On Tuesday 10 January 2023 at 05:38 UTC, a memcached amplification targeted a video streaming customer in Western Europe. The attack peaked at 332.0 Gbps and lasted 184 minutes. Traffic originated from 3220 autonomous systems in 58 countries, predominantly hijacked home routers.
| Vector | memcached amplification |
| Peak | 332.0 Gbps |
| Duration | 184 min |
| Time to mitigation | 0.300 s |
| Attack traffic reaching origin | 0.074% |
| Legitimate traffic challenged | 0.54% |
Timeline
The attack was preceded by a hacktivist channel announcing the target. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 24 points of presence.
What the customer saw
A brief increase in p99 latency of 203 ms during the first minute, then normal service.
Recommendations
- Enable authenticated origin pulls.
- Add a dedicated rate limit for the targeted route.
- Keep origin IPs out of public DNS history.
Thanks — sharing this with our on-call team.
Solid runbook advice. The DNS-at-2am point hit home.
Could you share the dataset behind the percentages?
How does the proof-of-work challenge behave on older Android devices? Any numbers below Android 10?
Would love a follow-up on how you handle HTTP/3 fingerprinting.
How do you avoid challenging uptime monitors and partners?
Nice to read a vendor blog that admits what went wrong.
Solid runbook advice. The DNS-at-2am point hit home.
Machine-readable ranges are at /ips.json and via the API.
The billing model is what got our finance team on board, honestly.