In October 2024, a financial institution experienced a sustained DDoS attack that generated 31 million security events in its SIEM over 4 hours. While the security operations center was fully occupied responding to the flood, attackers exfiltrated 31 million customer records through a separate application vulnerability. The DDoS was not incidental -- it was the operational component of the breach plan.
This combined attack pattern is documented across multiple incident reports from 2023-2025. DDoS-as-distraction is not a new concept, but its operational execution has become more sophisticated: the DDoS component is specifically calibrated to consume SOC attention without being so severe that it triggers an immediate all-hands incident response that might catch the concurrent breach activity.
How the Pattern Works
The attacker maintains two separate operational tracks. Track 1: a DDoS campaign targeting the organization's most visible internet properties -- the main website, the customer portal, or the API gateway. The attack is severe enough to generate alerts and require analyst attention, but not so severe that it causes complete service disruption (which would escalate immediately to executive attention and bring in more resources). Track 2: a targeted exploitation campaign against a different surface -- an internal API, a staging environment, or a third-party integration -- that proceeds while the SOC is occupied with Track 1.
The DDoS component serves two specific functions in this pattern. First, SIEM saturation: a sustained L7 flood generates thousands to millions of security events, increasing the probability that the breach-related events (authentication anomalies, unusual data export patterns, lateral movement indicators) are missed in the noise. Second, resource exhaustion: SOC analysts managing a live DDoS incident are not available to investigate anomalies in other systems at their normal level of attention.
Why DDoS Resilience Reduces Breach Risk
An organization with strong DDoS defenses handles Track 1 through automated mitigation rather than manual SOC response. The DDoS is absorbed by rate limit rules and WAF controls without requiring analyst intervention. The SOC remains available to detect and investigate the Track 2 breach activity. The attacker's distraction strategy fails because the distraction is neutralized automatically.
This is the operational risk argument for DDoS resilience investment that goes beyond availability SLAs. A DDoS attack that requires 4 hours of SOC attention creates a 4-hour window during which breach detection capability is degraded. Reducing that to 15 minutes of automated mitigation reduces the breach detection window by 94%. The availability impact and the breach-facilitation impact are both addressed by the same set of defenses.
"The DDoS was almost certainly coordinated with the exfiltration. The timing was too precise to be coincidental, and the attack rate was specifically calibrated -- not maximal, but high enough to keep us engaged."
Operational Response Protocols
Organizations aware of this pattern should implement split-track incident response protocols: when a DDoS event is declared, a separate analyst task explicitly checks for anomalous activity on non-targeted systems during the same window. This creates a brief but focused review that specifically looks for what the DDoS might be designed to obscure. The check should cover: unusual authentication patterns, large data transfers, new service account activity, and access to data stores that are not part of the targeted DDoS surface.
Detection Indicators
Indicators that a DDoS may be the distraction component: the attack rate is surprisingly consistent (attackers calibrate to keep you engaged without triggering full escalation), the attack vector does not match the organization's typical threat profile, the attack begins during business hours or immediately before a known high-value event (earnings announcement, product launch), or the attacked service is not the organization's highest-value target but is its most visible.
Reduce Your DDoS Distraction Window
DDactic identifies the gaps that require manual SOC response versus the configurations that enable automated mitigation -- reducing the distraction window attackers depend on.
Run a Free Scan