NewsAnonimo News

YouTube Taken Down by DDoS: Ghost Squad Hackers Claimed the Outage, and a Fictional Spy Channel Claimed It Too

The YouTube streaming service had a downtime of one to two hours during Wednesday evening US time. Millions of people around the globe weren’t able to stream videos on the service because of the disruption. These many countries and more include The United States, Europe, South American, and the Asia Pacific.

A group of hacktivists known as “Ghost Squad Hackers” (GSH) claims to be responsible for the downtime caused on the Google-owned Youtube servers. GSH Tweeted that they were responsible for the disruption on Twitter Wednesday morning, self-boasting about it, but without giving valid proof of their claim.

So far Google has kept their mouth shut regarding the cause of the disruption. YouTube has since been restored and is up and running; YouTube tweeted that the issue has been resolved.

It is important to notify our readers that GSH has a history of cyber attacks, including the CNN servers in previous operations. They are also known to have defaced numerous Afghan websites during 2016. These defaces included the Bank of Israel and the website owned by the Israeli Prime Minister.

Their preferred tactics are to perform distributed denial of service attacks, or DDos. It has been suggested by security analysts that these same cyber warfare tactics could have been used by them to disrupt YouTube on Wednesday.

Some twitter users had reports of services such as YouTube, YouTube Music, and YouTube TV being down for nearly two hours on Wednesday. They say the homepage of YouTube was either displaying no videos, or showed a network error when accessed with the mobile. It also affected computer users.

However, it may have been ICANN according to ICANN.org. Here is the start of the ICANN statement:

LOS ANGELES – 15 October 2018 – The Internet Corporation for Assigned Names and Numbers (ICANN) has determined that the first-ever changing of the cryptographic key that helps protect the Domain Name System (DNS) has been completed with minimal disruption of the global Internet. It was the first time the key has been changed since it was first put in use in 2010.

Adding to the confusion, Ghost Squad Hackers were not the only ones taking credit. A separate group calling itself “Project Zorgo,” which had been positioning itself online as an anti-YouTube collective, also claimed it had knocked the platform offline that same night, even posting a screenshot of a blank YouTube page as supposed evidence. Neither claim was ever backed by technical proof, and to this day no party has produced verifiable evidence that they caused the outage. The competing boasts only underscore a recurring problem with hacktivist outage claims: taking credit costs nothing, while substantiating it is another matter entirely.

What is clear is that Google never publicly attributed the disruption to any hacking group. The most grounded reading, shared by independent security observers, is that the simultaneous failure of YouTube, YouTube Music, and YouTube TV pointed toward an internal fault or infrastructure issue on Google’s side rather than an external DDoS campaign. When a single company’s tightly linked services all go dark at once, a back-end misconfiguration is usually a more plausible explanation than a flood of outside traffic.

The episode also fits a much broader pattern. Over the years, major online platforms including The New York Times, Spotify, Netflix, CNN, and Fox News have all been knocked offline at various points by DDoS exploits or internal failures, and the public is frequently left guessing at the true cause while opportunistic groups rush to claim credit. For readers, the takeaway is to treat any unverified “we did it” announcement with healthy skepticism until hard evidence appears.

For more background on how distributed denial of service campaigns and hacktivist claims unfold, see The AEGIS Alliance’s ongoing coverage in Anonimo News.

What the competing claims look like once the series is separated from the outage

The Project Zorgo post was not a technical report. On October 17, 2018, the account @ProjectZorgo wrote that it had “successfully taken YouTube offline,” and attached a screenshot of a blank page. The same account’s YouTube video, posted around the outage, told viewers that a “doomsday date” code had been tested and that the site had been forced down for more than an hour.

YouTube is Down - Doomsday Date Test Success

Read the video the way an investigator would read a claim of intrusion. The description lists Chad Wild Clay and Vy Qwaint as “TARGET Channels,” points people at an Instagram, and includes an affiliate link for stock music. The account published a handful of posts in August, September, and October 2018, then stopped behaving like an operational crew. Project Zorgo is the fictional hacker villain of a children’s spy series those creators were building on YouTube. Timing a villain video to a real outage is a content stunt. It is not evidence of a distributed denial-of-service campaign, and it does not belong in the same file as a group that has actually spent years claiming DDoS operations. Ghost Squad Hackers at least has a history of operations people can go look up. Project Zorgo has a plot.

The ICANN theory has a similar problem of scale. The root key rollover announced on October 15, 2018, was a global Domain Name System change, the first since 2010, and ICANN said it finished with minimal disruption. A failure of that kind would show up as DNSSEC validation errors across many unrelated sites. What users described on the night of October 16 was narrower: YouTube, YouTube Music, and YouTube TV misbehaving together, homepages empty or throwing a network error, while the rest of the web kept resolving. That pattern fits one company’s stack. It does not fit a root-key event.

Google’s habit, when it knows the cause, is to name the subsystem. That habit is the control case. On the night of February 17, 2026, YouTube failed again across the homepage, the app, YouTube Music, YouTube Kids, and parts of YouTube TV. Downdetector lit up. Within hours the company said an issue in the recommendations system had stopped videos from appearing on those surfaces, and that a smaller set of YouTube TV login failures was part of the same break. Deadline recorded the sequence. TechRadar’s live notes tracked the spike and the recovery. TeamYouTube told users the recommendations fault was fixed and that the main surfaces were back.

Nobody credible needed a hacker brand to explain that night, because the operator published the fault. The October 2018 silence is the interesting residue. Google restored the service and did not attribute the hour or two of darkness to Ghost Squad Hackers, to Project Zorgo, or to ICANN. No traffic graph, no command-and-control address, and no booter log has surfaced since to fill the gap. A real flood large enough to stall YouTube would have left traces at Google’s edge and at the transit providers in front of it. Those traces were not handed to the public, and the crews who wanted the credit did not have them either.

The AEGIS Alliance draws a hard line here. A tweet is not a packet capture. A screenshot of an error page proves only that the page errored. Readers who want the longer pattern of unverified credit-taking, and of the rare cases where a company does document a network it actually dismantled, can follow Hacker News and the reporting on the shadow network Google said it took apart after finding phones quietly lending out their connections. The October 2018 question stands where the original reporting left it. Ghost Squad Hackers said they did it. Google never said they did.

Kyle James Lee
Maggiore proprietario dell'alleanza aeguale. Ho studiato al college per le arti dei media, lo sviluppo del gioco. I Talenti interessa scrittore / scrittore di articoli, Graphic Design, Photoshop, Web Design e sviluppo, produzione Video, Social Media, ecommerce.
Pulsante per tornare all'inizio