🔴 [LATEST] SERVER KILLERS: REVEALED, 3 U.S. GOVERNMENT SITES DOWN    ◆    🔴 [LATEST] 313 TEAM ANNOUNCES SAUDI CIVIL DEFENSE OFFICIAL SITE IS DOWN    ◆    🔴 [LATEST] DDOS RIPPERSEC REVEALED: 10 PIECES OF EVIDENCE THAT TV7 ISRAEL NEWS WAS PARALYZED    ◆    🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN

~/ › ddos › article

ddos

Server Killers: Revealed, 3 U.S. Government Sites Down

> By Clara | Oct 07, 2026 | 7 min read

Server Killers announced attacks on three United States government sites on Thursday (17 September 2026), and check-host reports show that all three sites failed to open from nearly all of the visible monitoring nodes. The named sites are Science.gov, OSTI.gov, which belongs to the Department of Energy (DOE), and EFTPS.gov, the federal tax payment system under the Department of the Treasury.

The numbers are clear-cut. Of the 117 check results fully visible across the three reports, only one answered with a 200 (OK) code: the Vancouver, Canada node for EFTPS, with a response time of 6.49 seconds. All the rest recorded Connection timed out, including two nodes in Jakarta.

Figure 1 : Server Killers logo with a hooded silhouette, a binary-code shield, and the Russian flag
Figure 1 : Server Killers logo with a hooded silhouette, a binary-code shield, and the Russian flag
> TABLE_OF_CONTENTS [toggle]

Sequence of Disruptions from EFTPS to OSTI

EFTPS was checked first. The check-host report for www.eftps.gov/eftps/ was recorded on Thursday 17 September 2026 at 14:10 UTC, equivalent to 21:10 WIB (Western Indonesia Time). This free Department of the Treasury service is used to pay federal taxes online, from income tax and employment tax to excise tax.

In a browser, the EFTPS page displays ERR_CONNECTION_CLOSED, meaning the connection was abruptly closed from the server side. Check-host recorded Connection timed out at 40 of the 41 fully visible nodes, from Vienna, São Paulo, and Tokyo to Singapore and Stockholm. Only Vancouver got through.

Figure 2 : Server Killers and the EFTPS.gov disruption, check-host records only Vancouver responding with 200 (OK)
Figure 2 : Server Killers and the EFTPS.gov disruption, check-host records only Vancouver responding with 200 (OK)

About 44 minutes later, at 14:54 UTC (21:54 WIB), it was Science.gov’s turn. The Server Killers post for this site carries the note Duration: 1 hour and the hashtag #ServerKillers. All 39 monitoring nodes in the screenshot recorded Connection timed out.

Figure 3 : Server Killers and the Science.gov disruption, all check-host nodes record Connection timed out
Figure 3 : Server Killers and the Science.gov disruption, all check-host nodes record Connection timed out

The last report, for OSTI.gov, was recorded at 17:57 UTC, or 00:57 WIB on Friday 18 September. OSTI is the DOE office that collects, stores, and opens public access to scientific information from DOE-funded research. In its post, the group wrote “Full Infrastructure is strongly downed”, then linked a separate page whose title names some of the affected domains.

The result was the same: of the 37 fully visible nodes, every one failed to connect within the time limit. The two targets are also related, because the official DOE page lists Science.gov as one of the resources managed by OSTI.

Figure 4 : Server Killers and the disruption of OSTI.gov, owned by the U.S. Department of Energy, on 17 September 2026
Figure 4 : Server Killers and the disruption of OSTI.gov, owned by the U.S. Department of Energy, on 17 September 2026

Who Is Server Killers and What Is Its Attack Pattern

The Server Killers logo combines a hooded silhouette, an orange shield over a binary-code background, Saint Basil’s Cathedral, and the Russian flag. Target descriptions are written in English, and some posts come with a Russian translation. The group’s location and number of members cannot be confirmed from the available evidence.

Threat intelligence firm Cyjax notes that Server Killers has been active since at least early August 2023, focuses on DDoS attacks, and frequently targets Ukraine and the countries that support it. Its latest campaign targets Norway: as of 8 September 2026, 36 targets had been announced, accompanied by check-host links, some stating durations of between one and five hours.

ZeroFox adds that the group announced attacks on the United Kingdom, Poland, and Denmark, then on Spanish government sites in February 2026. The Server Killers posts about these three U.S. sites do not state any motive or demand.

The Server Killers channel has a small reach. According to Cyjax, its new channel had only 112 subscribers in early September 2026, consistent with the 56, 44, and 58 views on the three posts we reviewed.

For context on similar DDoS attacks, also read https://cyberasia.io/articles/

How to Read Check-Host Results

Check-host tests a single address from many locations at once. Connection timed out means the server did not respond within the time limit, while OK with a 200 code means the page opened normally. This report is a snapshot of a single moment, not a record of how long the disruption lasted.

Some things are not visible. The screenshots do not include HTTP codes such as 502, 504, or 429, so the attack vector cannot yet be determined: an HTTP request flood at layer 7 and a packet flood at the network layer can both produce this pattern. The only duration information, one hour for Science.gov, comes from Server Killers itself.

The list of monitoring nodes is also cut off in the middle of the alphabet, so results from locations in the United States do not appear. That matters, because the main users of all three sites are there. Simultaneous failures from Europe, Brazil, Japan, and Indonesia signal a widespread problem, but filtering of international traffic by the site operators cannot yet be ruled out as an explanation.

Impact on Public Services and Tax Payments

The evidence posted by Server Killers shows only an availability disruption, not a breach. The material reviewed contains no data samples, credential lists, or signs of access to internal systems.

EFTPS is the most sensitive because it involves tax obligations. The Bureau of the Fiscal Service under the Department of the Treasury states that taxpayers can pay through the eftps.gov site, by phone, or through intermediaries such as tax professionals, payroll services, and financial institutions. The phone and intermediary routes serve as backups when the online site is hard to open.

The case is different for Science.gov and OSTI.gov. Both are research access portals, so what is disrupted is access to scientific literature for researchers, students, and the public, not the operation of vital services.

For readers in Indonesia, two Jakarta monitoring nodes recorded the same failure in all three reports, so access from inside the country was likely disrupted as well at the time of each check.

As of this writing, we found no official statement from any of the three agencies. Three things are worth monitoring: statements from the Department of the Treasury and DOE, when services recover, and whether Server Killers adds more U.S. targets after its wave against Norway.

Emergency Steps for Admins Under DDoS Attack

The joint guidance from CISA, FBI, and MS-ISAC urges organizations to understand the DDoS protection their internet and cloud providers already have before an attack arrives. For admins already hit by a traffic surge like this, the following order of work makes sense:

  • Contact the ISP, hosting provider, or CDN to request upstream traffic filtering.
  • Apply rate limiting and WAF rules to the heaviest paths, such as search, login, and payment.
  • Serve static pages from cache or CDN, and temporarily turn off non-essential features.
  • Keep access and firewall logs: source addresses, user-agents, and the URL paths being flooded.
  • Separate critical services, such as authentication and payment, from the information site so that an attack on one part does not take everything down.
  • Put up a status page and prepare alternative channels for users.

FAQ

Q1 : Did the Server Killers attack leak tax data or personal data of U.S. citizens?

The available evidence does not show a leak. All that is visible is sites that cannot be opened, not copies of a database or access to internal panels. This pattern is common in DDoS attacks, which target the availability of a service, not the contents of its storage.

Q2 : Did tax payments through EFTPS stop as well?

That cannot be confirmed yet. The 14:10 UTC timestamp only shows that the site could not be opened from nearly all nodes at that moment, not how long the disruption lasted or the condition of the payment system behind it. Taxpayers should use other official channels and monitor announcements from the operator.

Q3 : How can you tell a DDoS attack from an ordinary server outage?

Look at the pattern. Simultaneous timeouts in many locations, a surge of requests from many IP addresses, or a single URL path being flooded point to DDoS. An ordinary outage is more often accompanied by consistent 5xx codes and traces of configuration or hardware changes in the logs.

Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.

> INTELLIGENCE_NOTICE

The report above detailing Server Killers: Revealed, 3 U.S. Government Sites Down is part of the CyberAsia public archive. For organizations requiring real-time attack telemetry, check-host latency records, and edge firewall mitigation strategies for ddos incidents, please refer to our Secure Drop or contact the research desk.

> ABOUT_AUTHOR: Clara

Threat Intelligence Analyst at CyberAsia covering regional hacktivist activity, distributed denial-of-service (DDoS) campaigns, and underground Telegram monitoring across the Asia-Pacific region.

> related_intel --suggest