On Thursday 25 September 2025 at 16:30 UTC, a GRE flood targeted a gaming community customer in Southeast Asia. The attack peaked at 116.2 Gbps and lasted 64 minutes. Traffic originated from 1876 autonomous systems in 98 countries, predominantly misconfigured open reflectors.
| Vector | GRE flood |
| Peak | 116.2 Gbps |
| Duration | 64 min |
| Time to mitigation | 0.337 s |
| Attack traffic reaching origin | 0.015% |
| Legitimate traffic challenged | 0.40% |
Timeline
The attack was preceded by a competitor’s product launch. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 39 points of presence.
What the customer saw
A brief increase in p99 latency of 193 ms during the first minute, then normal service.
Recommendations
- Keep origin IPs out of public DNS history.
- Enable authenticated origin pulls.
- Lower challenge thresholds on authentication endpoints during high-risk events.
Carpet bombing is nasty. Good to see a clear explanation of it.
Machine-readable ranges are at /ips.json and via the API.
Solid runbook advice. The DNS-at-2am point hit home.
Carpet bombing is nasty. Good to see a clear explanation of it.
Machine-readable ranges are at /ips.json and via the API.
Interesting that most attacks are under ten minutes. Our experience is similar.
We had the exact false-positive issue with CGNAT carriers. The weighting change makes sense.
Thanks! Yes — the risk score and its components are included in every log record.
Do you publish the edge IP ranges in a machine-readable format?