Plains Internet
Stopping a 400 Gbps Ransom-Driven DDoS Attack in Real Time
How Path Network's crisis response team rescued Plains Internet from an active extortion attack, routing traffic through global scrubbing centers within hours.
~400 Gbps
Peak attack size
15 hrs
Downtime before Path Network engaged
2 hrs
Time to crisis team on-call
$0
Ransom paid


client
Plains Internet is a locally owned wireless ISP delivering fixed wireless and fiber connectivity across the Texas Panhandle.
Location
TX, USA
industry
Internet Provider
Regional lifeline
Client background for Plains Internet
Who They Are
Plains Internet is a locally owned wireless internet service provider (WISP) founded in 2012 in Amarillo, Texas. Operating more than 20 tower sites across the Texas Panhandle, Plains Internet delivers fixed wireless and fiber-optic connectivity to homes, businesses, ranchers, schools, libraries, and emergency services throughout rural and urban communities that would otherwise struggle to get reliable broadband.
Last-mile wireless internet coverage
For many of Plains Internet's customers, especially in remote and underserved areas, their connection is often the only option available in the area, with no backup provider to switch to if it goes down.
The Incident
A sustained UDP reflection/amplification attack flooded Plains Internet's network. With no DDoS mitigation in place, there was nothing to stop it.
UDP reflection / amplification
Attack vector
89+ TB
Malicious traffic
18 hrs
Downtime
Ransom extortion
Motive
What Happened
Plains Internet came under a sustained distributed denial-of-service (DDoS) attack, primarily composed of UDP reflection/amplification traffic that peaked at roughly 400 Gbps. The attack was tied to a ransom extortion attempt, the attacker demanded payment to stop, which Plains Internet refused to pay.
Without DDoS mitigation in place, Plains Internet's network could not absorb or filter the flood of traffic. The attack knocked their network offline for 15 hours before they reached out to Path Network for emergency help, with the overall incident spanning up to 18 hours from first impact to full resolution.
Once Plains Internet's traffic was rerouted through Path Network's scrubbing infrastructure, Path's proprietary firewall telemetry captured the malicious traffic in real time as it was identified and dropped. Over one roughly three-and-a-half-hour window on July 15, the attack arrived in multiple distinct waves, sustained stretches above 100 Gbps for nearly an hour, with the traffic dropped by the firewall spiking to a peak of 406 Gbps at 4:28 PM before the flood tapered off. In total, Path's scrubbing centers filtered out an estimated 89+ terabytes of malicious traffic during that window alone, all without interrupting Plains Internet's legitimate customer traffic.


Crisis Response
This was a live crisis, not a scheduled onboarding
Plains Internet's network was down and under active extortion, so Path Network's crisis response team worked directly with their engineers in real time, from first contact to clean traffic.
T+2HRS, crisis team live
Step 01
Rapid Escalation
Plains Internet contacted Path Network directly while the attack was still active and their network was down. Within 2 hours of that first contact, Path Network's crisis response team was live on a call with the Plains Internet team, working through emergency onboarding in real time rather than a standard provisioning timeline.
Method, GRE tunneling
Step 02
Emergency GRE Tunnel Deployment
Our crisis response team worked directly with Plains Internet's engineers to configure their edge equipment and stand up GRE tunnels, redirecting all of Plains Internet's public internet traffic through Path Network's global scrubbing infrastructure.
Result, traffic clean
Step 03
Global Scrubbing at Scale
Once traffic was rerouted, Path Network's scrubbing centers filtered the malicious UDP reflection traffic out at the edge, far upstream of Plains Internet's network, while allowing legitimate customer traffic through uninterrupted.
The Outcome
With traffic routed through Path Network's scrubbing centers, the attack was neutralized and Plains Internet's network came back online. They never paid the ransom.

“We were dead in the water for 15 hours with no way to fight back. Path Network had our engineers on the phone within two hours and had our traffic clean shortly after — that’s the difference between a bad day and a business-ending one.”
— Andrew Monroe, CEO PlainsInternet
Debrief
Lessons learned & best practices
Speed matters
Every hour of downtime compounds business and reputational damage. Path Network's crisis response process is built to onboard new clients under active attack, not just during calm, planned rollouts.
Never pay the ransom
Extortion-driven DDoS attacks rely on victims having no alternative but to pay. With scrubbing infrastructure in place, that leverage disappears.
GRE tunnels enable fast protection
Rerouting traffic through a scrubbing network via GRE tunnels can be stood up in hours, not days, even for infrastructure that wasn't previously protected.




