Cloudflare mitigated dozens of hyper-volumetric DDoS attacks on its customers last weekend; the largest exceeded 71M rps, 35%+ higher than the previous record
This weekend, Cloudflare blocked what it describes as the largest volumetric distributed denial-of-service (DDoS) attack to date.
Context & Ripple Effects
Cloudflare had already reported successive record application-layer attacks, from a 17.2M-rps attack against a financial-sector customer to a 26M-rps HTTPS attack against a Free-plan customer. The new incident pushes that observed ceiling beyond 71M rps while affecting dozens of customers rather than a single disclosed target.
The coverage establishes that attack scale is rising across customer segments and service tiers, making network-scale mitigation capacity a core part of Cloudflare’s customer proposition.
First-order effects
- Cloudflare’s targeted customers avoided the immediate availability impact of dozens of hyper-volumetric attacks because its network absorbed and filtered the traffic.
- Cloudflare must provision and operate defenses for a request-rate record more than 35% above the prior benchmark, raising the operational bar for its DDoS service.
Second-order effects
- Websites evaluating edge-security providers gain a sharper capacity benchmark, putting pressure on rival providers to demonstrate mitigation at comparable request rates.
- The earlier attack on a customer using Cloudflare’s Free plan makes protection capacity relevant beyond premium enterprise deployments, increasing the importance of how providers allocate defensive capacity across tiers.
Third-order effects
- Repeated record-sized attacks point to DDoS resilience becoming a scale advantage: providers with larger, well-managed edge capacity can make baseline protection more broadly available, while smaller operators face a tougher capacity-allocation problem.
- The later 398M-RPS attack mitigated by Amazon, Google, and Cloudflare indicates that application-layer attack ceilings can move rapidly, favoring defenses that evolve with protocol-level vulnerabilities rather than static traffic thresholds.
The trend: DDoS defense is becoming an edge-scale capacity and protocol-security competition as record request rates repeatedly reset the required mitigation baseline.