Skip to content
HN On Hacker News ↗

Understanding the Recent DDoS Attack Against Read the Docs

▲ 217 points 82 comments by davidfischer 2w ago HN discussion ↗

Pangram verdict · v3.3

We believe this text is mainly human-written, with some AI content.

14 %

AI likelihood · overall

Human
93% human-written 7% AI-generated
SEGMENTS · HUMAN 0 of 1
SEGMENTS · AI 1 of 1
WORD COUNT 133
PEAK AI % 86% · §1
Analyzed
Sep 9
backend: pangram/v3.3
Segments scanned
1 windows
avg 133 words each
Distribution
93 / 7%
human / AI fraction
Verdict
Human
Pangram v3.3

Article text · 133 words · 1 segments analyzed

Human AI-generated
§1 AI · 86%

In mid-to-late June 2026, Read the Docs experienced the largest and most sophisticated distributed denial-of-service (DDoS) attack in our history. At its peak, our infrastructure was hit with over 5.5 million requests per minute, about 100 times our normal baseline traffic. The incident lasted for nearly ten days, testing our infrastructure, our edge defenses, and our incident response processes. Unlike simpler traffic floods we've seen in the past, this attack was more distributed, it adapted to our defenses rapidly, and it purposefully attacked areas that bypassed caching. Now that our small ops team is back to sleeping at normal hours, we wanted to walk through the anatomy of this kind of attack, why our existing rate limiting only partially mitigated it, and what strategies actually helped us (mostly) maintain availability throughout the attack.