Brian Krebs' site hit by record 620Gbps sustained DDos attack, nearly twice as big as any previous attack seen by Akamai; the site will be “offline for a while”
Cloud hosting giant Akamai Technologies has dumped journalist Brian Krebs from its servers after his website came under a “record” cyberattack.
Context & Ripple Effects
This is the opening data point in a decade-long escalation the corpus now documents end to end: the 620Gbps flood that knocked KrebsOnSecurity offline was nearly double anything Akamai had previously absorbed, and it was enough to make the CDN giant drop the site entirely. Within two years the record had tripled — GitHub's 1.35Tbps memcached-amplified attack in 2018 — and by 2023 Amazon, Google, and Cloudflare were jointly reporting a 398M requests-per-second attack roughly eight times the prior record.
The arc has not bent back: Cloudflare disclosed a 7.3Tbps attack in mid-2025 and then a 31.4Tbps Aisuru/Kimwolf botnet attack in December 2025, the largest ever publicly disclosed — roughly fifty times the size of the flood that ended Krebs' hosting in 2016. The 2016 episode matters because it established the pattern that still holds: record attacks are survivable, but only for targets whose providers can afford to absorb them.
First-order effects
- Akamai removed KrebsOnSecurity from its network after the attack, leaving the security journalist — whose reporting regularly antagonizes botnet operators — without hosting and offline indefinitely.
- The attack set a new record for Akamai, nearly twice any previous flood the company had mitigated, forcing an unplanned cost decision about defending a single high-profile customer.
Second-order effects
- Hosting and CDN providers now face a pricing problem the corpus keeps repeating: mitigation at record scale is only economical for the largest players, pushing security researchers and small publishers toward whichever provider can absorb multi-hundred-gigabit floods.
- Each disclosed record — GitHub's memcached abuse, the 2023 HTTP/2-era flaw, the Aisuru botnet — hands attackers a new amplification technique, so every mitigation disclosure doubles as a playbook for the next record attempt.
Third-order effects
- DDoS defense is consolidating into a scale game: by 2023 Amazon, Google, and Cloudflare were the ones jointly disclosing and mitigating record attacks, a structure where only hyperscale networks can credibly promise availability.
- If the trajectory from 620Gbps in 2016 to 31.4Tbps in 2025 continues, botnet-driven floods stop being a nuisance category and become an availability risk priced into where any high-visibility site is allowed to host.
The trend: DDoS attack sizes have escalated roughly fifty-fold in under a decade, concentrating credible mitigation in a handful of hyperscale networks while record disclosures keep handing attackers new amplification techniques.