Following the arrest of Pavel Durov, founder of the Telegram app, by French authorities on Saturday, August 24, 2024, a series of distributed denial-of-service (DDoS) attacks targeted French websites. These attacks appear to have been coordinated on Telegram, where links to French websites, including those of the Court of Cassation, the Paris Administrative Court, and the Confédération paysanne farmers’ union, were widely shared.
Listen to the interview with Jean-Baptiste Artignan, Partner at BlueSecure:
A call for retaliation on Telegram
Shortly after Durov’s arrest, accused by the French justice system of failing to act against illegal content disseminated through his platform, Telegram users called for digital retaliation. Under the hashtag #FreeDurov, calls to attack French websites were published, inviting participants to join forces and overwhelm the targeted sites with requests.
Diverse targets and varying impacts
Several institutional, media, and commercial websites were affected, including government websites and those of major companies. Some of the attacks caused temporary service disruptions, although most websites returned to normal operation after a few hours. The Confédération paysanne farmers’ union, for example, reported a spike in connection attempts that lasted approximately two hours.
A persistent yet disorganized threat
These attacks, claimed by various pro-Russian or Russia-affiliated hacker collectives, are part of a typical reaction to the arrest of a prominent public figure such as Durov. However, the heterogeneity and lack of coordination of the attacks show that these groups often lack expertise, as reflected in their random choice of targets, ranging from local associations to multinational corporations.
Potential escalation
As these cyberattacks could intensify in the coming days, particularly against European institutions such as the European Court of Human Rights, experts are calling for vigilance. Although these attacks are generally unsophisticated, they could evolve into more aggressive actions, such as data theft or the modification of web pages to spread propaganda (defacement).
The situation remains under close watch, with cybersecurity stakeholders preparing to address a possible escalation of attacks as the Durov case draws international attention.



