On Tuesday 19 August 2025 at 20:02 UTC, a credential stuffing targeted a tax authority portal customer in the Middle East. The attack peaked at 854.3 million requests per second and lasted 120 minutes. Traffic originated from 1217 autonomous systems in 68 countries, predominantly residential proxy networks.
| Vector | credential stuffing |
| Peak | 854.3 million requests per second |
| Duration | 120 min |
| Time to mitigation | 0.122 s |
| Attack traffic reaching origin | 0.044% |
| Legitimate traffic challenged | 0.32% |
Timeline
The attack was preceded by no stated motive. Request rates on the targeted routes exceeded their hourly baseline by a factor of 529 within 10 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.
What the customer saw
Checkout conversion was unchanged compared with the same hour of the previous week.
Recommendations
- Add a dedicated rate limit for the targeted route.
- Enable log streaming to your SIEM for faster correlation.
- Enable authenticated origin pulls.
The point about origin IPs leaking through certificate transparency logs is underrated.
Great write-up. We saw almost the same pattern on our login endpoint last month.
Do you publish the edge IP ranges in a machine-readable format?
Would love a follow-up on how you handle HTTP/3 fingerprinting.
Thanks! Yes — the risk score and its components are included in every log record.
Interesting that most attacks are under ten minutes. Our experience is similar.
Great to hear, thanks for sharing your experience.
This matches what we see in iGaming around big matches.
Verified good bots and allow-listed partners bypass challenges entirely.