On Monday 27 December 2021 at 22:58 UTC, a GRE flood targeted a electronics retail customer in Western Europe. The attack peaked at 328.6 Gbps and lasted 168 minutes. Traffic originated from 504 autonomous systems in 114 countries, predominantly residential proxy networks.
| Vector | GRE flood |
| Peak | 328.6 Gbps |
| Duration | 168 min |
| Time to mitigation | 0.327 s |
| Attack traffic reaching origin | 0.043% |
| Legitimate traffic challenged | 0.56% |
Timeline
The attack was preceded by an extortion email received two days earlier. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 16 points of presence.
What the customer saw
Checkout conversion was unchanged compared with the same hour of the previous week.
Recommendations
- Keep origin IPs out of public DNS history.
- Enable authenticated origin pulls.
- Review allow-listed partner ranges quarterly.
Thanks — sharing this with our on-call team.
Do you publish the edge IP ranges in a machine-readable format?
Verified good bots and allow-listed partners bypass challenges entirely.