Threat Bulletin 1292: cache-busting query flood against a online payments platform in the Nordics

On Tuesday 3 February 2026 at 18:44 UTC, a cache-busting query flood targeted a online payments customer in the Nordics. The attack peaked at 195.9 million requests per second and lasted 20 minutes. Traffic originated from 1951 autonomous systems in 86 countries, predominantly a Mirai-derived IoT botnet.

Vector cache-busting query flood
Peak 195.9 million requests per second
Duration 20 min
Time to mitigation 0.872 s
Attack traffic reaching origin 0.072%
Legitimate traffic challenged 0.54%

Timeline

The attack was preceded by a publicly announced sales event. Request rates on the targeted routes exceeded their hourly baseline by a factor of 734 within 10 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.

What the customer saw

A brief increase in p99 latency of 209 ms during the first minute, then normal service.

Recommendations

  • Add a dedicated rate limit for the targeted route.
  • Lower challenge thresholds on authentication endpoints during high-risk events.
  • Enable log streaming to your SIEM for faster correlation.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top