/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Brian Krebs' site hit by record 620Gbps sustained DDoS attack, nearly twice as big as any previous attack seen by Akamai; the site will be “offline for a while”

Paul Szoldra / Business Insider :

Business Insider Paul Szoldra

Context & Ripple Effects

KrebsOnSecurity going dark under a sustained 620Gbps flood is the moment the DDoS arms race became front-page news: the traffic was nearly double anything Akamai had previously measured against a single target, and it landed on a one-man investigative site rather than a bank or a retailer. The implied message to journalists and researchers who publish on botnet operators is that reporting itself is now a targetable offense.

The record did not stand long in relative terms. Within eighteen months, GitHub absorbed a 1.35Tbps attack amplified through exposed memcached servers, and by 2023 Amazon, Google, and Cloudflare were jointly describing an HTTP-layer flood of 398M requests per second that Google mitigated. Each jump reframed what 'record' means — from raw bandwidth in 2016 to request rates by 2023, as attackers shifted from volumetric saturation to application-layer exhaustion.

First-order effects

  • Krebs loses his publishing platform indefinitely — the site goes fully offline rather than behind a partial mitigation, showing that even well-defended independent sites can be priced out of protection at this scale.
  • Akamai is forced to absorb nearly twice its largest prior attack on a single customer, a direct stress test of its scrubbing capacity and a live demonstration of why premium DDoS protection carries a price floor.

Second-order effects

  • High-risk publishers and small enterprises face a forced choice between expensive always-on CDN/scrubbing contracts and accepting downtime, pushing revenue toward Akamai, Cloudflare, and similar providers.
  • Attackers' success against a hardened target signals that rented botnet capacity had become cheap enough to weaponize against individuals, raising the insurance and defense budget line for any organization doing adversarial reporting or research.

Third-order effects

  • If the pattern holds — 620Gbps in 2016, 1.35Tbps by 2018, terabit-plus floods mitigated routinely thereafter — DDoS defense consolidates structurally around a handful of hyperscale networks with enough aggregate capacity to absorb nation-scale floods, leaving smaller hosts unable to guarantee availability.
  • The escalation also points toward regulation of the amplification supply chain: each record attack has traced to abusable open infrastructure (memcached, then whatever came next), making insecure-by-default devices and services a systemic liability rather than an individual operator's problem.

The trend: DDoS attacks are scaling faster than any single site's defenses, driving the industry toward a few hyperscale mitigation networks while each new record resets expectations for what critical publishers must buy to stay online.