On Monday 22 November 2021 at 04:29 UTC, a ACK flood targeted a news publisher customer in the Nordics. The attack peaked at 158.6 Gbps and lasted 78 minutes. Traffic originated from 1731 autonomous systems in 63 countries, predominantly mobile carrier ranges.
| Vector | ACK flood |
| Peak | 158.6 Gbps |
| Duration | 78 min |
| Time to mitigation | 0.438 s |
| Attack traffic reaching origin | 0.001% |
| Legitimate traffic challenged | 0.16% |
Timeline
The attack was preceded by a ransom note demanding payment in Monero. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 15 points of presence.
What the customer saw
No customer-visible impact. The on-call engineer was notified and acknowledged the incident from the dashboard.
Recommendations
- Enable log streaming to your SIEM for faster correlation.
- Review allow-listed partner ranges quarterly.
- Enable authenticated origin pulls.