Cloudflare says it stopped a month long DDoS campaign targeting orgs in financial services, internet, and telecommunications sectors, that peaked at 3.8Tbps
During a distributed denial-of-service campaign targeting organizations in the financial services, internet, and telecommunications sectors …
Context & Ripple Effects
Cloudflare's earlier disclosures traced a rising DDoS burden across both application-layer and volumetric attacks, including a 2021 financial-sector attack measured at 17.2 million requests per second. This campaign matters because it extends that pattern to several infrastructure-dependent sectors at once.
The company had also reported dozens of hyper-volumetric attacks exceeding 71 million requests per second in 2023. The new disclosure adds a sustained, multi-target campaign to a record-driven sequence rather than describing an isolated spike.
First-order effects
- Cloudflare's targeted financial-services, internet, and telecom customers receive immediate traffic-scrubbing protection against a campaign that reached 3.8 Tbps, limiting the attackers' ability to exhaust their network capacity.
- The incident reinforces Cloudflare's role as the mitigation layer between large attack traffic and customers whose services depend on continuous internet availability.
Second-order effects
- Organizations in the affected sectors face added pressure to test DDoS resilience, incident response, and provider capacity against prolonged attacks rather than brief peaks.
- Competing security and network providers must demonstrate that their mitigation infrastructure can absorb multi-terabit traffic and sustain protection across a campaign, not merely advertise peak-rate defenses.
Third-order effects
- If attacks continue to scale and persist, DDoS defense is likely to become more concentrated among platforms with globally distributed capacity, raising the strategic importance of provider choice for critical online services.
- The recurring shift between request-rate and bandwidth-rate records suggests resilience planning will need to cover multiple attack vectors, not treat a single headline metric as sufficient.
The trend: Escalating DDoS campaigns are turning high-capacity, always-on traffic mitigation into core infrastructure for internet-facing essential sectors.