On 29 October 2024 an internet service provider in East Asia was hit by a UDP flood measured at 5.6 terabits per second — the largest attack Cloudflare has publicly reported. It came from a Mirai-variant botnet of more than 13,000 devices and it lasted eighty seconds.
The company’s account of the mitigation is the part worth quoting: it was fully autonomous, required no human intervention, triggered no alerts and caused no performance degradation.
Eighty Seconds Is The Design, Not A Failure
A volumetric attack is not trying to stay up. It is trying to saturate a link before anything can respond, and once the target is unreachable there is no reason to keep paying for the traffic. Short and enormous is the efficient shape.
That shape defeats a human response entirely. Eighty seconds is less time than it takes to read a page alert, and a defence that depends on somebody noticing has already lost. This is the one category in the corpus where automation is not a convenience but the only workable answer.
Thirteen Thousand Devices Is Not Many
Mirai-family botnets are assembled from consumer routers, cameras and recorders reachable from the internet with default or weak credentials. Thirteen thousand of them producing 5.6 Tbps works out at roughly 430 megabits each — which is to say, a modern home connection running flat out.
The corpus keeps returning to this arithmetic in different forms. The capacity to do serious harm is assembled from equipment whose owners have no idea it is participating, cannot tell, and would not be notified if anyone found out.
Why The Desk Grades This Medium
Every figure here — the throughput, the device count, the duration, the botnet family — comes from the mitigating vendor. Cloudflare is the only party with the telemetry, which makes it both the best available source and an interested one: a record attack absorbed without incident is a marketing asset as well as a fact.
The desk has no way to verify any of it independently and says so rather than laundering a vendor number into an established one. The file is here because volumetric denial of service is otherwise almost absent from this corpus, and the reason it is absent is instructive: an attack that a provider absorbs silently produces no notification, no regulator filing and no victim statement.
It leaves no trace in the record at all — except in the report of the company that stopped it.
Compiled from Cloudflare’s published DDoS threat reporting, listed below. Every quantitative claim in this file — 5.6 Tbps, 13,000+ devices, eighty seconds, the Mirai-variant attribution, and the 21.3 million attacks mitigated across 2024 — originates with Cloudflare, which mitigated the attack and is the only party holding the telemetry. This desk cannot corroborate any of it and grades the file medium for that reason, not because the figures look implausible. The per-device arithmetic is this desk’s own, derived from the two published figures. The targeted provider has not been named and is not identified here. Corrections: corrections@forensicpost.com.
- DDoS threat report for 2024 Q4Cloudflare