On August 11, 2026, a customer of Nine (an ISP) and Nine's own infrastructure were targeted by a massive DDoS attack peaking at 500–600 Gbit/s, involving the CECbot and Katana botnets using UDP amplification techniques. The attack occurred in waves over three days, affecting multiple services, but caused no data breach or system compromise; mitigation required upstream providers to implement blackholing since the attack volume exceeded Nine's own network capacity.