On Wednesday 24 December 2025 at 17:51 UTC, a SYN flood targeted a healthcare portal customer in North America. The attack peaked at 221.4 Gbps and lasted 21 minutes. Traffic originated from 3930 autonomous systems in 86 countries, predominantly a Mirai-derived IoT botnet.
| Vector | SYN flood |
| Peak | 221.4 Gbps |
| Duration | 21 min |
| Time to mitigation | 0.788 s |
| Attack traffic reaching origin | 0.064% |
| Legitimate traffic challenged | 0.39% |
Timeline
The attack was preceded by a breaking political story. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 28 points of presence.
What the customer saw
No customer-visible impact. The on-call engineer was notified and acknowledged the incident from the dashboard.
Recommendations
- Review allow-listed partner ranges quarterly.
- Keep origin IPs out of public DNS history.
- Lower challenge thresholds on authentication endpoints during high-risk events.
We had the exact false-positive issue with CGNAT carriers. The weighting change makes sense.
Great to hear, thanks for sharing your experience.
Any plans to support per-tenant limits keyed on a JWT claim?
The billing model is what got our finance team on board, honestly.
Great write-up. We saw almost the same pattern on our login endpoint last month.
Great to hear, thanks for sharing your experience.
We moved from a scrubbing provider to always-on last year; time to mitigation went from minutes to basically nothing.
How do you avoid challenging uptime monitors and partners?
How do you avoid challenging uptime monitors and partners?
The billing model is what got our finance team on board, honestly.
Any plans to support per-tenant limits keyed on a JWT claim?
Verified good bots and allow-listed partners bypass challenges entirely.