On Monday 13 July 2026 at 13:28 UTC, a Slowloris targeted a tax authority portal customer in the Middle East. The attack peaked at 427.4 million requests per second and lasted 165 minutes. Traffic originated from 263 autonomous systems in 65 countries, predominantly mobile carrier ranges.
| Vector | Slowloris |
| Peak | 427.4 million requests per second |
| Duration | 165 min |
| Time to mitigation | 0.312 s |
| Attack traffic reaching origin | 0.024% |
| Legitimate traffic challenged | 0.17% |
Timeline
The attack was preceded by no stated motive. Request rates on the targeted routes exceeded their hourly baseline by a factor of 103 within 12 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.
What the customer saw
A brief increase in p99 latency of 75 ms during the first minute, then normal service.
Recommendations
- Review allow-listed partner ranges quarterly.
- Add a dedicated rate limit for the targeted route.
- Enable log streaming to your SIEM for faster correlation.
This matches what we see in iGaming around big matches.
The billing model is what got our finance team on board, honestly.