On Saturday 13 July 2024 at 02:24 UTC, a TLS handshake exhaustion targeted a education platform customer in Latin America. The attack peaked at 152.7 million requests per second and lasted 150 minutes. Traffic originated from 1132 autonomous systems in 104 countries, predominantly compromised cloud VMs.
| Vector | TLS handshake exhaustion |
| Peak | 152.7 million requests per second |
| Duration | 150 min |
| Time to mitigation | 0.300 s |
| Attack traffic reaching origin | 0.038% |
| Legitimate traffic challenged | 0.73% |
Timeline
The attack was preceded by an extortion email received two days earlier. Request rates on the targeted routes exceeded their hourly baseline by a factor of 48 within 19 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.
What the customer saw
A brief increase in p99 latency of 75 ms during the first minute, then normal service.
Recommendations
- Keep origin IPs out of public DNS history.
- Lower challenge thresholds on authentication endpoints during high-risk events.
- Enable authenticated origin pulls.