Russian e-commerce giant Wildberries says DDoS attack delayed payments to sellers
Wildberries told several Russian media outlets earlier this week that payments to some sellers were delayed by security measures introduced after a distributed denial-of-service (DDoS) attack targeted systems used to track and withdraw their earnings.
In mid-to-late June 2026, Read the Docs faced the largest and most sophisticated distributed denial-of-service (DDoS) attack in its history. The attack peaked with over 5.5 million requests per minute, which is about 100 times the usual daily peak traffic of under 100k requests per minute. The attack lasted nearly ten days, challenging the company's infrastructure, edge defenses, and incident response processes.
Unlike earlier traffic floods, this attack was more complex, adaptive, and specifically targeted areas designed to bypass caching. Read the Docs' small operations team had to resume normal working hours after addressing the situation. The company has traditionally allowed spiders and bots to scrape the documentation they host, and rate limiting based on IP addresses usually handled most abuse problems. However, in recent years, AI crawlers have become prevalent, leading to more sophisticated attacks.
The June attack was over 10 times larger than any previous incident Read the Docs had experienced. The malicious requests originated from millions of unique IP addresses across hundreds of networks worldwide, including residential IP blocks and major/minor hosting providers. Attackers used random HTTP request headers and TLS connection parameters to evade signature-based filters. They also targeted URLs that resulted in cache misses, such as non-existent pages with unique paths and temporary redirects.
Read the Docs' defenses adapted to AI-generated scrapers relatively easily, but the June attack was significantly larger than anything the company had faced before. The massive volume, global distribution, header and TLS randomization, cache evasion tactics, and adaptive behavior made this attack particularly challenging. The attacks targeted multiple Read the Docs properties, including public community documentation, commercially hosted docs, and author-facing dashboards requiring logins.
Despite considering a JavaScript challenge, the company opted for rate limiting and targeted challenges combined with more caching and pushing features out to the edge.
Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Understanding the recent DDoS attack against Read the Docs about.readthedocs.com