Threat Bulletin 1385: HTTP/2 rapid reset against a sports betting platform in Central Europe

On Monday 15 June 2026 at 00:35 UTC, a HTTP/2 rapid reset targeted a sports betting customer in Central Europe. The attack peaked at 413.0 million requests per second and lasted 50 minutes. Traffic originated from 2602 autonomous systems in 10 countries, predominantly misconfigured open reflectors.

Vector HTTP/2 rapid reset
Peak 413.0 million requests per second
Duration 50 min
Time to mitigation 0.757 s
Attack traffic reaching origin 0.028%
Legitimate traffic challenged 0.21%

Timeline

The attack was preceded by an extortion email received two days earlier. Request rates on the targeted routes exceeded their hourly baseline by a factor of 787 within 21 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.

What the customer saw

Checkout conversion was unchanged compared with the same hour of the previous week.

Recommendations

  • Add a dedicated rate limit for the targeted route.
  • Lower challenge thresholds on authentication endpoints during high-risk events.
  • Review allow-listed partner ranges quarterly.

8 thoughts on “Threat Bulletin 1385: HTTP/2 rapid reset against a sports betting platform in Central Europe”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top