I am reliably informed by Google Shield that my site krebsonsecurity.com on Monday was the target of the biggest DDoS attack Google has ever had to deal with, clocking in at ~6.3 Tbps. This is not quite a record; apparently, an attack Cloudflare had to deal with in April is the largest known DDoS to date -- at ~6.5 Tbps.

It's been a while since we've seen a big DDoS. For reference, this one was about 10x the size of the Mirai botnet attack that launched a record DDoS against my site in 2016, knocking it offline for nearly 4 days until I got the site behind Google Sheild.

I'll know more in a bit. Below is the CF blog about their April attack.

https://blog.cloudflare.com/ddos-threat-report-for-2025-q1/#hyper-volumetric-attacks-continue-spill-into-q2

Targeted by 20.5 million DDoS attacks, up 358% year-over-year: Cloudflare’s 2025 Q1 DDoS Threat Report

DDoS attacks are surging. In 2025 Q1, Cloudflare blocked +20M attacks (a 358% YoY spike) along with 5.6 Tbps and 4.8 Bpps record-breaking attacks. And that's just the beginning. Read more in our latest DDoS Threat Report.

The Cloudflare Blog

@briankrebs Axact is likely behind this right, BK?

https://krebsonsecurity.com/2025/05/pakistani-firm-shipped-fentanyl-analogs-scams-to-us/

Your post accusing them was pretty salty.

Pakistani Firm Shipped Fentanyl Analogs, Scams to US – Krebs on Security

@GreekFrenchMontana IDK. It appears to have been launched by a botnet that anyone can hire. But yes, it comes after some strange things going on with that story URL in Google, which has hidden the story completely.

https://infosec.exchange/@briankrebs/114512527951494345

BrianKrebs (@[email protected])

Weirdly, this story appears to now be buried in Google. If you search on the headline in Google (Pakistani Firm Shipped Fentanyl Analogs, Scams to US) you will see tons of places linking to my story, and you will see tags from the story. I don't see this behavior for any other story of mine on the homepage of KrebsOnSecurity.com now. But the story itself is basically gone from Google's search results. Gee, I wonder how that happened?

Infosec Exchange