Summary
- Mapping Media Freedom was hit by a DDoS attack on 1 October and temporarily became unavailable.
- The platform has been restored, and there is currently no indication that personal data was affected.
- ECPMF is continuing to investigate the source and circumstances of the attack.
A distributed denial of service attack temporarily disrupted access to a European platform used to document threats and violations against journalists and media workers.
The European Centre for Press and Media Freedom said its Mapping Media Freedom platform was deliberately overwhelmed on 1 October, making the service temporarily unavailable to the public.
Technical measures have since restored access, and ECPMF said current information provides no indication that personal data was affected. The organisation is continuing to investigate the incident and has not attributed the attack to a particular individual, state or group.
Mapping Media Freedom records incidents affecting journalists across Europe, creating a shared evidence base covering violence, intimidation, legal pressure and other forms of interference with media activity.
A DDoS attack can produce serious disruption without an attacker entering the underlying application or obtaining stored information. Instead, systems are flooded with requests or network traffic until legitimate users can no longer reach the service or supporting infrastructure becomes overwhelmed.
Availability therefore becomes the target in its own right. Although confidentiality and integrity tend to dominate breach reporting, preventing users from reaching a public service can be enough to interrupt its purpose even when the underlying records remain intact.
For Mapping Media Freedom, public accessibility is central to the platform’s value because journalists, researchers and civil society organisations use the database to understand threats across multiple European countries. Temporary loss of access does not erase those records, but it prevents them from being consulted while mitigation is under way.
ECPMF has not disclosed the volume of traffic directed at the platform, the infrastructure used to generate it or the defensive measures required to restore service. Investigators have also not established a public link between the attack and any particular entry, country or political event.
Those gaps leave motive and attribution unresolved. The organisation’s work on press freedom does not by itself establish that the attack was politically directed, and no evidence currently connects it with a state actor or identifiable campaign.
Civil society organisations nevertheless present attractive targets for disruption because they often combine public visibility with smaller technology teams and infrastructure budgets than major commercial platforms. An availability attack can therefore impose mitigation and recovery costs even when it does not produce a data breach.
DDoS services can also be assembled from compromised devices or rented criminal infrastructure, allowing attackers to generate large volumes of traffic without maintaining an extensive bespoke network of their own.
European governments and cybersecurity agencies have faced repeated denial of service campaigns against public bodies, media organisations and other internet-facing services during periods of political tension, although each incident requires its own evidence before being connected with a broader operation.
The Mapping Media Freedom attack remains narrower in confirmed scope. Public access was disrupted, service has been restored and investigators currently see no indication that personal information was affected.
ECPMF said it would notify individuals directly if subsequent investigation shows that their data was involved. Until then, the case is primarily an availability incident affecting an information service rather than a confirmed compromise of the records behind it.
The recovery restores the platform’s immediate function, while the unresolved source of the attack leaves ECPMF with the separate task of understanding whether its defences need to change for future attempts against the same service.





