DDoS Attack Delays Payments to Sellers on Russia’s Wildberries Marketplace
What Happened – Wildberries, Russia’s largest e‑commerce platform, confirmed that a distributed denial‑of‑service (DDoS) attack targeted the systems used to track and withdraw earnings for marketplace sellers. The surge in traffic forced the company’s security controls to throttle payment processing, leaving billions of rubles in seller payouts delayed.
Why It Matters for Trust & Control Assurance
- The incident illustrates the need for continuous monitoring of availability controls and documented incident‑response procedures that can be presented as audit evidence.
- Demonstrating that technical safeguards can be temporarily tightened without compromising fund safety aligns with control objectives around resilience and recovery.
- Mapping the DDoS mitigation response to a single control objective provides a defensible posture across multiple frameworks (e.g., NIST CSF, ISO 27001).
Who Is Affected – Large online marketplaces, payment processors, and third‑party sellers that rely on real‑time settlement services.
Recommended Actions – Review and harden DDoS mitigation controls; test incident‑response playbooks for payment‑system disruptions; collect and retain evidence of mitigation steps to satisfy control‑assurance requirements. Source: The Record
Technical Notes – The attack was a volumetric DDoS that overwhelmed the payment‑tracking subsystem; no vulnerability (CVE) was disclosed, and attribution remains unconfirmed. Source: The Record