On Saturday 6 April 2024 at 22:43 UTC, a ACK flood targeted a developer platform customer in Central Europe. The attack peaked at 213.2 Gbps and lasted 69 minutes. Traffic originated from 3119 autonomous systems in 39 countries, predominantly compromised cloud VMs.
| Vector | ACK flood |
| Peak | 213.2 Gbps |
| Duration | 69 min |
| Time to mitigation | 0.138 s |
| Attack traffic reaching origin | 0.085% |
| Legitimate traffic challenged | 0.75% |
Timeline
The attack was preceded by a competitor’s product launch. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 39 points of presence.
What the customer saw
A brief increase in p99 latency of 217 ms during the first minute, then normal service.
Recommendations
- Keep origin IPs out of public DNS history.
- Review allow-listed partner ranges quarterly.
- Enable authenticated origin pulls.
Any plans to support per-tenant limits keyed on a JWT claim?