John Kelsey Gammell, a former employee at Minnesota-based point-of-sale (POS) services provider Washburn Computer Group, has been sentenced to serve 15 years in prison for engaging in and directing distributed denial of service (DDoS) attacks against U.S. websites.Gammell directed DDoS attacks against websites operated by his past employers, companies that declined to hire him, competitors of his business and law enforcement agencies and courts, according to the U.S. Department of Justice (DOJ). He launched DDoS attacks against these websites from at least July 2015 until about March 2017.Several Minnesota organizations were affected by Gammell's DDoS attacks, including:In addition, Gammell purchased subscriptions from multiple "DDoS-for-hire" companies, including:Gammell used various techniques to avoid detection and circumvent DDoS attack victims' mitigation efforts, and these techniques included:Gammell in January pleaded guilty to one count of conspiracy to commit intentional damage to a protected computer and two counts of being a felon-in-possession, according to DOJ. He also admitted to directing DDoS-for-hire companies to launch cyberattacks.
- Washburn Computer Group.
- Dakota County Technical College.
- Minneapolis Community and Technical College.
- Hennepin County Sheriff's Office.
- VDoS.
- CStress.
- Inboot.
- Booter.xyz.
- IPStresser.
- Deploying IP address anonymization services to hide his identity and location.
- Using multiple DDoS-for-hire services at the same time to amplify his attacks.
- Utilizing spoofed emails to disguise his conduct.
- Submitting cryptocurrency payments for DDoS-for-hire services.
- Leveraging encryption and drive-cleaning tools to conceal digital evidence of his conduct on his computers.
