/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Cloudflare says it stopped a month long DDoS campaign targeting orgs in financial services, internet, and telecommunications sectors, that peaked at 3.8Tbps

During a distributed denial-of-service campaign targeting organizations in the financial services, internet, and telecommunications sectors …

BleepingComputer Ionut Ilascu

Context & Ripple Effects

Cloudflare's earlier disclosures traced a rising DDoS burden across both application-layer and volumetric attacks, including a 2021 financial-sector attack measured at 17.2 million requests per second. This campaign matters because it extends that pattern to several infrastructure-dependent sectors at once.

The company had also reported dozens of hyper-volumetric attacks exceeding 71 million requests per second in 2023. The new disclosure adds a sustained, multi-target campaign to a record-driven sequence rather than describing an isolated spike.

First-order effects

  • Cloudflare's targeted financial-services, internet, and telecom customers receive immediate traffic-scrubbing protection against a campaign that reached 3.8 Tbps, limiting the attackers' ability to exhaust their network capacity.
  • The incident reinforces Cloudflare's role as the mitigation layer between large attack traffic and customers whose services depend on continuous internet availability.

Second-order effects

  • Organizations in the affected sectors face added pressure to test DDoS resilience, incident response, and provider capacity against prolonged attacks rather than brief peaks.
  • Competing security and network providers must demonstrate that their mitigation infrastructure can absorb multi-terabit traffic and sustain protection across a campaign, not merely advertise peak-rate defenses.

Third-order effects

  • If attacks continue to scale and persist, DDoS defense is likely to become more concentrated among platforms with globally distributed capacity, raising the strategic importance of provider choice for critical online services.
  • The recurring shift between request-rate and bandwidth-rate records suggests resilience planning will need to cover multiple attack vectors, not treat a single headline metric as sufficient.

The trend: Escalating DDoS campaigns are turning high-capacity, always-on traffic mitigation into core infrastructure for internet-facing essential sectors.

Discussion

  • @eastdakota Matthew Prince on x
    Not all records you're happy about breaking: @Cloudflare recently mitigated the largest ever reported hyper-volumetric #DDoS attack. 3.8 terabits per second (Tbps) and 2.14 billion packets per second (Bpps). Handled automatically any without any customer impact. Details to come. …
  • @dhh @dhh on x
    This is why I love Cloudflare. Owning your own hardware doesn't mean you can't contract with a bodyguard. We do that and it saved our bacon a few months ago when we were attacked.