11, 2026, aimed first at one of its customers and later at Nine's own services. The company says Deploio applications, its website, Cockpit, and ticketing were affected at different times during recurring waves from Tuesday evening to Thursday around 12:51.
Nine is explicit about one important boundary: it says customer data was not compromised. The incident was an overload attack, not an intrusion.
Why mitigation got messy
The company says outside telemetry from Nokia Deepfield showed two botnet families, CECbot and Katana, and confirmed that the customer was targeted first before the attack broadened to Nine's infrastructure.
Nine describes the method as UDP amplification. Once an uplink is saturated, filtering inside the provider's own network is too late, because the unwanted packets have already crowded out legitimate traffic. That is why blackholing and upstream mitigation become the real levers.
The incident also pushed Nine to move exposed applications behind bunny.net's CDN with DDoS protection after blackholing alone was not enough against request-volume pressure.
Quick takeaways
- Nine says its automated detection originally missed customer-owned networks it announced on the customer's behalf; it says that gap was closed the same night.
- The company found it had not systematically verified blackhole effectiveness across every traffic path.
- Nine says it is hardening Cockpit and ticketing and working to reduce shared-address dependencies on Deploio.