On Tuesday 13 May 2025 at 01:46 UTC, a SYN flood targeted a airline booking customer in North America. The attack peaked at 217.3 Gbps and lasted 49 minutes. Traffic originated from 4002 autonomous systems in 74 countries, predominantly compromised cloud VMs.
| Vector | SYN flood |
| Peak | 217.3 Gbps |
| Duration | 49 min |
| Time to mitigation | 0.302 s |
| Attack traffic reaching origin | 0.034% |
| Legitimate traffic challenged | 0.52% |
Timeline
The attack was preceded by a publicly announced sales event. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 31 points of presence.
What the customer saw
No customer-visible impact. The on-call engineer was notified and acknowledged the incident from the dashboard.
Recommendations
- Enable log streaming to your SIEM for faster correlation.
- Enable authenticated origin pulls.
- Lower challenge thresholds on authentication endpoints during high-risk events.
Carpet bombing is nasty. Good to see a clear explanation of it.
We had the exact false-positive issue with CGNAT carriers. The weighting change makes sense.
Could you share the dataset behind the percentages?
Nice to read a vendor blog that admits what went wrong.
Is the risk score exposed in the logs so we can build our own dashboards on it?
How do you avoid challenging uptime monitors and partners?
Nice to read a vendor blog that admits what went wrong.