Extortion DDoS took Basecamp down for 45 minutes
Basecamp and its sibling services were fully unreachable for 45 minutes and intermittently degraded for nearly two hours, affecting all customers on a Monday morning.
Your status page must be load-tested for outage-level traffic spikes, and incident communication must begin within five minutes of detection — not after internal triage is complete.
Criminals launched a multi-vector DDoS attack exceeding 20Gbps — combining SYN flood, DNS reflection, ICMP flooding, and NTP amplification — as part of an extortion attempt.
The volumetric attack saturated the network before mitigations were in place; filtering was eventually routed through a single provider but the status page, hosted off-site, also buckled under the surge of concerned users checking it, extending the communication gap.
When designing for availability under external attack, how would you architect your status and incident-communication channels so they remain reachable precisely when your primary service is not?