/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Brian Krebs' site hit by record 620Gbps sustained DDos attack, nearly twice as big as any previous attack seen by Akamai; the site will be “offline for a while”

Cloud hosting giant Akamai Technologies has dumped journalist Brian Krebs from its servers after his website came under a “record” cyberattack.

Business Insider Paul Szoldra

Context & Ripple Effects

This is the opening data point in a decade-long escalation the corpus now documents end to end: the 620Gbps flood that knocked KrebsOnSecurity offline was nearly double anything Akamai had previously absorbed, and it was enough to make the CDN giant drop the site entirely. Within two years the record had tripled — GitHub's 1.35Tbps memcached-amplified attack in 2018 — and by 2023 Amazon, Google, and Cloudflare were jointly reporting a 398M requests-per-second attack roughly eight times the prior record.

The arc has not bent back: Cloudflare disclosed a 7.3Tbps attack in mid-2025 and then a 31.4Tbps Aisuru/Kimwolf botnet attack in December 2025, the largest ever publicly disclosed — roughly fifty times the size of the flood that ended Krebs' hosting in 2016. The 2016 episode matters because it established the pattern that still holds: record attacks are survivable, but only for targets whose providers can afford to absorb them.

First-order effects

  • Akamai removed KrebsOnSecurity from its network after the attack, leaving the security journalist — whose reporting regularly antagonizes botnet operators — without hosting and offline indefinitely.
  • The attack set a new record for Akamai, nearly twice any previous flood the company had mitigated, forcing an unplanned cost decision about defending a single high-profile customer.

Second-order effects

  • Hosting and CDN providers now face a pricing problem the corpus keeps repeating: mitigation at record scale is only economical for the largest players, pushing security researchers and small publishers toward whichever provider can absorb multi-hundred-gigabit floods.
  • Each disclosed record — GitHub's memcached abuse, the 2023 HTTP/2-era flaw, the Aisuru botnet — hands attackers a new amplification technique, so every mitigation disclosure doubles as a playbook for the next record attempt.

Third-order effects

  • DDoS defense is consolidating into a scale game: by 2023 Amazon, Google, and Cloudflare were the ones jointly disclosing and mitigating record attacks, a structure where only hyperscale networks can credibly promise availability.
  • If the trajectory from 620Gbps in 2016 to 31.4Tbps in 2025 continues, botnet-driven floods stop being a nuisance category and become an availability risk priced into where any high-visibility site is allowed to host.

The trend: DDoS attack sizes have escalated roughly fifty-fold in under a decade, concentrating credible mitigation in a handful of hyperscale networks while record disclosures keep handing attackers new amplification techniques.