Record 2 Tbps DDoS Wave Tests Resilience of Global Financial Networks
A distributed denial-of-service campaign has crested at an unprecedented 2 terabits per second, hammering a cluster of financial institutions with the largest volumetric assault the sector has absorbed to date. Security vendors monitoring the event say the traffic surge combined reflection-based amplification with a sweeping botnet of compromised IoT devices, producing a flood that briefly saturated upstream transit providers across three continents. Unlike earlier record-setting floods that targeted technology platforms, this strike was purpose-built around payment processors, retail brokerage gateways, and treasury clearing endpoints.
The timing has put Australian banking CISOs on high alert. Although the on-premises firewalls and scrubbing centres of the major banks stood up under the initial bombardment, downstream service providers and fintech intermediaries showed latency spikes and session drops during the peak window. Commonwealth Bank, Westpac, ANZ, and NAB have all confirmed they are reviewing logs from the past 48 hours, even where customer-facing services remained online.
Domestic regulators are also taking notice. The Australian Prudential Regulation Authority (APRA) has reminded authorised deposit-taking institutions of their obligations under CPS 234, which requires entities to maintain information security capabilities commensurate with the size and importance of their operations. The Australian Cyber Security Centre has separately raised its threat advisory level for the financial services sector, noting that volumetric DDoS is increasingly being used as cover for follow-on intrusion attempts.
The episode lands at a moment when Australian banks are already investing heavily in scrubbing capacity, anycast networks, and cross-border failover agreements with overseas peering partners. It also coincides with renewed scrutiny of third-party risk, particularly the role of regional ISPs and managed DDoS providers whose networks sit between customer endpoints and the global financial message routing fabric.
Anatomy of the 2 Tbps Onslaught
The 2 Tbps peak was not a single burst but a rolling siege, according to telemetry shared by mitigation providers. Engineers describe a layered design in which UDP amplification from misconfigured DNS, NTP, and STUN servers provided the bulk of the bandwidth, while a parallel HTTP/2 rapid-reset layer targeted application gateways behind the volumetric front. Peak packets-per-second numbers crossed 600 Mpps at the height of the campaign, enough to overrun the line-rate forwarding tables of several Tier 2 carriers in Europe and Asia.
Botnet operators have continued to weaponise poorly secured routers, DVRs, and IP cameras, many of them still shipped with default administrative credentials. Researchers tracking the underlying command-and-control infrastructure note a high overlap with botnet families previously observed targeting online gaming and cryptocurrency services, suggesting a shared rental economy for booter and stresser platforms. The shift to financial targets mirrors a broader pivot researchers have documented across 2025, where extortion crews have blended volumetric DDoS with ransomware threats to pressure victims into paying.
What distinguishes financial institutions from previous high-profile victims such as GitHub or cloud hyperscalers is the regulatory exposure around downtime. A trading platform or retail brokerage that goes dark for even fifteen minutes can trigger market-integrity alarms, breach service-level agreements with correspondent banks, and in some jurisdictions expose the operator to fines. Attackers appear to have modelled their demands around this asymmetry, choosing peak windows that overlap with end-of-day settlement, payroll processing, and market-open periods.
Australian Banks on Standby
Commonwealth Bank confirmed it engaged its upstream scrubbing partner within minutes of the campaign being detected, routing NetBank and CommBiz traffic through additional scrubbing pools in Sydney and Singapore. ANZ disclosed it observed elevated volumetric traffic on its transaction processing gateways but reported no degradation in customer channels. Westpac and NAB declined to detail specific countermeasures but pointed to ongoing investments in anycast routing and BGP-based blackholing controls as the primary mitigation posture.
APRA's CPS 234 has become the implicit baseline for these responses. The standard requires boards to ensure that information security risk is managed across all information assets, including those held by third-party providers. After the Optus and Medibank breaches of 2022, APRA sharpened its expectations on incident reporting, financial sector resilience exercises, and the contractual obligations imposed on outsourced service providers. A 2 Tbps attack is exactly the kind of scenario those exercises were designed to rehearse.
Australia has not been immune to large-scale DDoS events in the past. A 2016 incident targeting the census website, attributed at the time to offshore sources, exposed limitations in the country's domestic scrubbing capacity and led to the creation of dedicated threat-sharing forums such as the Financial Services Information Sharing and Analysis Center local chapter. More recently, Newcastle-based utilities and Brisbane councils have absorbed smaller but politically motivated DDoS campaigns. The 2 Tbps event is the first time the local banking sector has had to mobilise at this scale in real time.
Mega-DDoS Events Compared
To put the current 2 Tbps surge in context, it is worth comparing it against other record-setting volumetric events of the past seven years. The data below draws on disclosed figures from major mitigation providers and post-event technical write-ups.
| Event | Peak throughput | Year | Primary target | Mitigation outcome |
|---|---|---|---|---|
| Spamhaus-Cyberbunker reflection campaign | ~300 Gbps | 2013 | Spamhaus | Partial outage, slowed downstream providers |
| GitHub memcached reflection | 1.7 Tbps | 2018 | GitHub | Akamai Prolexic absorbed, 15-minute degradation |
| AWS Shield mitigated event | 2.3 Tbps | 2020 | Unnamed AWS customer | No customer-visible impact |
| Microsoft Azure mitigated event | 3.47 Tbps | 2022 | Azure endpoint | No customer-visible impact |
| Cloudflare-reported hyper-volumetric event | 3.8 Tbps | 2024 | Multiple ISPs | Mitigated, limited collateral |
| Current financial-sector campaign | 2 Tbps | 2025 | Banking and brokerage gateways | Scrubbing engaged, partial degradation |
The pattern is unmistakable. After a brief plateau between 2018 and 2020, attackers have continued to find new amplification primitives, with peak volumes more than doubling over the past five years. At the same time, the median target has shifted from social platforms and open-source infrastructure to commercial services with strict uptime obligations and a willingness to pay extortion fees.
Defensive Posture and Regulatory Pressure
For Australian financial institutions, the 2 Tbps event crystallises several defensive priorities that were already on internal roadmaps. The combination of upstream scrubbing, on-premise rate limiting, and behavioural analytics is no longer a luxury but an expectation embedded in supervisory dialogue with APRA. Boards have begun asking pointed questions about scrubbing capacity guarantees, contract penalties for upstream providers, and the time required to engage crisis-mode runbooks.
The local regulatory landscape is tightening in parallel. Beyond CPS 234, the Notifiable Data Breaches scheme under the Privacy Act 1988 obliges banks to escalate incidents involving personal information, and APRA's prudential practice guide on operational risk management provides additional colour on resilience testing. ASIC has also increased its scrutiny of how listed financial entities disclose cyber events to the market, raising the bar for timely and accurate investor communication during and after an outage.
Core mitigation controls financial CISOs are prioritising:
- Anycast-based ingress architectures that distribute attack traffic across multiple scrubbing points in Sydney, Melbourne, and offshore
- BGP FlowSpec and RTBH coordination with upstream providers, allowing rapid advertisement of blackhole routes during the worst of a flood
- Behavioural baselining of API endpoints to distinguish botnet-driven HTTP/2 floods from genuine customer traffic
- Contractual DDoS-mitigation service-level agreements with financial credits tied to time-to-mitigate
- Tabletop exercises that simulate simultaneous volumetric and ransomware events, mirroring the blended tactics now standard in extortion playbooks
The financial sector's investment cycle is also accelerating. Several large Australian institutions have moved from best-effort DDoS protection bundled into their existing internet subscriptions to dedicated scrubbing subscriptions with capacity guarantees measured in tens of terabits. The shift is partly driven by the regulator, partly by board-level risk appetite, and partly by the realisation that a single successful outage during a market event can erase years of accumulated margin.
A Shifting Threat Landscape
The financial sector DDoS surge sits inside a wider pattern of escalating cyber pressure on critical services. Energy grids, water utilities, and telecommunications operators have all reported parallel campaigns in recent months, suggesting either a coordinated criminal consortium or a shared toolkit being rented to multiple buyers. The line between financially motivated extortion crews and state-aligned operators has continued to blur, with several campaigns exhibiting the discipline, persistence, and infrastructure hygiene more often associated with apt-group-linked-to-state-actor-deploys-new-backdoor-in-energy-sector than with opportunistic cybercriminals.
Australian defenders are also tracking a quieter but related trend: the use of so-called "DDoS-as-a-service" marketplaces by ideologically motivated actors who rent capacity for short, sharp campaigns against banks perceived to be involved in politically sensitive sectors such as fossil fuel financing or defence contracts. This adds a reputational dimension to the technical challenge, because institutions can be targeted not for what they host on their networks but for what they fund in the broader economy.
Threats defenders are watching alongside the financial-sector wave:
- Ransomware operators using volumetric DDoS as a smokescreen while data exfiltration is in progress
- Supply-chain attacks on smaller fintech intermediaries with weaker DDoS postures
- Targeting of cross-border payment messaging systems such as SWIFT member endpoints and real-time gross settlement gateways
- Manipulation of public-facing status pages and investor relations channels to amplify the reputational damage of an outage
- Long-tail extortion that resumes DDoS pressure even after a ransom is paid, eroding trust in negotiated settlements
The 2 Tbps event is unlikely to be the last word in this cycle. Australian banks, regulators, and downstream service providers have absorbed the test and emerged with lessons that will inform infrastructure spend, contract renegotiation, and supervisory engagement for the rest of the decade. For now, the message from the scrubbing centre floors in Sydney and Singapore is the same one CISOs have been repeating for years: capacity is no longer optional, and the next flood is already being prepared.
SecNews24.com