Security

TypePad Claims It Was Hit By Another DDoS Attack

Comment

Image Credits:

A number of technology companies, including MeetupBasecamp, Vimeo, Bit.ly and others, have undergone website-crashing DDoS attacks (distributed denial-of-service) in recent months, but SAY Media-owned blogging platform Typepad, apparently, has the dubious honor of being taken down for an extended outage more than once in just a few weeks. The company has confirmed to us this morning that it is again undergoing another DDoS attack, which has taken its service offline.

However, until all the facts are in and TypePad can provide more info about the nature of this attack, which right now it’s unable to do, it’s unclear at this time that this morning’s network outage is definitely a DDoS attack — the same as before. Because it’s still early in the investigation, it’s possible the company is presuming a DDoS attack, where only a network outage was at fault.

We’ll update when we — and they — know more. However, when asked around an hour ago, TypePad did say that it was indeed “under a DDoS attack.”

In April, we reported that Typepad was undergoing an extended DDoS attack, which, at the time, had been underway off and on for nearly five days. The company explained that the attack was similar in style to that which had taken down Basecamp, and confirmed that it was working with technology providers, including CloudFlare and Fastly to help mitigate the attack and bring its service back online.

Though TypePad never shared extensive technical details about the DDoS attack, the typical scenario — and one that Basecamp had faced, as well — involves an initial demand for some sort of “ransom” once the site and its related services have been knocked offline. The amount first requested is usually small, but once attackers know they have a willing victim, they’ll often increase the amount.

SAY Media said it had also received a “ransom” note, and was cooperating with the FBI on an investigation.

According to Paul Devine, VP of Engineering at Say Media, this new Typepad attack began at 6:00 AM PT and the company is again working with CloudFlare and Fastly to mitigate the situation. “[We] don’t expect these attacks to have longevity,” he tells us. “We’re looking forward to having the sites up and running as quickly as we can.”

As of a few minutes ago, the company tweeted that blogs were loading. However, at the same time, the URL www.typepad.com was still largely crashed when we tried it ourselves. That is, instead of loading up properly, CloudFlare is providing a snapshot of the site through its “Always Online” service, which helps sites offer a webpage instead of an error message when taken down through cyberattacks like this.

The www.saymedia.com website address came up, however, though a bit slowly. (SAY Media operates a number of brands, including ReadWrite, xoJane, Fashionista, Cupcakes and Cashmere, and others.) The site loads but a “fatal error” message appears at the bottom of the page.

Screen Shot 2014-05-19 at 1.07.57 PM

Thanks to newer, more powerful types of DDoS attacks that have emerged as of late, attacks that once would have been thought to be record-breaking in size are now becoming routine. For instance, Meetup’s attack was 8 Gigabits in size, and it’s not uncommon for NTP-based DDoS attacks (which exploit an older protocol called Network Time Protocol) to be 10 Gigabits in size.

However, one side effect of these attacks is that when a company later experiences a network outage, they sometimes immediately presume that they’re being attacked again. It can be difficult to tell the difference, especially in the early hours of these sorts of situations. We’ll be looking for TypePad to provide its customers with a longer post-mortem following this morning’s outage.

Given multiple attacks over the course of several weeks, the company has a responsibility to let their customers know whether or not they’re being targeted by criminals, or if unrelated network outages came into play this morning instead.

More TechCrunch

The valuation of Oyo, once India’s second-most valuable startup at $10 billion, has dipped to $2.4 billion in a new funding round. The Gurugram-headquartered startup has raised $173.5 million in…

Oyo valuation crashes over 75% in new funding

Susan Wojcicki, a longtime Googler who spent nearly a decade as the CEO of YouTube, passed away Friday after a two-year battle with non-small cell lung cancer. Wojcicki, who was…

The tech world mourns Susan Wojcicki

While Amazon has continued releasing Echo devices, including an upgraded Spot announced last month, the company has taken its foot off the gas.

As Alexa turns 10, Amazon looks to generative AI

He really said that: When asked about the company’s “Plan B” if mortgage rates don’t fall, Redfin CEO Glenn Kelman responded, “Plan B is to drink our own urine or…

Redfin CEO promises to ‘drink our own urine’ if mortgage rates don’t fall

Turkey appears to have restored access to Meta-owned Instagram, after blocking the app on August 2.  Abdulkadir Uraloglu, the country’s minister of transport and infrastructure, posted today that the ban…

Turkey restores access to Instagram

Elon Musk doesn’t want Tesla to be just an automaker. He wants Tesla to be an AI company, one that’s figured out how to make cars drive themselves.  Crucial to…

Tesla’s Dojo, a timeline

OpenAI co-founder John Schulman has left the company for rival AI startup Anthropic. In addition, OpenAI co-founder and president Greg Brockman is taking an extended leave after nine years at…

OpenAI faces more leadership shake-ups

Featured Article

Maybe Friend wasn’t crazy for spending $1.8M on a domain after all

Avi Schiffmann, the founder and CEO of Friend, told TechCrunch over email that the purchase has already paid for itself.

Maybe Friend wasn’t crazy for spending $1.8M on a domain after all

Featured Article

One man decided to take on Google Maps, 20 years later OpenStreetMap is still going strong

From internet protocols and operating systems, to databases and cloud services, some technology is so omnipresent most people don’t even know it exists. The same can be said about OpenStreetMap, the community-driven platform that serves companies and software developers with geographic data and maps so they can rely a little…

One man decided to take on Google Maps, 20 years later OpenStreetMap is still going strong

This list only includes major penalties issued to tech firms under the GDPR. In recent years, some significant sanctions have also been issued on Big Tech

The 10 largest GDPR fines on Big Tech

The data breach is the latest security issue to beset CSC ServiceWorks over the past year, after multiple researchers found security bugs.

CSC ServiceWorks reveals 2023 data breach affecting thousands of people

Featured Article

After global IT meltdown, CrowdStrike courts hackers with action figures and gratitude

CrowdStrike tried to go back to business as usual at one of the world’s largest annual cybersecurity conferences, weeks after its massive global IT crash.

After global IT meltdown, CrowdStrike courts hackers with action figures and gratitude

Tragedy has again struck a famous Silicon Valley family. Former YouTube CEO Susan Wojcicki just passed away, according to social media posts by her husband, Dennis Troper, and by Google…

Former YouTube CEO Susan Wojcicki has passed away at age 56

This is the second cyberattack targeting the school device management service Mobile Guardian this year.

Student raised security concerns in Mobile Guardian MDM weeks before cyberattack

Featured Article

Smartwatches shipments see sharp decline in India

India’s wearable market declined in Q2, primarily because smartwatch are not attracting consumers.

Smartwatches shipments see sharp decline in India

Anysphere, a two-year-old startup that’s developed an AI-powered coding assistant called Cursor, has raised over $60 million in a Series A financing at a $400 million post-money valuation, two sources…

Anysphere, a GitHub Copilot rival, has raised $60M Series A at  $400M valuation from a16z, Thrive, sources say

The internet is full of deepfakes — and most of them are nudes. According to a report from Home Security Heroes, deepfake porn makes up 98% of all deepfake videos…

How to ask Google to remove deepfake porn results from Google Search

Researchers found flaws that could allow anyone to spy on the owners of Ecovacs home robots by hijacking their cameras and microphones.

Ecovacs home robots can be hacked to spy on their owners, researchers say

When digging into the data to determine how large the exodus everyone on Threads is talking about actually is, we oddly came up short.

The X exodus that wasn’t

Substack is opening up to more users with its recent announcement that anyone can now publish content on its platform without setting up a publication. With the change, Substack is…

Substack now lets anyone publish posts, even if they don’t have a newsletter

WeRide, a Chinese autonomous vehicle company, is officially gearing up for a U.S. public debut, over a year after China started easing its effective ban of foreign IPOs.  WeRide registered…

China’s autonomous vehicle startup WeRide prepares for a US IPO

Welcome to Startups Weekly — your weekly recap of everything you can’t miss from the world of startups. Want it in your inbox every Friday? Sign up here. This week we…

AI founders play musical chairs

Featured Article

How a cybersecurity researcher befriended, then doxed, the leader of LockBit ransomware gang

Jon DiMaggio used sockpuppet accounts, then his own identity, to infiltrate LockBit and gain the trust of its alleged admin, Dmitry Khoroshev.

How a cybersecurity researcher befriended, then doxed, the leader of LockBit ransomware gang

The U.K. government has indicated it may seek stronger powers to regulate tech platforms following days of violent disorder across England and Northern Ireland fueled by the spread of online…

As unrest fueled by disinformation spreads, the UK may seek stronger power to regulate tech platforms

The Startup Battlefield is the crown jewel of Disrupt, and we can’t wait to see which of the thousands of applicants will be selected to pitch to panels of top-tier VCs…

First look at the Startup Battlefield judges at TechCrunch Disrupt 2024

The startup’s core technology is a proprietary material that absorbs moisture from the air, allowing air conditioning to cool buildings more efficiently.

Humidity sucks. Transaera has a new way to deal with it

YouTube’s latest test involves a sleep timer that pauses the video after, well, a set period of time.

YouTube is testing a sleep timer on its Premium tier

Ola Electric, India’s largest electric two-wheeler maker, surged by 20% on its public debut on Friday, making it the biggest listing among Indian firms in two years. Shares of the…

Ola Electric surges 20% in India’s biggest listing in two years

Rocket Lab surpassed $100 million in quarterly revenue for the first time, a 71% increase from the same quarter of last year. This is just one of several shiny accomplishments…

Rocket Lab’s sunny outlook bodes well for future constellation plans 

In 1996, two companies, Patersons HR and Payroll Solutions, formed a venture called CloudPay to provide payroll and payments services to enterprise clients. CloudPay grew quietly over the next several…

CloudPay, a payroll services provider, lands $120M in new funding