On Tuesday 15 August 2023 at 00:19 UTC, a login endpoint flood targeted a online payments customer in Central Europe. The attack peaked at 866.7 million requests per second and lasted 157 minutes. Traffic originated from 4076 autonomous systems in 66 countries, predominantly a rented booter service.
| Vector | login endpoint flood |
| Peak | 866.7 million requests per second |
| Duration | 157 min |
| Time to mitigation | 0.408 s |
| Attack traffic reaching origin | 0.024% |
| Legitimate traffic challenged | 0.20% |
Timeline
The attack was preceded by a hacktivist channel announcing the target. Request rates on the targeted routes exceeded their hourly baseline by a factor of 374 within 31 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.
What the customer saw
A brief increase in p99 latency of 99 ms during the first minute, then normal service.
Recommendations
- Review allow-listed partner ranges quarterly.
- Enable log streaming to your SIEM for faster correlation.
- Enable authenticated origin pulls.
This matches what we see in iGaming around big matches.
Would love a follow-up on how you handle HTTP/3 fingerprinting.
Verified good bots and allow-listed partners bypass challenges entirely.
Solid runbook advice. The DNS-at-2am point hit home.
We had the exact false-positive issue with CGNAT carriers. The weighting change makes sense.
Would love a follow-up on how you handle HTTP/3 fingerprinting.
How does the proof-of-work challenge behave on older Android devices? Any numbers below Android 10?
The billing model is what got our finance team on board, honestly.