Cloudflare says it mitigated a 17.2M rps DDoS attack last month, ~3x larger than any previous DDoS attack, targeting a customer in the financial industry
Internet infrastructure company Cloudflare disclosed today that it mitigated the largest volumetric distributed denial of service (DDoS) attack that was recorded to date.
Context & Ripple Effects
Cloudflare's disclosure established an early requests-per-second benchmark for attacks against its customers. Subsequent coverage shows the ceiling kept rising, from a 26M-RPS HTTPS attack against a free-plan customer to dozens of hyper-volumetric attacks in a single weekend.
The later involvement of Amazon and Google in mitigating a 398M-RPS attack tied to a software bug places Cloudflare's incident in a broader contest to absorb and filter exceptional traffic at internet scale.
First-order effects
- Cloudflare's financial-industry customer received mitigation for an attack far above the previously disclosed record, while Cloudflare gained a concrete demonstration of its network-defense capacity.
- The incident raises the operational bar for the customer's own availability planning: protection must handle sudden request floods rather than only ordinary traffic spikes.
Second-order effects
- Other edge and cloud providers face a sharper capacity-and-detection benchmark as customers compare their ability to withstand record-scale request floods.
- Financial-sector buyers have stronger reason to evaluate DDoS protection as a core availability service, favoring providers that can demonstrate mitigation at large scale.
Third-order effects
- Repeated record attacks point toward DDoS resilience becoming concentrated in globally distributed platforms with the capacity to absorb traffic before it reaches a customer's infrastructure.
- As vulnerabilities can amplify attacks across multiple providers, as in the later 398M-RPS incident, coordinated mitigation and rapid patching become as important as individual vendors' filtering capacity.
The trend: DDoS attacks are escalating in volume and exploiting broader infrastructure weaknesses, pushing availability protection toward large-scale network platforms and cross-provider response.