Understanding the Recent DDoS Attack Against Read the Docs
20 days ago
- Read the Docs experienced a major DDoS attack in June 2026, peaking at 5.5 million requests per minute, 100 times normal traffic.
- The attack was globally distributed, used randomized headers/TLS, adapted to defenses, and targeted cache-bypassing URLs like 404s and 302 redirects.
- Defense strategies included aggressive caching, Cloudflare edge services, targeted rate limiting, and client fingerprinting rather than simple IP blocking.
- Key lessons: cache everything, protect cache-miss surfaces, use targeted challenges, and manage infrastructure as code.
- The attack lasted nearly ten days, but the team maintained availability without resorting to universal JavaScript challenges.