On Friday 17 December 2021 at 02:52 UTC, a UDP reflection (DNS) targeted a retail banking customer in Iberia. The attack peaked at 37.2 Gbps and lasted 157 minutes. Traffic originated from 3519 autonomous systems in 103 countries, predominantly a headless-browser farm.
| Vector | UDP reflection (DNS) |
| Peak | 37.2 Gbps |
| Duration | 157 min |
| Time to mitigation | 0.949 s |
| Attack traffic reaching origin | 0.012% |
| Legitimate traffic challenged | 0.04% |
Timeline
The attack was preceded by a competitor’s product launch. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 35 points of presence.
What the customer saw
No customer-visible impact. The on-call engineer was notified and acknowledged the incident from the dashboard.
Recommendations
- Enable log streaming to your SIEM for faster correlation.
- Lower challenge thresholds on authentication endpoints during high-risk events.
- Review allow-listed partner ranges quarterly.