A non-profit non-partisan research organization focused on analyzing foreign interference in Australia, UK, USA, Canada and New Zealand

Canadian Teenager's 2000 Cyber Attack Exposed Critical Internet Infrastructure Vulnerabilities

MafiaBoy's DDoS campaign against major websites demonstrated nascent cyber threats to national security
Posted: March 22, 2026 at 11:24 AM
Last Updated: March 22, 2026 at 11:24 AM
Other
Written by: Morsten Plack (Senior Investigator)
<p>A 15-year-old Canadian hacker operating under the pseudonym <strong>MafiaBoy</strong> executed a coordinated series of distributed denial-of-service attacks in February 2000 that brought down six major websites and caused an estimated <strong>$1.2 billion in damages</strong>. The attacks against Yahoo!, Amazon, eBay, CNN, Dell, and E*Trade marked one of the first demonstrations of how readily available hacking tools could paralyze critical internet infrastructure.</p><p>Michael Calce, later identified as the teenager behind the attacks, launched his campaign on February 7, 2000, beginning with Yahoo!, then the internet's most popular search engine. The attack rendered Yahoo! inaccessible for hours, sending shockwaves through the technology sector and financial markets. Over the following days, Calce systematically targeted other high-profile websites, exploiting vulnerabilities in early internet architecture that lacked robust DDoS protection mechanisms.</p><p>The attacks utilized a network of compromised computers to flood target websites with traffic, overwhelming their servers and making them inaccessible to legitimate users. Security analysts noted that Calce employed relatively unsophisticated tools that were widely available online, highlighting the low barrier to entry for conducting such operations. The teenager operated from his bedroom in Montreal, using compromised university computer networks to amplify his attacks.</p><p>Law enforcement agencies across North America mobilized to investigate what initially appeared to be the work of sophisticated cybercriminals or potentially hostile foreign actors. The FBI, Royal Canadian Mounted Police, and other agencies coordinated an international manhunt that ultimately led to Calce's arrest in April 2000. His capture revealed that one of the most damaging cyber attacks to date had been perpetrated by a single teenager seeking notoriety rather than financial gain or political objectives.</p><p>The incident exposed critical vulnerabilities in internet infrastructure that had national security implications. Government officials and cybersecurity experts warned that if a teenager could bring down major commercial websites, hostile state actors could potentially target more sensitive systems. The attacks prompted increased investment in cybersecurity measures and influenced early discussions about protecting critical digital infrastructure.</p><p>Calce was sentenced to eight months in a youth detention facility and received probation, marking one of the first major prosecutions for cyber attacks. The case established important legal precedents for prosecuting distributed denial-of-service attacks and highlighted the need for international cooperation in cybercrime investigations. The relatively lenient sentence reflected both Calce's age and the nascent state of cyber law at the time.</p>