The record DDoS filed at 26-0302 — 31.4 terabits per second, 200 million requests per second — was directed at companies in the telecommunications sector. That choice of target is worth separating from the record itself.
Carriers Occupy Three Positions At Once
A telecommunications provider is the target of the attack. It is also the network carrying the attack, because the compromised consumer devices are connected through carriers. And it is the operator of the infrastructure the attack is trying to disrupt.
No other sector sits in all three positions simultaneously, and the combination is why carrier-level intervention keeps being proposed and keeps not happening at scale.
The Provider Can See What Nobody Else Can
A consumer cannot tell their router is compromised. A device manufacturer has no visibility into deployed hardware. An attack target sees only aggregate traffic arriving.
The access provider sits at the one point where an individual compromised device is identifiable — its own customer, on its own network, generating traffic patterns that do not match a household.
Why They Do Not Act
Detecting compromised customer equipment creates an obligation to do something about it, and every available action is expensive: support calls, hardware replacement, and a customer who experiences the intervention as their provider breaking their internet.
The benefit accrues to everyone else. This is a textbook externality, and it is the same shape as the water-sector funding problem filed at 26-0729 — the party positioned to fix it bears the cost and captures none of the value.
It also means telecommunications carriers should expect to remain the preferred target, since attacking them applies pressure to the only entity capable of reducing the attack surface.
This is an analysis file built on published reporting, listed below. The attack figures are as reported; the analysis of carrier position is ours and labelled as such. Corrections: corrections@forensicpost.com.