Irish National Lottery plagued by DDoS attack
Both the website and ticket issuing machines were affected


The Irish National Lottery has been hit by a DDoS attack, with hackers bringing down the website and ticket machines on the day of the biggest draw for the last 18 months.
Criminals were able to knock operator Premier Lotteries Ireland (PLI) offline for two hours on Wednesday, meaning customers trying to buy tickets for the 12 million (9 million) were unable to take part.
However, the organisers were undeterred, despite missing out on probably thousands of Euros of ticket sales and the midweek draw still went ahead. No one went on to win the lottery.
"Indications are that this morning's technical issues were as a result of a DDoS attack affecting our communications networks," a statement from PLI said.
"The issues were resolved by the National Lottery's DDoS protection systems, limiting disruption and restoring all operations within two hours. This incident is still under investigation. However, we can confirm that at no point was the National Lottery gaming system or player data affected."
Security commentators said it wasn't surprising a lottery website was attacked, because they naturally see peaks of traffic at certain times - especially when there's a much larger jackpot than usual - which puts extra pressure on the IT infrastructure behind such websites and systems naturally.
Adding a DDoS attack on top, even if it's not serious, will cause the site to crash much sooner than a website that has been designed to deal with a high volume of requests at all times.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
However, John Graham-Cumming at DDoS-protection company Cloudflare told the BBC the thing to note was the machines used to issue lottery tickets were also affected, meaning there was no way anyone could purchase a ticket for the draw.
"They said you couldn't buy tickets from the ticket machines, which is really interesting, it's not just the website - it would be quite interesting to understand why that happened," he said.

Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.
-
Asus ZenScreen Fold OLED MQ17QH review
Reviews A stunning foldable 17.3in OLED display – but it's too expensive to be anything more than a thrilling tech demo
By Sasha Muller
-
How the UK MoJ achieved secure networks for prisons and offices with Palo Alto Networks
Case study Adopting zero trust is a necessity when your own users are trying to launch cyber attacks
By Rory Bathgate
-
UK crime fighters wrangle “several thousand” potential cyber criminals in DDoS-for-hire honeypot
News The sting follows a recent crackdown on DDoS-for-hire services globally
By Ross Kelly
-
US begins seizure of 48 DDoS-for-hire services following global investigation
News Six people have been arrested who allegedly oversaw computer attacks launched using booters
By Zach Marzouk
-
Will triple extortion ransomware truly take off?
In-depth Operators are now launching attacks with three extortion layers, but there are limitations to this model
By Connor Jones
-
GoDaddy web hosting review
Reviews GoDaddy web hosting is backed by competitive prices and a beginner-friendly dashboard, and while popular, beware of hidden prices
By Daniel Blechynden
-
Japan investigates potential Russian Killnet cyber attacks
News The hacker group has said it’s revolting against the country’s militarism and that it’s “kicking the samurai”
By Zach Marzouk
-
LockBit hacking group to be 'more aggressive' after falling victim to large-scale DDoS attack
News The ransomware group is currently embroiled in a battle after it leaked data belonging to cyber security company Entrust
By Connor Jones
-
Record for the largest ever HTTPS DDoS attack smashed once again
News The DDoS attack lasted 69 minutes and surpassed the previous record of 26 million RPS
By Praharsha Anand
-
Cloudflare unveils new One Partner Program with zero trust at its core
News Cloudflare CEO Matthew Prince says the initiative aims to take the complexity out of zero trust architecture
By Daniel Todd