Skip to main content

Four Billion Requests: The DDoS Campaign That Followed Our Meta Abuse-Ad Reporting

0
Medium
Published: 09/09/2026 (09/09/2026, 21:54:05 UTC)
Source: Reddit BlueTeam

Description

A large-scale distributed denial-of-service (DDoS) campaign targeted AI Weekly following their investigative reporting on Meta's advertising partner GatherOne and associated nudify apps with child-safety concerns. The attack generated roughly four billion HTTP requests, primarily targeting the specific investigative article. The campaign caused significant server resource exhaustion, including maxing out Nginx worker connections, filling disk storage, and causing numerous server errors and job failures. The attack persisted in waves, shifting focus from the article to the homepage when mitigated, and returning weeks later. There is no evidence implicating Meta, GatherOne, or related entities in orchestrating the attacks. The campaign weaponized infrastructure to disrupt reporting rather than engage in direct rebuttal or criticism.

Reddit Discussion

r/Information_Security·posted by u/Justgototheeffinmoon
00

Cloudflare’s dashboard showed roughly four billion edge requests across the attack window. The flood first targeted one investigation, moved to our homepage when blocked, and returned weeks later.

Roughly four billion requests.

That is what Cloudflare’s HTTP Traffic dashboard showed across the selected attack window after AI Weekly reported on Meta’s advertising pipeline for nudify apps and serious child-safety allegations.

Four billion.

The first attack began at 02:42 UTC on August 22—just 33½ hours after we updated our investigation into Meta advertising partner GatherOne.

It did not hit the site indiscriminately. It hammered that exact article.

In the final retained sample of 100,000 requests, 95,603 targeted the investigation. Almost 95,000 used randomized query strings to bypass caching. More than 33,000 were POST requests, and over 95,000 arrived without a referrer. The traffic came from thousands of addresses.

The attack exhausted all 4,096 available Nginx worker connections, generated roughly 41 GB of logs and drove the server’s 75 GB disk to 100% usage. Tens of thousands of requests ended in server errors. Backups and production jobs failed.

Cloudflare showed approximately four billion requests at its edge. The number is vastly larger than our origin count because traffic blocked or absorbed by Cloudflare never reached our server—and therefore never entered our Nginx logs.

Call it what it was: a massive attack.

Our reporting covered findings by the Tech Transparency Project. Meta’s own disclosures named GatherOne or related company Hongkong Gather Wisdom as advertiser and payer for 210 Facebook pages that collectively ran roughly 30,800 AI and face-swap advertisements.

Forty-three pages ran more than 7,600 ads for apps that TTP verified could digitally undress women. Ads from 179 pages were removed by Meta for violating sexual-content policies.

One advertised app, BAfter, contained an explicitly pornographic sharing area. Six Google Play reviewers alleged that it contained sexual images or videos of children.

Those allegations did not prove that GatherOne created, possessed or knowingly promoted child sexual abuse material. We corrected our reporting to make that distinction explicit. GatherOne said it had zero tolerance for such content, suspended new advertising accounts involving nudify services and terminated access for the entity associated with BAfter. Meta said it banned the app.

Then came the flood.

When we defended the article, the campaign moved to our homepage. On August 24, a second wave generated approximately 2.5 million requests at our origin from 14,290 IP addresses. It peaked at 176,152 requests per minute—nearly 3,000 every second. It included 771,000 POST requests and caused approximately 2.43 million server errors.

The same attack patterns returned again in September.

On September 6, hundreds of requests from 509 different IP addresses converged on the original article within three hours. On September 9, another wave produced thousands of origin requests and more than 3,600 server failures while Cloudflare blocked additional traffic upstream.

We have no evidence that Meta, GatherOne, Hongkong Gather Wisdom or any named advertising partner launched, ordered or knew about these attacks. We are not accusing them.

We are stating the facts:

We published an investigation. Someone flooded that exact investigation. When it was defended, the traffic moved to our homepage. Weeks later, it returned.

Four billion requests are not criticism. They are not a rebuttal. They are infrastructure being weaponized against reporting.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 14:49:36 UTC

Technical Analysis

Following AI Weekly's report on Meta's advertising partner GatherOne and allegations concerning nudify apps, a massive DDoS campaign ensued, generating approximately four billion HTTP requests over multiple waves. The initial attack began 33.5 hours after publication, targeting the exact investigative article with randomized query strings to bypass caching and a high volume of POST requests. The attack overwhelmed server resources, including exhausting all 4,096 Nginx worker connections and filling the server disk to 100% capacity, causing tens of thousands of server errors and failures in backups and production jobs. Cloudflare's edge network absorbed much of the traffic, indicating a significantly larger volume than what reached the origin server. Subsequent waves targeted the homepage and returned weeks later with similar patterns. The campaign leveraged thousands of IP addresses and generated millions of requests per minute at peak. No evidence links the named companies to the attack, which appears to be an infrastructure weaponization against investigative reporting.

Potential Impact

The DDoS campaign caused severe resource exhaustion on AI Weekly's origin server, including maxing out Nginx worker connections, filling disk storage to capacity, generating tens of thousands of server errors, and causing failures in backups and production jobs. The attack disrupted normal website operations and availability, particularly affecting the investigative article and later the homepage. Cloudflare mitigated much of the traffic at the edge, preventing even greater impact on the origin infrastructure.

Defensive Guidance

Cloudflare's edge network absorbed and blocked a significant portion of the attack traffic, reducing the load on the origin server. AI Weekly defended the targeted article and homepage by leveraging Cloudflare's mitigation capabilities. No official patch or fix applies as this is a DDoS campaign rather than a software vulnerability. Continued use of robust DDoS protection services and monitoring for attack patterns is recommended. There is no indication that the named companies are responsible or that further action against them is warranted based on this incident.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
blueteamsec+AskNetsec+Information_Security
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":33,"reasons":["external_link","newsworthy_keywords:campaign","non_newsworthy_keywords:meta","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["campaign"],"foundNonNewsworthy":["meta"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6aa2c3648744ddd5a6cc1c3a

Added to database: 09/10/2026, 14:49:08 UTC

Last enriched: 09/10/2026, 14:49:36 UTC

Last updated: 09/10/2026, 17:37:36 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses