On AUG 9 a United States payments processor absorbed the largest volumetric attack on public record: a peak of 22.3 Tbps and 4.1 Bpps, sustained above 15 Tbps for nearly forty minutes. Mitigation provider Meridian Edge published detailed telemetry this week.
The firepower came from a botnet of roughly 1.9 million compromised devices, mostly consumer routers and DVRs with vendor-default credentials. Notably, less than a third of the traffic was classic UDP reflection. The majority was direct-path HTTPS flooding from the devices themselves.
Anycast did the heavy lifting. The flood scattered across more than 190 edge sites, each scrubbing locally with eBPF and XDP filters dropping packets at the network card. Two sites in Southeast Asia browned out briefly; everything else held, and the processor reported no customer-visible downtime.
The direct-path problem
"Reflection is dying and direct-path is the future of volumetric attacks. It changes what your edge has to be able to do, because you cannot filter it by protocol quirk anymore."
Caleb Fontaine, head of network defense, Meridian Edge
Direct-path floods look like legitimate client traffic, which pushes mitigation toward behavioral scoring and per-site capacity rather than signature filters. That favors networks with many small edges over few large scrubbing centers, a quiet architectural shift that echoes the lessons of the Northlake outage: distribution is resilience.
Attribution remains murky. The botnet's command infrastructure rotated through bulletproof hosting in three jurisdictions, and a related federal advisory stops short of naming an operator. Takedowns of booter services continue to lag the botnets they rent.
Meridian's engineers close their report with a number rather than advice: at current botnet growth, they model a 30 Tbps event within 18 months. The question for every network team is not whether the record falls, but whether their interconnects are wide enough to shrug when it does.