Denial of Service
In plain terms
A service is overwhelmed with requests until it stops responding. Nothing is stolen and nothing is altered: it's availability that's being targeted.
Definition
A denial-of-service attack consists of making a service unavailable by flooding it with requests or exhausting its resources. It differs from everything else in this catalogue in its goal: neither data nor accounts, but interruption. When the flooding comes from many devices at once, it's called a distributed attack.
How it works
The distributed form is the most common, and it mobilizes compromised devices scattered widely — often connected objects enrolled without their owners' knowledge, left unmonitored. This is the point that directly concerns an individual reader: in the vast majority of cases, you are not the target of a denial-of-service attack, you are potentially one of its means. Motivations, on the target side, range from economic pressure to activism; sometimes the flooding also serves as a diversion while something else happens elsewhere. At an individual's scale, the visible effect is indirect: a service you use becomes unreachable for a few hours. A home internet line can be targeted directly, but that's a markedly less frequent case than the term's notoriety suggests.
Warning signs
- Online service unreachable or very slow, for you as for others at the same time
- Announcement from the provider reporting an availability incident
- Your own connection saturated with no usage explaining it, several devices affected
- Notice from your internet provider about abnormal outbound traffic — in that case you're on the side of the means, not the targets
How to verify
First check whether the unavailability is specific to you: try it over mobile data, and see if other users report the same thing. A service unreachable for everyone is the provider's problem, and there's nothing for you to do about it. Saturation limited to your own line, on the other hand, is worth examining your own devices for.
What to do
What you can act on is your possible contribution, and it's far from negligible: change the factory passwords of everything connected, enable automatic updates, disable remote access on equipment that doesn't need it, and remove from the network anything no longer receiving updates. These are the devices that make up the networks used for these attacks.
If it already happened
If a service you use is unavailable, there's nothing to do on your end except wait, and be wary of messages exploiting the incident — a visible outage is a classic opportunity for fake 'account restoration' messages. If your own line is targeted, or your internet provider flags abnormal traffic, contact them: only they can act upstream. Then identify the device responsible, reset it to factory settings, and update it. Report the incident to the relevant authority.
Frequently asked questions
- Am I a likely target?
- Rarely, as an individual. What really concerns you is the other end: your connected objects can be enrolled to take part in these attacks, without anything alerting you. That's why the useful measures in this entry focus on your own equipment.
- A service I use is down. What should I do?
- Wait, and stay alert to what happens during the incident: known outage periods are prime opportunities for fake messages announcing a restoration or asking you to reconnect. Always reach the service through your own means rather than through a received link.
Related attacks
Official sources
Also known as: DDoS, denial-of-service attack, DoS, service flooding.
This article is part of the Network and Wi-Fi attacks family. Last updated: 2026-09-03.