/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Cloudflare says it mitigated a 26M-requests-per-second DDoS attack, the largest HTTPS DDoS attack detected to date, targeting a customer using its Free plan

Internet infrastructure firm Cloudflare said today that it mitigated a 26 million request per second distributed denial-of-service …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Cloudflare had already reported stopping a 17.2M-rps DDoS attack and, more recently, a 15.3M-rps HTTPS attack against a crypto customer. The new incident raises its disclosed HTTPS benchmark while extending that protection to a customer using the Free plan.

The record did not stand for long: related coverage later shows Google Cloud blocking a 46M-rps attack, while Cloudflare subsequently reported dozens of attacks whose largest exceeded 71M rps. The sequence makes attack-handling scale a visible point of competition among infrastructure providers.

First-order effects

  • Cloudflare's Free-plan customer avoided the immediate availability impact of a 26M-rps HTTPS flood, demonstrating that Cloudflare applied its mitigation capacity beyond paid tiers.
  • Cloudflare gains a new public performance benchmark for its HTTPS DDoS defenses, following its earlier disclosed 15.3M-rps event.

Second-order effects

  • Google Cloud and other infrastructure providers face a more explicit benchmark for high-volume HTTPS attack mitigation; Google Cloud's later 46M-rps disclosure shows that scale claims quickly became comparative.
  • Customers evaluating DDoS protection receive evidence that Cloudflare's entry-level service can absorb an attack volume previously associated with major targeted incidents, sharpening the distinction between baseline protection and premium service features.

Third-order effects

  • The later progression to dozens of hyper-volumetric attacks exceeding 71M rps indicates that record-setting request floods are becoming a recurring capacity test rather than isolated events.
  • If this escalation continues, DDoS resilience will increasingly be determined by the size and automation of an infrastructure provider's mitigation network, concentrating the advantage with providers able to operate protection at scale across customer tiers.

The trend: Application-layer DDoS attacks are escalating in disclosed request rates, turning large-scale automated mitigation into a competitive capability for cloud and edge providers.

Discussion

  • @iblametom Thomas Brewster on x
    CloudFlare reports record breaking DDoS attack (HTTPS). “Within less than 30 seconds, this botnet generated more than 212 million HTTPS requests from over 1,500 networks in 121 countries.” https://blog.cloudflare.com/ ...
  • @campuscodi Catalin Cimpanu on x
    Cloudflare said that it mitigated last week a 26M rps DDoS attack. According to the company, the attack is now the largest HTTPS DDoS attack on record, beating a previous 17.2M rps HTTPS DDoS attack recorded last year. https://blog.cloudflare.com/ ... https://twitter.com/...
  • @cloudflare @cloudflare on x
    Last week, Cloudflare automatically detected and mitigated a 26 million request per second DDoS attack — the largest HTTPS DDoS attack on record. https://blog.cloudflare.com/ ...