Brian Krebs' site hit by record 620Gbps sustained DDoS attack, nearly twice as big as any previous attack seen by Akamai; the site will be “offline for a while”
Paul Szoldra / Business Insider :
Context & Ripple Effects
KrebsOnSecurity going dark under a sustained 620Gbps flood is the moment the DDoS arms race became front-page news: the traffic was nearly double anything Akamai had previously measured against a single target, and it landed on a one-man investigative site rather than a bank or a retailer. The implied message to journalists and researchers who publish on botnet operators is that reporting itself is now a targetable offense.
The record did not stand long in relative terms. Within eighteen months, GitHub absorbed a 1.35Tbps attack amplified through exposed memcached servers, and by 2023 Amazon, Google, and Cloudflare were jointly describing an HTTP-layer flood of 398M requests per second that Google mitigated. Each jump reframed what 'record' means — from raw bandwidth in 2016 to request rates by 2023, as attackers shifted from volumetric saturation to application-layer exhaustion.
First-order effects
- Krebs loses his publishing platform indefinitely — the site goes fully offline rather than behind a partial mitigation, showing that even well-defended independent sites can be priced out of protection at this scale.
- Akamai is forced to absorb nearly twice its largest prior attack on a single customer, a direct stress test of its scrubbing capacity and a live demonstration of why premium DDoS protection carries a price floor.
Second-order effects
- High-risk publishers and small enterprises face a forced choice between expensive always-on CDN/scrubbing contracts and accepting downtime, pushing revenue toward Akamai, Cloudflare, and similar providers.
- Attackers' success against a hardened target signals that rented botnet capacity had become cheap enough to weaponize against individuals, raising the insurance and defense budget line for any organization doing adversarial reporting or research.
Third-order effects
- If the pattern holds — 620Gbps in 2016, 1.35Tbps by 2018, terabit-plus floods mitigated routinely thereafter — DDoS defense consolidates structurally around a handful of hyperscale networks with enough aggregate capacity to absorb nation-scale floods, leaving smaller hosts unable to guarantee availability.
- The escalation also points toward regulation of the amplification supply chain: each record attack has traced to abusable open infrastructure (memcached, then whatever came next), making insecure-by-default devices and services a systemic liability rather than an individual operator's problem.
The trend: DDoS attacks are scaling faster than any single site's defenses, driving the industry toward a few hyperscale mitigation networks while each new record resets expectations for what critical publishers must buy to stay online.