Cloudflare reported mitigating a 3.8 terabit per second DDoS attack that began July 10 at 14:22 UTC. The attack lasted six hours and targeted 1.2 million customer domains. Traffic peaked at 920 million packets per second.
The botnet comprised 4.7 million compromised IoT devices primarily in Brazil and Indonesia. Cloudflare's anycast network absorbed the flood across 300 cities. All customer sites remained online throughout the incident.
Similar attacks in 2025 reached 2.5 Tbps maximum. Cloudflare has invested 200 million dollars in new scrubbing centers since January. The company now handles 20 percent of global web traffic.
Why this matters
The attack highlights continued growth in IoT botnet scale. Enterprises using Cloudflare experienced zero downtime despite record volume. This reinforces the value of distributed anycast defense over centralized solutions.
Smaller hosting providers without equivalent capacity faced indirect strain. Regulators may accelerate IoT security mandates following this event. Cloudflare plans to release detailed attack signatures to the security community next week.
Future investments include machine learning models trained on 2026 attack patterns. The company expects similar threats to increase through the end of the year.