Australian businesses rely on telecommunications, hosting and cloud services that often share upstream networks. A large distributed denial-of-service (DDoS) attack against one provider can therefore disrupt services used by organisations that were not the original target.
The Australian Signals Directorate (ASD) reported an increase in denial-of-service attacks against Australian organisations in March 2025. A major provider incident in May 2026 was a practical reminder that shared infrastructure can create flow-on risk.
What is a DDoS attack?
A DDoS attack uses many computers, internet-connected devices or other systems to flood an online service with traffic or requests. The aim is to exhaust bandwidth or processing capacity so legitimate users cannot reliably reach the service.
Depending on the target and the mitigation in place, users may see:
- service interruptions or timeouts
- increased latency
- intermittent connectivity
- reduced call quality or unstable sessions
What happened in May 2026?
Synergy Wholesale’s official status notice recorded a DDoS attack beginning at 10:33 am AEST on 23 May 2026. The notice listed its Melbourne and Sydney network components as affected, reported tentative mitigation later that day and marked the incident resolved at 9:12 am AEST on 26 May 2026.
Information Age reported that VentraIP, Synergy Wholesale’s sister company, estimated the attack at more than 600 Gbps and said much of the traffic came from compromised devices using Australian home NBN connections. The same report quoted an NBN spokesperson clarifying that the incident had nothing directly to do with the NBN network, its servers or its connections.
That distinction matters: traffic can originate from compromised devices connected through an access network without the access network itself being breached or being the target.
Why downstream customers can be affected
Telecommunications services depend on interconnected carriers, data centres, cloud platforms, DNS providers and other suppliers. If a shared upstream link or platform is saturated or isolated during mitigation, multiple providers and their customers can experience disruption at the same time.
No provider can guarantee that every sufficiently large or rapidly changing DDoS attack will be absorbed without impact. The practical goal is to reduce the likelihood and duration of disruption through preparation, monitoring, upstream coordination and tested response procedures.
What MyNiche does during an upstream incident
MyNiche monitors notices from relevant suppliers and upstream carriers, coordinates through those providers when an incident affects customer services and communicates verified information as it becomes available. Response actions depend on the affected service and the controls available to the responsible network operator.
A practical resilience checklist
ASD’s current guidance recommends preparing before an attack. For a business, useful checks include:
- Prioritise services: decide which phone, internet, website, email and remote-access services must remain available and what temporary interruption the business can tolerate.
- Question providers: understand their DDoS prevention, upstream arrangements, notification thresholds and pre-approved response actions.
- Monitor availability: use alerts for important services rather than waiting for users to report a problem.
- Keep an out-of-band contact method: retain a mobile or other channel that does not depend on the affected service.
- Maintain and test an incident response plan: include provider contacts, internal responsibilities, customer communications and recovery priorities.
- Review redundancy: consider whether critical locations or functions need a second access method, carrier or hosted service.
- Secure connected devices: patch routers and internet-connected equipment, replace default credentials and use strong unique passwords and multi-factor authentication where available. This helps reduce the chance that your own devices become part of a botnet.
If you notice a service problem
- Check whether the issue affects one user, one site or the whole organisation.
- Record the time, affected service, locations and a specific example such as a failed call or error message.
- Use your alternative contact or connectivity method if the affected service is business-critical.
- Contact MyNiche with those details so the issue can be checked and escalated efficiently.
If you want to review your telecommunications resilience, contact MyNiche to discuss service dependencies, failover options and incident communications.
Fact-checked on 25 July 2026 using Synergy Wholesale’s incident notice, Information Age’s incident report and ASD guidance. This article provides general information, not a guarantee that any particular mitigation will prevent an outage.

