Cyber Security News

Massive DDoS Attacks at 633.7 Gbps Combining ACK, PUSH, RESET, and SYN Packets

DDoS attack evolves with changing tech and attacker motivations, with recent cases involving significant damages and legal consequences.

Recently, the DDoS defense platform of Akamai Prolexic prevented the largest DDoS attack on a major U.S. financial institution’s platform, reaching 633.7 Gbps and 55.1 Mpps.

Security analysts at Akamai reported that this largest DDoS attack lasted for less than 2 minutes, and in this attack, threat actors used the combination of the following flood attack vectors:-

  • ACK
  • PUSH
  • RESET
  • SYN

Prolexic’s DDoS protection shield platform prevented several record-breaking attacks in Europe and Asia-Pacific, including a 704.8 Mpps spike in September 2022 and a 900.1 Gbps surge in February 2023.

Advanced DDoS protection is crucial for companies in today’s world. Apptrana provides comprehensive coverage against DDoS and Bot attacks, making it highly recommended for businesses to employ.

Malicious Traffic source

Here below, we have mentioned the top malicious traffic sources:-

  • Bulgaria
  • Brazil
  • China
  • India
  • United States
  • Thailand
  • Russia
  • Ukraine
  • Vietnam
  • Japan
Distribution of peacetime traffic and attack traffic (Source – Akamai)

Moreover, U.S. traffic surged to over twice its usual volume during the attack. DDoS attacks, deliberate and cost-effective, now serve as smokescreens for triple extortion ransomware attacks on vital financial institutions, impacting entire economies.

Document
FREE Webinar

Live DDoS Attack Simulation

Attend the Live DDoS Website & API Attack Simulation webinar to gain knowledge on various types of attacks and how to prevent them.

Attack Analysis

From 10-15% historically, DDoS attacks on financial services surged to over 30% since 2021, marking a significant shift in attack patterns once seen primarily in the following sectors:-

  • Software
  • Tech
  • Gaming
  • Media
  • Entertainment
  • Internet
  • Telecom

Besides this, a surge in deeper reconnaissance threats and attacks on vulnerable assets was noted by the security researchers at Akamai. 

However, the recent DDoS attack seems quite different than the usual ones, as in this attack, threat actors directly targeted a major US-based financial institution’s primary web page, aiming to disrupt online banking.

Moreover, Akamai confirmed zero collateral damage due to proactive defense with their global command center partnership. While in today’s high-risk environment, a solid DDoS strategy is crucial and essential.

Recommendations

Here below, we have mentioned all the recommendations provided by the Akamai:-

  • Make sure to adopt CISA recommendations promptly.
  • Check all the key subnets and IPs for effective mitigation controls.
  • Establish continuous DDoS security controls as your initial defense layer.
  • Enhance security with advanced network cloud firewall beyond basic DDoS protection.
  • Form a proactive crisis team and keep incident plans and runbooks up to date.

Keep informed about the latest Cyber Security News by following us on Google NewsLinkedinTwitter, and Facebook.

Guru Baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

GitAuto Strengthens Code Security By Automating QA At Scale

In the current software landscape, security breaches caused by untested or poorly tested code are…

35 minutes ago

Cybersecurity in Mergers and Acquisitions – CISO Focus

Cybersecurity in mergers and acquisitions is crucial, as M&A activities represent key inflection points for…

2 hours ago

Top Cybersecurity Trends Every CISO Must Watch in 2025

In 2025, cybersecurity trends for CISOs will reflect a landscape that is more dynamic and…

2 hours ago

Zero Trust Architecture – A CISO’s Blueprint for Modern Security

Zero-trust architecture has become essential for securing operations in today’s hyper-connected world, where corporate network…

2 hours ago

Chrome 136 Released With Patch For 20-Year-Old Privacy Vulnerability

The Chrome team has officially promoted Chrome 136 to the stable channel for Windows, Mac,…

3 hours ago

SecAI Debuts at RSA 2025, Redefining Threat Investigation with AI

By fusing agentic AI and contextual threat intelligence, SecAI transforms investigation from a bottleneck into…

13 hours ago