Back to blog
dns Published: AEU DNS Newsroom

Wave of Cyberattacks After George Floyd's Death Highlights DNS and DDoS Defenses

Wave of Cyberattacks After George Floyd's Death Highlights DNS and DDoS Defenses

Following the murder of George Floyd, websites faced a surge in digital attacks, prompting Cloudflare to spotlight DDoS and DNS security for at-risk groups.

In early June 2020, as protests spread across the United States after the killing of George Floyd, the internet saw a parallel wave of malicious activity. On June 2, 2020, Cloudflare, a major internet infrastructure and security company, published a blog post authored by Matthew Prince and John Graham-Cumming that detailed cyberattacks occurring in the days after the murder. The post appeared under Cloudflare's Project Galileo, an initiative that offers free security services to vulnerable public interest websites such as those run by human rights groups, independent media, and community organizations. While the specific numbers were not part of the published excerpt, the post made clear that attackers were actively targeting websites during this period of social unrest, seeking to knock them offline or compromise their visitors.

A distributed denial-of-service (DDoS) attack is one of the most common methods used in such campaigns. In a DDoS attack, the attacker floods a website with so much junk traffic from many different sources that legitimate visitors cannot reach it. Attackers often control networks of compromised computers, called botnets, to launch these floods. The Domain Name System (DNS) also plays a central role in both attacks and defense. DNS acts like the internet's phonebook: it translates human-friendly domain names such as example.com into the numeric IP addresses that computers use to connect to each other. DNS security is critical because attackers can tamper with DNS responses to redirect users to fake websites or to amplify DDoS attacks by sending spoofed requests. Cloudflare's blog post highlighted both DDoS and DNS attacks during this period, showing how real-world social unrest often spills into cyberspace.

The targets of these attacks were varied. Hacktivists, pranksters, and criminals often exploit moments of social upheaval to test defenses, steal data, or silence voices. Smaller community groups and local news outlets are especially vulnerable because they may lack the resources for robust protection. Cloudflare's Project Galileo steps in by providing free DDoS mitigation, a web application firewall, and DNS security to organizations that work in human rights, independent media, and community advocacy, ensuring they can stay online even when under attack. This support is crucial because staying online is often a matter of free expression and public safety during protests and civil unrest.

For everyday internet users and website owners, DNS security deserves close attention. When a website is attacked via DNS, users may be silently redirected to a fake version of the site designed to steal passwords or spread malware. This is called DNS hijacking or DNS spoofing. An attacker who gains control of a domain's DNS settings can also redirect email or fraudulently obtain security certificates, undermining trust in the entire website. Site owners can protect themselves by using a reputable DNS provider, enabling two-factor authentication on their domain registrar and DNS accounts, and monitoring for unauthorized changes. Encrypted DNS protocols such as DNS over HTTPS (DoH) and DNS over TLS (DoT) add an important layer of protection by encrypting the path between your device and the DNS resolver, preventing eavesdropping and tampering.

For readers who run websites or simply care about their online privacy, adopting a privacy-first encrypted DNS resolver like AEU DNS can reduce the risk of DNS hijacking and spoofing, adding a practical layer of protection during periods of heightened cyber risk. This kind of protection is especially valuable when real-world events trigger spikes in malicious online activity, as it helps ensure that your internet requests go to the right place and that your browsing stays private.

Cyberattacks tied to social events are not new, but they serve as reminders that security is not only a technical issue but also a matter of resilience for communities and free expression. By understanding how DDoS and DNS attacks work and taking simple precautions, individuals and organizations can better withstand these digital onslaughts. The Cloudflare post from June 2020 remains a useful case study in how infrastructure providers and security teams respond when the physical world and the digital world collide.

Terms explained

DDoS
A distributed denial-of-service attack floods a website with so much fake traffic from many computers that real visitors cannot get through.
DNS
The Domain Name System is like the internet's phonebook, turning website names such as example.com into the numeric addresses computers use to connect.
DNS hijacking
When an attacker secretly changes the DNS settings for a website so that visitors are sent to a fake version of the site, often to steal passwords or spread malware.
Resolver
A DNS resolver is the server your device asks to look up the numeric address for a website name; using a trustworthy resolver is important for staying safe online.
Encrypted DNS
Encrypted DNS protocols like DNS over HTTPS (DoH) or DNS over TLS (DoT) scramble your DNS requests so that no one watching the network can see which websites you are visiting or tamper with the answers.
Project Galileo
A Cloudflare program that gives free security and performance services to vulnerable public interest websites such as those run by human rights groups, journalists, and community organizations.

How to protect yourself

  1. Switch your devices and router to a DNS resolver that supports encrypted DNS (like DNS over HTTPS or DNS over TLS) so attackers cannot easily redirect your internet requests to fake websites.
  2. If you run a website, enable a DDoS protection service such as a web application firewall or a content delivery network that can automatically absorb attack traffic and keep your site online.
  3. Turn on two-factor authentication for your domain registrar and DNS provider accounts, and lock your domain so attackers cannot transfer or hijack it without your approval.
  4. Set up monitoring and alerts for your website traffic so you are notified immediately if a sudden flood of visits occurs, which could signal a DDoS attack.
  5. Keep your browser and operating system updated, and avoid clicking on suspicious links or email attachments, especially during times of high-profile news events when phishing attempts increase.

Source: blog.cloudflare.com

Get private, encrypted DNS