https://arstechnica.com/security/2025/06/record-ddos-pummels-site-with-once-unimaginable-7-3tbps-of-junk-traffic/ Skip to content Ars Technica home Sections Forum Subscribe * AI * Biz & IT * Cars * Culture * Gaming * Health * Policy * Science * Security * Space * Tech * Feature * Reviews * Store * AI * Biz & IT * Cars * Culture * Gaming * Health * Policy * Science * Security * Space * Tech Forum Subscribe Story text Size [Standard] Width * [Standard] Links [Standard] * Subscribers only Learn more Pin to story Theme * HyperLight * Day & Night * Dark * System Search dialog... Sign In Sign in dialog... Sign in never-ending arms race Record DDoS pummels site with once-unimaginable 7.3Tbps of junk traffic Attacker rained down the equivalent of 9,300 full-length HD movies in just 45 seconds. Dan Goodin - Jun 20, 2025 3:04 pm | 92 [server-ddos-storm-surge-300x169] [server-ddos-storm-surge] Credit: Aurich Lawson / Getty Credit: Aurich Lawson / Getty Text settings Story text Size [Standard] Width * [Standard] Links [Standard] * Subscribers only Learn more Minimize to nav Large-scale attacks designed to bring down Internet services by sending them more traffic than they can process keep getting bigger, with the largest one yet, measured at 7.3 terabits per second, being reported Friday by Internet security and performance provider Cloudflare. The 7.3Tbps attack amounted to 37.4 terabytes of junk traffic that hit the target in just 45 seconds. That's an almost incomprehensible amount of data, equivalent to more than 9,300 full-length HD movies or 7,500 hours of HD streaming content in well under a minute. Indiscriminate target bombing Cloudflare said the attackers "carpet bombed" an average of nearly 22,000 destination ports of a single IP address belonging to the target, identified only as a Cloudflare customer. A total of 34,500 ports were targeted, indicating the thoroughness and well-engineered nature of the attack. The vast majority of the attack was delivered in the form of User Datagram Protocol packets. Legitimate UDP-based transmissions are used in especially time-sensitive communications, such as those for video playback, gaming applications, and DNS lookups. It speeds up communications by not formally establishing a connection before data is transferred. Unlike the more common Transmission Control Protocol, UDP doesn't wait for a connection between two computers to be established through a handshake and doesn't check whether data is properly received by the other party. Instead, it immediately sends data from one machine to another. UDP flood attacks send extremely high volumes of packets to random or specific ports on the target IP. Such floods can saturate the target's Internet link or overwhelm internal resources with more packets than they can handle. Since UDP doesn't require a handshake, attackers can use it to flood a targeted server with torrents of traffic without first obtaining the server's permission to begin the transmission. UDP floods typically send large numbers of datagrams to multiple ports on the target system. The target system, in turn, must send an equal number of data packets back to indicate the ports aren't reachable. Eventually, the target system buckles under the strain, resulting in legitimate traffic being denied. A much smaller portion of the attack, measured at just 0.004 percent, was delivered as reflection attacks. Reflection attacks direct malicious traffic to one or more third-party intermediaries, such as Network Time Protocol services for syncing server clocks. The attacker spoofs the sender IP of the malicious packets to give the appearance they're being delivered by the final target. When the third party sends a response, it's delivered to the target rather than the destination of the original source of the traffic. Reflection attacks provide multiple benefits to attackers. For one, such attacks cause the DDoS to be delivered from a wide variety of destinations. That makes it harder for targets to defend against the onslaught. Additionally, by choosing intermediary servers known to generate responses that are in some cases thousands of times bigger than the originating request, attackers can magnify the firepower available to them by a thousandfold or more. Cloudflare and other players routinely advise server administrators to lock down servers to prevent them from responding to spoofed packets, but inevitably, many don't heed the advice. Cloudflare said the record DDoS exploited various reflection or amplification vectors, including the previously mentioned Network Time Protocol; the Quote of the Day Protocol, which listens on UDP port 17 and responds with a short quote or message; the Echo Protocol, which responds with the same data it receives; and Portmapper services used identify resources available to applications connecting through the Remote Procedure Call. Cloudflare said the attack was also delivered through one or more Mirai-based botnets. Such botnets are typically made up of home and small office routers, web cameras, and other Internet of Things devices that have been compromised. DDoS sizes have continued a steady climb over the past three decades. In March, Nokia reported that a botnet dubbed Eleven11bot delivered a DOS with a peak of 6.5Tbps. In May, KrebsonSecurity said it came under a DDos that peaked at 6.3Tbps. Photo of Dan Goodin Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 92 Comments Comments Forum view Loading Loading comments... Prev story Next story Most Read 1. Listing image for first story in Most Read: Study: Meta AI model can reproduce almost half of Harry Potter book 1. Study: Meta AI model can reproduce almost half of Harry Potter book 2. 2. Record DDoS pummels site with once-unimaginable 7.3Tbps of junk traffic 3. 3. MIT student prints AI polymer masks to restore paintings in hours 4. 4. To avoid admitting ignorance, Meta AI says man's number is a company helpline 5. 5. A shark scientist reflects on Jaws at 50 Customize Ars Technica has been separating the signal from the noise for over 25 years. With our unique combination of technical savvy and wide-ranging interest in the technological arts and sciences, Ars is the trusted source in a sea of information. After all, you don't need to know everything, only what's important. More from Ars * About Us * Staff Directory * Newsletters * Ars Videos * General FAQ * RSS Feeds Contact * Contact us * Advertise with us * Reprints Manage Preferences (c) 2025 Conde Nast. All rights reserved. Use of and/or registration on any portion of this site constitutes acceptance of our User Agreement and Privacy Policy and Cookie Statement and Ars Technica Addendum and Your California Privacy Rights. Ars Technica may earn compensation on sales from links on this site. Read our affiliate link policy. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Conde Nast. Ad Choices