HeadlinesBriefing favicon HeadlinesBriefing.com

Read the Docs DDoS Attack Analysis

Hacker News •
×

In June 2026, Read the Docs experienced its largest DDoS attack, peaking at 5.5 million requests per minute—100 times normal traffic. The attack lasted nearly ten days, testing infrastructure and defenses. Unlike previous incidents, it was highly distributed across millions of IPs and hundreds of networks globally, including residential IPs.

Attackers randomized headers and TLS parameters to evade signature-based filters, bypassing Cloudflare's automated protections and hitting rate limiting and WAF rules directly. They targeted cache-missing URLs like 404s and 302s, and adapted to blocks by rotating paths and IP pools. The scale and breadth were unprecedented, originating from every country, making per-CDN rate limiting ineffective.

Even a hardcoded Nginx redirect, normally handling thousands of requests per second, was overwhelmed. The attack also targeted author-facing dashboards requiring logins. While Cloudflare's Under Attack Mode was an option, the team avoided it to minimize disruption.

This incident highlights the evolving sophistication of DDoS attacks and the need for adaptive, multi-layered defenses.