On Saturday 19 April 2025 at 13:32 UTC, a UDP reflection (NTP) targeted a fashion retail customer in Latin America. The attack peaked at 41.4 Gbps and lasted 160 minutes. Traffic originated from 899 autonomous systems in 91 countries, predominantly a headless-browser farm.
| Vector | UDP reflection (NTP) |
| Peak | 41.4 Gbps |
| Duration | 160 min |
| Time to mitigation | 0.677 s |
| Attack traffic reaching origin | 0.074% |
| Legitimate traffic challenged | 0.45% |
Timeline
The attack was preceded by no stated motive. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 25 points of presence.
What the customer saw
No customer-visible impact. The on-call engineer was notified and acknowledged the incident from the dashboard.
Recommendations
- Enable authenticated origin pulls.
- Add a dedicated rate limit for the targeted route.
- Review allow-listed partner ranges quarterly.
Great write-up. We saw almost the same pattern on our login endpoint last month.
Would love a follow-up on how you handle HTTP/3 fingerprinting.
Carpet bombing is nasty. Good to see a clear explanation of it.
Machine-readable ranges are at /ips.json and via the API.
Do you publish the edge IP ranges in a machine-readable format?
Good question. We will cover that in a follow-up post.
Our auditors asked for exactly this kind of incident evidence under DORA.
We moved from a scrubbing provider to always-on last year; time to mitigation went from minutes to basically nothing.
Machine-readable ranges are at /ips.json and via the API.
Would love a follow-up on how you handle HTTP/3 fingerprinting.
Thanks! Yes — the risk score and its components are included in every log record.
Would love a follow-up on how you handle HTTP/3 fingerprinting.
Solid runbook advice. The DNS-at-2am point hit home.
Great to hear, thanks for sharing your experience.