On Saturday 25 October 2025 at 13:58 UTC, a TLS handshake exhaustion targeted a education platform customer in the Middle East. The attack peaked at 697.0 million requests per second and lasted 188 minutes. Traffic originated from 2254 autonomous systems in 31 countries, predominantly hijacked home routers.
| Vector | TLS handshake exhaustion |
| Peak | 697.0 million requests per second |
| Duration | 188 min |
| Time to mitigation | 0.182 s |
| Attack traffic reaching origin | 0.013% |
| Legitimate traffic challenged | 0.67% |
Timeline
The attack was preceded by a breaking political story. Request rates on the targeted routes exceeded their hourly baseline by a factor of 492 within 10 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.
What the customer saw
Checkout conversion was unchanged compared with the same hour of the previous week.
Recommendations
- Review allow-listed partner ranges quarterly.
- Keep origin IPs out of public DNS history.
- Lower challenge thresholds on authentication endpoints during high-risk events.
We had the exact false-positive issue with CGNAT carriers. The weighting change makes sense.
Machine-readable ranges are at /ips.json and via the API.
Carpet bombing is nasty. Good to see a clear explanation of it.
The point about origin IPs leaking through certificate transparency logs is underrated.