PlainSite Operator Sought Court Discovery in DDoS Case

Aaron Greenspan has petitioned a federal court to compel records regarding cyberattacks on his research platform.

Updated on Sept. 21, 2026 in Cybersecurity

Bold flat-color editorial illustration featuring an abstract geometric courthouse facade, evoking the gravity of a federal legal proceeding.
Legal researcher Aaron Greenspan has filed a request in U.S. District Court seeking discovery regarding DDoS attacks on his platform, PlainSite. AI Illustration. Upload story photo >

Live Poll

Should lobbying firms be held legally accountable for cyberattacks linked to the governments they represent?

Legal researcher Aaron Greenspan has filed a request in the U.S. District Court for the District of Columbia seeking discovery regarding a series of distributed denial-of-service (DDoS) attacks against his website, PlainSite. The filing targets Bola Tinubu and the lobbying firm DCI Group.

Why it matters

The legal action highlights the intersection of international political lobbying and private digital infrastructure security. Greenspan argues that the timing of the attacks on his research platform correlates with specific legal filings and procedural deadlines.

PlainSite recorded peak DDoS traffic of 1 gigabit per second and 1.8 million packets per second during the incidents. These attacks utilized 110,000 source hosts and pushed server load averages to 500.

The players

Aaron Greenspan

Founder and operator of PlainSite, a legal research website that tracks litigation and corporate filings.

Bola Tinubu

The political figure named in the court discovery request concerning the origin of cyberattacks.

DCI Group

A lobbying and public affairs firm that registered as an agent for the Nigerian government in December 2025.

The details

Distributed denial-of-service (DDoS) attacks — an attempt to crash a server by overwhelming it with a flood of internet traffic from multiple sources — targeted PlainSite starting in April 2025. Greenspan requested six written questions and four requests for admission for Bola Tinubu, alongside a subpoena for documents from DCI Group. The filing also references a $4.5 million payment made to DCI Group in December 2025.

Timeline

  1. April 2025: DDoS attacks on the PlainSite website began.

  2. December 12, 2025: DCI Group received a $4.5 million payment.

  3. August 6, 2026: An intense period of DDoS attacks commenced.

  4. September 9, 2026: Greenspan filed the discovery request with the U.S. District Court.

The Tech Race

This filing underscores the growing legal scrutiny applied to the digital methods used by foreign-funded lobbying operations. It follows a pattern of private researchers attempting to leverage U.S. discovery processes to expose the entities behind persistent network infrastructure threats.

The case illustrates the practical difficulties private operators face in attributing large-scale network disruption to specific political actors. It reinforces the necessity for robust mitigation tools to maintain platform uptime when infrastructure becomes a target for external pressure.

The takeaway

This case tests whether private individuals can use federal discovery to link political lobbying contracts with specific technical attacks. Readers should monitor court records for the judge's ruling on the discovery request, which will determine if DCI Group is compelled to release records.

Further reading

For broader trends in digital security and threat intelligence, see Cybersecurity.

Live Poll

Should lobbying firms be held legally accountable for cyberattacks linked to the governments they represent?