World's largest DDoS attack reached 400Gbps, says Arbor Networks
NTP amplification fuelling era of super-massive DDoS — Share Twitter Facebook LinkedIn Google Plus Email this article — Some time in December 2014 an unnamed ISP experienced an NTP reflection DDoS attack that peaked …
Context & Ripple Effects
Arbor Networks' disclosure that a December 2014 NTP reflection attack peaked at 400Gbps against an unnamed ISP was, at the time, a world record — and its warning that NTP amplification would fuel 'super-massive' DDoS proved prescient. Within two years, Brian Krebs' site was hit by a sustained 620Gbps attack nearly twice anything Akamai had seen before.
A decade on, the arc holds: Cloudflare mitigated a 7.3Tbps attack in mid-2025 and then a 31.4Tbps Aisuru/Kimwolf botnet attack in late 2025, while Amazon, Google, and Cloudflare jointly disclosed a volumetric record driven by a new protocol flaw rather than raw bandwidth. Each new amplification vector — from open NTP resolvers to fleets of 100K+ misconfigured middlebox servers — resets the ceiling.
First-order effects
- The unnamed target ISP had to absorb junk traffic at 400Gbps, forcing real-time traffic scrubbing and making Arbor's attack telemetry immediately valuable to every operator sizing its own defenses.
Second-order effects
- Every record-setting reflection technique pushes carriers and content networks toward upstream filtering and outsourced mitigation, shifting the defense market toward high-capacity scrubbing providers like Cloudflare, Akamai, Google, and Amazon — the same firms later disclosing the biggest attacks.
Third-order effects
- The pattern Arbor flagged in 2015 — attackers renting amplification from misconfigured internet infrastructure rather than building botnets big enough on their own — has become structural: each new exploitable protocol (NTP, then middlebox reflection, then application-layer flaws) reopens the arms race regardless of defensive progress, with disclosed records climbing roughly two orders of magnitude in a decade.
The trend: DDoS attacks keep scaling by hijacking misconfigured internet infrastructure as amplifiers, and mitigation keeps consolidating into the hyperscale scrubbing networks best positioned to absorb them.