Technology
Read the Docs weathered massive ten-day cyberattack, postmortem reveals
A mid-2026 DDoS attack peaked at 5.5 million requests per minute, according to Hacker News.
The short version
- Read the Docs faced a sophisticated distributed denial-of-service attack spanning nearly ten days in mid-to-late June 2026.[Hacker News]
- Traffic peaked at more than 5.5 million requests per minute, roughly 100 times the platform's standard baseline.[Hacker News]
- The assault leveraged millions of IP addresses, randomized headers and TLS parameters, and aimed at cache misses such as 404 errors.[Hacker News]
- Cloudflare automated systems stopped known botnets, but significant traffic bypassed initial checks and required manual rate limiting and WAF rules.[Hacker News]
Key facts
- Read the Docs sustained a sophisticated DDoS attack in mid-to-late June 2026 lasting nearly ten days.[Hacker News]
- Peak incoming volume reached over 5.5 million requests per minute, approximately 100 times the baseline.[Hacker News]
- Malicious traffic stemmed from millions of distinct IP addresses distributed across residential blocks and hosting providers globally.[Hacker News]
- The attackers randomized HTTP headers and TLS connection parameters to evade signature-based detection.[Hacker News]
- The assault specifically targeted uncached endpoints, including non-existent 404 paths and 302 redirects.[Hacker News]
- While automated defenses filtered known botnets, substantial malicious traffic slipped through to rate limiting and WAF controls.[Hacker News]
What remains uncertain
- The identity, origin, and specific motivation of the threat actors behind the coordinated attack remain undisclosed.[Hacker News]
Sources
Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.