Full Breakdown
Sir David Davis’s Parliamentary Website Hit by Massive DDoS Attack
4/28/2026, 11:44:57 PM
Incident Overview
On Thursday, Sir David Davis’s website was compromised. Malicious links redirected users to South-East Asian gambling sites before the page was taken down. After a brief restoration, the site suffered a DDoS attack Davis said was “traceable to China”. In 24 hours the attack generated 142 million requests and nearly 800 GB of data, forcing the site offline and prompting Davis to call it “a direct interference with a Member of Parliament carrying out his duties”.
Background: IPSA-Backed Parliamentary Site
The site is hosted by the Independent Parliamentary Standards Authority (IPSA), which provides MPs with a secure platform for constituency communication and parliamentary publications. IPSA is responsible for technical integrity, but security measures were not disclosed publicly.
Key Figures
Key figures are Sir David Davis, MP for Goole and Pocklington; Deputy Speaker Nus Ghani; the Parliamentary Security Department (PSD), which advises on personal device security; and the Parliamentary Digital Service (PDS), which manages parliamentary accounts.
Attack Scale and Technical Details
The DDoS attack generated 142 million requests, consuming about 800 GB of data. The breach inserted gambling-site links before the traffic flood overwhelmed the server. Davis’s office said most traffic was “traceable to China”, though a few hits came from other countries. No data exfiltration was reported.
Parliamentary Responses
Sir David Davis told the Commons the attack interfered with his duties. Deputy Speaker Nus Ghani said she could not discuss defensive details publicly and advised MPs to contact the PSD for personal security and the PDS service desk for parliamentary accounts.
Criticism Over Transparency
Parliamentary officials’ refusal to disclose preventative measures has been described as a source of tension, raising questions about the resilience of IPSA-backed sites.
Conflicting Reports and Gaps
The claim that traffic was traceable to China relies on Davis’s assessment; no independent verification is cited. No statements from Chinese authorities or forensic details are provided, leaving the exact origin and method of the attack unclear.
Verbatim Quotes
- “Last Thursday, my IPSA-provided website was compromised.” — Sir David Davis, MP
- “Malicious links were inserted, redirecting users to South East Asian gambling websites – I guess it could be worse.” — Sir David Davis, MP
- “In just 24 hours, the site was hit with 142 million requests, consuming nearly 800GB of data.” — Sir David Davis, MP
- “I do not think it would be appropriate to discuss the details publicly about preventative action and how members are supported to protect themselves against these kinds of cyber threats.” — Nus Ghani, Deputy Speaker
Outlook
At 09:30 BST on Tuesday the site still showed a maintenance notice. The episode has sparked calls for a review of cyber-security protocols for IPSA-backed sites and for Parliament to clarify safeguards for MPs.
