/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Cloudflare says it mitigated a 17.2M rps DDoS attack last month, ~3x larger than any previous DDoS attack, targeting a customer in the financial industry

Internet infrastructure company Cloudflare disclosed today that it mitigated the largest volumetric distributed denial of service (DDoS) attack that was recorded to date.

The Record Catalin Cimpanu

Context & Ripple Effects

Cloudflare's disclosure established an early requests-per-second benchmark for attacks against its customers. Subsequent coverage shows the ceiling kept rising, from a 26M-RPS HTTPS attack against a free-plan customer to dozens of hyper-volumetric attacks in a single weekend.

The later involvement of Amazon and Google in mitigating a 398M-RPS attack tied to a software bug places Cloudflare's incident in a broader contest to absorb and filter exceptional traffic at internet scale.

First-order effects

  • Cloudflare's financial-industry customer received mitigation for an attack far above the previously disclosed record, while Cloudflare gained a concrete demonstration of its network-defense capacity.
  • The incident raises the operational bar for the customer's own availability planning: protection must handle sudden request floods rather than only ordinary traffic spikes.

Second-order effects

  • Other edge and cloud providers face a sharper capacity-and-detection benchmark as customers compare their ability to withstand record-scale request floods.
  • Financial-sector buyers have stronger reason to evaluate DDoS protection as a core availability service, favoring providers that can demonstrate mitigation at large scale.

Third-order effects

  • Repeated record attacks point toward DDoS resilience becoming concentrated in globally distributed platforms with the capacity to absorb traffic before it reaches a customer's infrastructure.
  • As vulnerabilities can amplify attacks across multiple providers, as in the later 398M-RPS incident, coordinated mitigation and rapid patching become as important as individual vendors' filtering capacity.

The trend: DDoS attacks are escalating in volume and exploiting broader infrastructure weaknesses, pushing availability protection toward large-scale network platforms and cross-provider response.

Discussion

  • @therecord_media @therecord_media on x
    A botnet of more than 20,000 infected devices was used to launch the largest volumetric distributed denial of service (DDoS) attack that was ever recorded, according to Cloudflare https://therecord.media/...
  • @jgrahamc John Graham-Cumming on x
    Also multiple attacks over 1Tbps. https://twitter.com/... https://twitter.com/...
  • @eastdakota Matthew Prince on x
    Incredible that @Cloudflare stopped the largest DDoS attack in history and it was just another day at the office. I wasn't even aware of the scale until I read this post. https://blog.cloudflare.com/ ...
  • @bjerreroland Benjamin Roland Bjerre on x
    Imagine having such superior security product that you won't even notice that you are stopping the biggest DDoS attack in history. $NET @aktieuniverset https://twitter.com/...