SyloSpace

How do cyberattacks on data centres disrupt internet services?

A data centre is the equipment that stores and moves digital information plus the systems that keep it running, so attacks on it can cut off internet services.

Updated 52 minutes ago6 min readVersion 2
CommentsFollow

Covers: This page explains the technical and operational pathways through which cyberattacks on data centres can degrade or interrupt internet services, including DDoS, ransomware, supply-chain compromise, and attacks on cooling or power management. It does not cover attacks on end-user devices, nation-state attribution debates, or legal liability questions.

Also answers: How do cyberattacks on data centers affect the internet? · Why do data centre attacks cause internet outages? · What happens to the internet when a data centre is hacked? · How can a cyberattack take down internet services?

Close-up of server cooling fans in a vibrant data center
Photo: Winston Chen

The short answer

Interpretation AI-prepared starting map

A data centre is a physical facility that houses electronic equipment used to process, store and transmit digital information, together with the environmental control equipment needed to keep that equipment running. Because internet services depend on such facilities, attacks that damage or disable them can interrupt those services. The clearest confirmed case in the available evidence is the repeated targeting of Yandex's data centre in 2026, which forced the company to suspend operations. Beyond that, the evidence describes how distributed denial-of-service (DDoS) campaigns have evolved from single-step floods into multi-stage operations, which is the main technical pathway documented here for degrading services.123

What this rests on5 independent sources
  • Evidence 16
  • Interpretation 6

Did this answer your question?

Be the first to vote
Your perspective belongs in the picture.Join free to vote

In brief

  1. A data centre is defined by its electronic equipment and the environmental control equipment that keeps it operable, so cooling and power management are part of the attack surface, not an afterthought.1

    Evidence-backed
    Join free to vote
  2. The clearest confirmed case in the available evidence is the repeated 2026 targeting of a Yandex data centre, which forced the company to suspend operations.2

    Evidence-backed
    Join free to vote
  3. DDoS is increasingly a multi-stage operation — preparation, development, execution — rather than a single volumetric flood, which changes how disruption unfolds.3

    Evidence-backed
    Join free to vote
  4. Defences surveyed for DDoS include anycast and scrubbing, BGP Flowspec, programmable data planes, adaptive ML detection and API hardening.3

    Evidence-backed
    Join free to vote
  5. Evidence on ransomware and grid attacks suggests consequences depend on redundancy and practised manual fallbacks, but this has not been demonstrated for data centres in the sources here.45

    Interpretation
    Join free to vote

At a glance

The picture in numbers

Live · updated just now

Three-phase attack chain proposed by researchers

Phase 1

preparation

Phase 2

development

Phase 3

execution

DDoS campaigns unfold in stages, not one flood4

The evidence behind it

5 sources
  • Reviews of many studies1
  • Other studies and data2
  • Background2

Published in 2026

Sources on this page by kind and year
SourceKindYear
Ukraine strikes Yandex data centre in third attack on Russian tech giantBackground2026
Data center (Wikipedia)BackgroundUnknown
A Survey of Emerging DDoS Threats in New Power Systems.Other studies and data2026
Comprehensive security review and challenges for smart and power grids to prevent cyber-attacks in IoTs.Reviews of many studies2026
Cyber-resilient Intensive Care Unit: Ransomware is a Patient-safety Crisis-A Resource-stratified Approach for India.Other studies and data2026

The community around it

No one has added to this page yet. Firsthand experience, a newer study or a different reading of the numbers would show up here, credited to you.

What it means for you

Which fits you?

Pick the situation closest to yours. Each answer says what it rests on.

If you want the basic definition of a data centre and why it is a target

the Energy Independence and Security Act of 2007 definition covers both the electronic equipment and the environmental control equipment that maintains operating conditions, which is why cooling and power count as part of the attack surface.1

Evidence-backed

If you are looking for a confirmed example of an attack on a data centre with an operational effect

the reported strikes on a Yandex data centre, the third that week, forced the company to suspend its operations.2

Evidence-backed

If you are trying to model how a DDoS attack degrades a service

treat it as a three-phase chain — preparation, development, execution — rather than a single flood, since incidents from 2019 to 2024 show dependencies on novel hardware, network architectures and application protocols.3

Evidence-backed

If you are choosing defences against DDoS for infrastructure you run

the surveyed options are anycast and scrubbing, BGP Flowspec, programmable data planes, adaptive machine-learning detection and API hardening, with research pointing to cross-layer telemetry, adversarially robust learning, automated mitigation orchestration and cooperative takedown.3

Evidence-backed

If you operate a critical service and are planning for cyber-physical failure

the ICU ransomware framework suggests starting with minimum viable controls — downtime kits, paper records, designated roles and structured drills — before adding targeted redundancy, on the argument that survival during digital failure depends on analog competencies practised beforehand.4

Evidence-backed

If you are assessing vulnerabilities in power distribution that feeds a facility

the smart-grid survey identifies threats to exchanged data and power control commands, and stresses ensuring Quality of Service across the communication technologies and networks involved, including SCADA and cloud components.5

Evidence-backed

The full story · 4 chapters

01

What a data centre is and why attacks on it matter

AI summary:Defines a data centre as electronic equipment plus the environmental control equipment that keeps it operable, which is why cooling and power count as targets.

Evidence-backed

Evidence-backed: A data centre is a physical room, building or facility for storing, managing and disseminating data and information, including computer systems and associated components. The United States' Energy Independence and Security Act of 2007 defines it as "any facility that primarily contains electronic equipment used to process, store, and transmit digital information", including a free-standing structure or a facility within a larger structure that uses environmental control equipment to maintain the proper conditions for operating electronic equipment. Data centres date back to the 1940s, with the U.S. military's ENIAC as an early example, and come in different models depending on their workloads.1

Interpretation

Interpretation: The definition matters for this question because it makes explicit that a data centre is not only computers: it is also the environmental control equipment that keeps them operable. That is why the scope of this page includes attacks on cooling and power management — those systems are part of what a data centre is, not an optional extra.1

02

A confirmed case: repeated strikes on a Yandex data centre

Evidence-backed

Evidence-backed: Ukraine struck a Yandex data centre in what was reported as the third attack that week on the Russian tech giant, forcing the company to suspend its operations. This is a confirmed report of an attack on a data centre with a direct operational consequence: the operator stopped running services.2

Interpretation

Interpretation: What this case does not establish is the mechanism of disruption. The report describes the effect — suspended operations — but not whether services went down because of damage to servers, to network links, to power or cooling, or because the operator chose to shut systems down as a precaution. Readers should treat the pathway from this attack to any particular internet outage as unconfirmed.2

03

DDoS as a multi-stage pathway to disruption

AI summary:Describes DDoS shifting from single floods to a three-phase preparation, development and execution chain, and surveys defences against it.

Evidence-backed

Evidence-backed: DDoS has often been framed as a single-step volumetric assault, but ubiquitous intelligence and ambient connectivity increasingly enable DDoS campaigns to unfold as multi-stage operations rather than isolated floods. Reviewing incidents from 2019 to 2024, researchers propose a three-phase DDoS attack chain — preparation, development and execution — that captures contemporary tactics and their dependencies on novel hardware, network architectures and application protocols.3

Evidence-backed

Evidence-backed: The same review surveys current defences: anycast and scrubbing, BGP Flowspec, programmable data planes, adaptive machine-learning detection and API hardening. It also outlines research directions in cross-layer telemetry, adversarially robust learning, automated mitigation orchestration and cooperative takedown. Large language models are noted as a possible way to strengthen traditional DDoS defences through richer contextual understanding.3

Interpretation

Interpretation: For a reader trying to understand how an attack on a data centre becomes an internet outage, the multi-stage framing is the most useful idea here: disruption is not necessarily one big flood, but a sequence in which preparation and development set up the conditions for execution. The review does not, however, measure how much service degradation results at each stage.3

04

Adjacent evidence: power systems and ransomware

AI summary:Covers smart grid vulnerabilities and a ransomware case, suggesting failure consequences depend on redundancy and practised manual fallbacks.

Evidence-backed

Evidence-backed: Smart grids are described as resilient, adaptive, self-recovery and sustainable power distribution systems that have shifted from a unidirectional model towards a bi-directional one. These large, complex, self-healing systems have numerous vulnerabilities that threaten exchanged data and power control commands, and the survey describes threats, attacks, vulnerabilities, security measures and limitations for IoT-based smart grids, including detailed descriptions of SCADA architecture and cloud computing as critical components. Its findings point to the need to ensure Quality of Service across the communication technologies and networks deployed in smart grids, and to develop network models and middleware to improve that QoS.5

Evidence-backed

Evidence-backed: On ransomware, the 2022 All India Institute of Medical Sciences (AIIMS) Delhi attack is cited as exposing fragmented systems, an absence of post-incident clinical surveillance, and the operational reality that "Western" cybersecurity fixes do not translate directly to resource-variable settings. The authors reframe cyber-resilience as a bedside safety competency rather than an IT concern and propose a three-tier preparedness framework: Tier 1 minimum viable controls achievable by any ICU (downtime kits, paper medication administration records, designated roles, structured drills); Tier 2 targeted redundancy; Tier 3 advanced capabilities for tertiary centres. Their conclusion is that when digital systems fail, patient survival depends on analog competencies practised before the crisis.4

Interpretation

Interpretation: Neither of these sources is about data centres or internet services, so they should not be read as direct evidence for this page. Their transferable point is structural: when a cyber-physical system fails, the consequences depend on the redundancy and manual fallbacks that exist beforehand, and on how well those fallbacks have been practised. That logic plausibly applies to a data centre losing power management or cooling, but the sources here do not test it in that setting.54

Your turn

Have your say

See where others stand. Join free to add your perspective. One answer per account.

How do you feel about this?

No votes yet
Your perspective belongs in the picture.Join free to vote

Quick questions from connected pages

Before you go

What to remember

The few things worth keeping from this page.

  1. A data centre is defined by its electronic equipment and the environmental control equipment that keeps it operable, so cooling and power management are part of the attack surface, not an afterthought.

  2. The clearest confirmed case in the available evidence is the repeated 2026 targeting of a Yandex data centre, which forced the company to suspend operations.

  3. DDoS is increasingly a multi-stage operation — preparation, development, execution — rather than a single volumetric flood, which changes how disruption unfolds.

This answer keeps changing

When new evidence or a better source comes in, this page is updated (it's on version 2, last changed 52 minutes ago). Follow it to be told when that happens.

Up nextHow much electricity do data centres and AI use?How much electricity do data centres and artificial intelligence use, and how is that demand expected to change?

Ask this Sylo

Still wondering about something?

Answers come only from this page's reviewed material, with citations, and say plainly when the page doesn't cover it yet.

Behind this page

Who's adding to it, where it comes from, how it changed and what would make it better. Always open to everyone.

Discussion

Nobody has added anything yet. If you have experience, evidence or a different view, you could be the first.

Sources

Numbers match the citations in the article. A working link isn't proof that a page supports a claim; check the quoted passage and date.

  1. 1
    Data center (Wikipedia)
    WikipediaPublished Oct 8, 2026Checked Oct 11, 2026
    “A data center is a physical room, building, or facility for storing, managing, and disseminating data and information, including computer systems and associated components, housing IT infrastructure, and training artificial intelligence. The United States' act of Congress, the Energy Independence and Security Act of 2007, defines a data center as "any facility that primarily contains electronic equipment used to process, store, and transmit digital information." This includes "a free-standing structure" or "a facility within a larger structure, that uses environmental control equipment to maintain the proper conditions for the operation of electronic equipment." According to IBM, data centers date back to the 1940s, with the U.S. military's Electrical Numerical Integrator and Computer (ENIAC) as an early example. Data centers have different models depending on their workloads.”
  2. 2
    Ukraine strikes Yandex data centre in third attack on Russian tech giant
    BBC NewsPublished Oct 11, 2026Checked Oct 11, 2026
    “It is the third time this week that Ukraine has targeted Russian tech giant Yandex, forcing the company to suspend its operations.”
  3. 3
    A Survey of Emerging DDoS Threats in New Power Systems.
    Sensors (Basel, Switzerland) (Luo et al.)Published Feb 8, 2026Checked Oct 11, 2026
    “Although attack-chain models are standard for Advanced Persistent Threat (APT) analysis, they have seldom been applied to DDoS, which is often framed as a single-step volumetric assault. However, ubiquitous intelligence and ambient connectivity increasingly enable DDoS campaigns to unfold as multi-stage operations rather than isolated floods. In parallel, large language models (LLMs) create new opportunities to strengthen traditional DDoS defenses through richer contextual understanding. Reviewing incidents from 2019 to 2024, we propose a three-phase DDoS attack chain-preparation, development, and execution-that captures contemporary tactics and their dependencies on novel hardware, network architectures, and application protocols. We classify these patterns, contrast them with conventional DDoS, survey current defenses (anycast and scrubbing, BGP Flowspec, programmable data planes, adaptive ML detection, API hardening), and outline research directions in cross-layer telemetry, adversarially robust learning, automated mitigation orchestration, and cooperative takedown.”
  4. 4
    Cyber-resilient Intensive Care Unit: Ransomware is a Patient-safety Crisis-A Resource-stratified Approach for India.
    Indian journal of critical care medicine : peer-reviewed, official publication of Indian Society of Critical Care MediciPublished May 25, 2026Checked Oct 11, 2026
    “India faces a compounded risk-the 2022 All India Institute of Medical Sciences (AIIMS) Delhi ransomware attack exposed fragmented systems, an absence of post-incident clinical surveillance, and the operational reality that "Western" cybersecurity fixes do not translate directly to resource-variable settings. This Viewpoint reframes cyber-resilience as a bedside safety competency rather than an information technology (IT) concern and proposes a resource-stratified three-tier preparedness framework. Tier 1 defines minimum viable controls achievable by any ICU: Downtime kits, paper medication administration records (MARs), designated roles, and structured drills. Tier 2 adds targeted redundancy; tier 3 outlines advanced capabilities for tertiary centers. When digital systems fail, patient survival depends on analog competencies practiced before the crisis.How to cite this articleChoudhuri B, Prakash J, Pal B, Veenith T. Cyber-resilient Intensive Care Unit: Ransomware is a Patient-safety Crisis-A Resource-stratified Approach for India. Indian J Crit Care Med 2026;30(5):363-367.”
  5. 5
    Comprehensive security review and challenges for smart and power grids to prevent cyber-attacks in IoTs.
    MethodsX (Kabier et al.)Published Jul 13, 2026Checked Oct 11, 2026
    “This SG offers resilient, adaptive, self-recovery, and sustainable power distribution. The recent past has seen a gradual shift from unidirectional power systems towards the SG's bi-directional model. However, these large, complex, and self-healing SG systems have numerous vulnerabilities that threaten the exchanged data and power control commands. Therefore, many research efforts have been directed towards the enhancement of the SG security. In this paper, an overview of threats, attacks, vulnerabilities, security measures, and limitations for the IoT-based SG are described. We also give detailed descriptions of the Supervisory Control and Data Acquisition (SCADA) architecture as well as cloud computing as critical components of the smart grids. Moreover, this survey paper discusses tools and methods for verifying security protocols. The outcomes indicate the necessity of ensuring Quality of Service (QoS) in various communication technologies and networks deployed in SGs. The findings also point to the significance of developing network models and middleware to enhance QoS of the smart grid networks, which collect various data from diverse smart components and sensors.”

How it changed

Published 1 time since Oct 11, 2026.

  1. Version 2Oct 11, 2026Live now

    AI-prepared Starting Map from live research.

    • First published version.
Every version, side by side

Help improve it

The brief is open about what's uncertain. These are the specific gaps that new material would fill.

  • “What a data centre is and why attacks on it matter” rests on one independent source

    A second, independent source that confirms or challenges it would make this part more reliable.

  • “A confirmed case: repeated strikes on a Yandex data centre” rests on one independent source

    A second, independent source that confirms or challenges it would make this part more reliable.

  • “DDoS as a multi-stage pathway to disruption” rests on one independent source

    A second, independent source that confirms or challenges it would make this part more reliable.

Open questions

  • What was the actual mechanism by which the Yandex data centre strikes forced suspension of operations — physical damage, network disruption, power or cooling failure, or precautionary shutdown?

    No answers yet

  • How often do attacks on cooling or power management in data centres translate into measurable internet service degradation, and over what timescales?

    No answers yet

  • What is documented about supply-chain compromise of data centre operators or their equipment, and how does it differ in effect from direct attack?

    No answers yet

  • How much service degradation results at each phase of the three-phase DDoS attack chain, and how effective are the surveyed defences in practice?

    No answers yet

  • Do data centre operators maintain manual or analog fallbacks comparable to the ICU downtime kits, and are they exercised?

    No answers yet

Around this topic

Sylos connect: narrower topics report up to broader ones, so what's learned in one place shows up where it matters.

Ask this Sylo

Answers only from “How do cyberattacks on data centres disrupt internet services?”

Ask anything about this page. The AI reads only its reviewed brief, sources and contributions, cites what it used, and says when the page doesn't cover something.