On Saturday 1 November 2025 at 02:47 UTC, a carpet-bombing UDP flood targeted a gaming community customer in the UK. The attack peaked at 286.4 Gbps and lasted 138 minutes. Traffic originated from 3511 autonomous systems in 80 countries, predominantly mobile carrier ranges.
| Vector | carpet-bombing UDP flood |
| Peak | 286.4 Gbps |
| Duration | 138 min |
| Time to mitigation | 0.812 s |
| Attack traffic reaching origin | 0.062% |
| Legitimate traffic challenged | 0.69% |
Timeline
The attack was preceded by a breaking political story. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 24 points of presence.
What the customer saw
A brief increase in p99 latency of 25 ms during the first minute, then normal service.
Recommendations
- Enable authenticated origin pulls.
- Enable log streaming to your SIEM for faster correlation.
- Add a dedicated rate limit for the targeted route.
How does the proof-of-work challenge behave on older Android devices? Any numbers below Android 10?
The billing model is what got our finance team on board, honestly.
Nice to read a vendor blog that admits what went wrong.
Is the risk score exposed in the logs so we can build our own dashboards on it?