Cloud and Hosting31.05.2026

South African Internet company hit by large-scale DDoS attack

South African hosting company Rackzar has notified customers that its network has been targeted by a distributed denial-of-service (DDoS) attack, causing connectivity problems to its servers.

“We have identified a sophisticated and targeted attack with the sole intention of extortion,” the company said on its system status page.

“We have put measures in place to attempt to reduce the impact to your services and will continue working with our upstream partners to mitigate the attack.”

This is the second time in two weeks Rackzar has been targeted by large-scale DDoS attacks. The company told MyBroadband it was hit in the previous wave that caused severe disruptions in South Africa.

In the week of 18 May 2026, several Internet infrastructure companies in South Africa were taken offline by massive DDoS attacks, with one peaking at 1Tbps and another at 675Gbps.

Network Platforms, which suffered the attack that peaked at 675Gbps, revealed that it had received an extortion demand to make the DDoS stop.

Rackzar has confirmed to MyBroadband that it received a similar ransom note and received another extortion demand for the current DDoS attack, although the attackers’ name has changed.

The notes from the previous attacks came from “BlackMatter”. This time, they are “WhiteDwarf”. It is unclear whether Rackzar is dealing with a copycat or if the attackers have changed their name.

Rackzar told MyBroadband that it would only be able to provide detailed feedback about the attack once they had mitigated it.

However, MyBroadband has seen the ransom note. It demanded a payment of 5 XMR (Monero), equivalent to about R30,500.

Monero is a crypto asset which is not widely traded in South Africa. None of the major exchanges like VALR, Luno, and Binance offer markets for XMR.

AltCoinTrader offers a listing for the asset, where it traded at around R6,450 at the time of publication. At Bitfinex, a major overseas exchange, XMR traded at around $373.

Therefore, the extortionists were demanding the equivalent of between R30,500 and R32,250, depending on the exchange.

“The attack is directed at our upstream network infrastructure and is causing intermittent packet loss and elevated latency for some customers,” Rackzar told customers.

“We are working closely with our upstream partners and internet exchange peers to identify, filter, and mitigate the malicious traffic as quickly as possible.”

Rackzar said customers may experience intermittent connectivity disruptions until the attack was fully mitigated.

“We apologise for any inconvenience and will continue to provide updates as the situation develops.”

DDoS extortion

Netscout Cyber Threat Horizon showing incoming attacks to South Africa on 31 May 2026

Two weeks ago, MyBroadband reported that several hosting providers and other Internet infrastructure companies in South Africa were knocked offline due to sustained DDoS attacks.

Prominent hosting company 1-Grid suffered an extended outage, which drew attention to the scale of attacks targeting web hosting companies in South Africa.

A reliable industry source told MyBroadband that Host Africa, Diamatrix (known as Domains.co.za), and Liquid Intelligent Technologies had suffered attacks.

Internet infrastructure company Network Platforms and longstanding webhosting provider Xneelo also soon reported attacks.

That wave of attacks started on Sunday, 17 May, and had halted within three days. Companies told MyBroadband that the attacks had stopped by Wednesday, 20 May.

This was confirmed by the American network monitoring and DDoS mitigation company NetScout, which said its data also showed the attacks began to let up on Wednesday.

BlackMatter’s extortion note to companies promised the attacks would not stop for 14 days and demanded payment of 2.5 XMR at the time.

That was half what WhiteDwarf is trying to extort from Rackzar in this latest wave of attacks. The two extortion notes are otherwise nearly identical.

“Unfortunately, you have become a target of WhiteDwarf, a massive DDoS attack has been launched on your networks (the attack will begin in 30 minutes after this letter),” the new note stated.

BlackMatter’s original note from two weeks ago stated that the attacks would begin in 15 minutes. WhiteDwarf also changed the aggressive wording in BlackMatter’s original note.

“You have two ways — ignore, in which case the attacks will be stopped in 14 days, and your business will most likely be destroyed by then,” the original note read.

WhiteDwarf’s note deletes the latter half of the sentence, no longer threatening the victim with the destruction of their business.

“Compensate us a small amount. We guarantee decency and complete anonymity on our part. After receiving the transfer, the attack will be stopped within 5 minutes, and you will never hear from us again.”

Cybersecurity experts have raised questions about the extortion demands, as the amounts seem too low relative to the cost of perpetrating the attack.

Victims reported that the attackers used a combination of Carpet Bombing, IP Fragmentation, and DNS Amplification to overwhelm their networks with traffic.

Experts said the relatively small amounts being demanded by the attackers do not make sense, given how costly it was to run such a large-scale DDoS attack for an extended period.

Show comments

Latest news

More news

Trending news

Sign up to the MyBroadband newsletter