Four Billion Requests: The DDoS Campaign That Followed Our Meta Abuse-Ad Reporting
A large-scale distributed denial-of-service (DDoS) campaign targeted AI Weekly following their investigative reporting on Meta's advertising partner GatherOne and associated nudify apps with child-safety concerns. The attack generated roughly four billion HTTP requests, primarily targeting the specific investigative article. The campaign caused significant server resource exhaustion, including maxing out Nginx worker connections, filling disk storage, and causing numerous server errors and job failures. The attack persisted in waves, shifting focus from the article to the homepage when mitigated, and returning weeks later. There is no evidence implicating Meta, GatherOne, or related entities in orchestrating the attacks. The campaign weaponized infrastructure to disrupt reporting rather than engage in direct rebuttal or criticism.
AI Analysis
Technical Summary
Following AI Weekly's report on Meta's advertising partner GatherOne and allegations concerning nudify apps, a massive DDoS campaign ensued, generating approximately four billion HTTP requests over multiple waves. The initial attack began 33.5 hours after publication, targeting the exact investigative article with randomized query strings to bypass caching and a high volume of POST requests. The attack overwhelmed server resources, including exhausting all 4,096 Nginx worker connections and filling the server disk to 100% capacity, causing tens of thousands of server errors and failures in backups and production jobs. Cloudflare's edge network absorbed much of the traffic, indicating a significantly larger volume than what reached the origin server. Subsequent waves targeted the homepage and returned weeks later with similar patterns. The campaign leveraged thousands of IP addresses and generated millions of requests per minute at peak. No evidence links the named companies to the attack, which appears to be an infrastructure weaponization against investigative reporting.
Potential Impact
The DDoS campaign caused severe resource exhaustion on AI Weekly's origin server, including maxing out Nginx worker connections, filling disk storage to capacity, generating tens of thousands of server errors, and causing failures in backups and production jobs. The attack disrupted normal website operations and availability, particularly affecting the investigative article and later the homepage. Cloudflare mitigated much of the traffic at the edge, preventing even greater impact on the origin infrastructure.
Mitigation Recommendations
Cloudflare's edge network absorbed and blocked a significant portion of the attack traffic, reducing the load on the origin server. AI Weekly defended the targeted article and homepage by leveraging Cloudflare's mitigation capabilities. No official patch or fix applies as this is a DDoS campaign rather than a software vulnerability. Continued use of robust DDoS protection services and monitoring for attack patterns is recommended. There is no indication that the named companies are responsible or that further action against them is warranted based on this incident.
Four Billion Requests: The DDoS Campaign That Followed Our Meta Abuse-Ad Reporting
Description
A large-scale distributed denial-of-service (DDoS) campaign targeted AI Weekly following their investigative reporting on Meta's advertising partner GatherOne and associated nudify apps with child-safety concerns. The attack generated roughly four billion HTTP requests, primarily targeting the specific investigative article. The campaign caused significant server resource exhaustion, including maxing out Nginx worker connections, filling disk storage, and causing numerous server errors and job failures. The attack persisted in waves, shifting focus from the article to the homepage when mitigated, and returning weeks later. There is no evidence implicating Meta, GatherOne, or related entities in orchestrating the attacks. The campaign weaponized infrastructure to disrupt reporting rather than engage in direct rebuttal or criticism.
Reddit Discussion
Cloudflare’s dashboard showed roughly four billion edge requests across the attack window. The flood first targeted one investigation, moved to our homepage when blocked, and returned weeks later.
Roughly four billion requests.
That is what Cloudflare’s HTTP Traffic dashboard showed across the selected attack window after AI Weekly reported on Meta’s advertising pipeline for nudify apps and serious child-safety allegations.
Four billion.
The first attack began at 02:42 UTC on August 22—just 33½ hours after we updated our investigation into Meta advertising partner GatherOne.
It did not hit the site indiscriminately. It hammered that exact article.
In the final retained sample of 100,000 requests, 95,603 targeted the investigation. Almost 95,000 used randomized query strings to bypass caching. More than 33,000 were POST requests, and over 95,000 arrived without a referrer. The traffic came from thousands of addresses.
The attack exhausted all 4,096 available Nginx worker connections, generated roughly 41 GB of logs and drove the server’s 75 GB disk to 100% usage. Tens of thousands of requests ended in server errors. Backups and production jobs failed.
Cloudflare showed approximately four billion requests at its edge. The number is vastly larger than our origin count because traffic blocked or absorbed by Cloudflare never reached our server—and therefore never entered our Nginx logs.
Call it what it was: a massive attack.
Our reporting covered findings by the Tech Transparency Project. Meta’s own disclosures named GatherOne or related company Hongkong Gather Wisdom as advertiser and payer for 210 Facebook pages that collectively ran roughly 30,800 AI and face-swap advertisements.
Forty-three pages ran more than 7,600 ads for apps that TTP verified could digitally undress women. Ads from 179 pages were removed by Meta for violating sexual-content policies.
One advertised app, BAfter, contained an explicitly pornographic sharing area. Six Google Play reviewers alleged that it contained sexual images or videos of children.
Those allegations did not prove that GatherOne created, possessed or knowingly promoted child sexual abuse material. We corrected our reporting to make that distinction explicit. GatherOne said it had zero tolerance for such content, suspended new advertising accounts involving nudify services and terminated access for the entity associated with BAfter. Meta said it banned the app.
Then came the flood.
When we defended the article, the campaign moved to our homepage. On August 24, a second wave generated approximately 2.5 million requests at our origin from 14,290 IP addresses. It peaked at 176,152 requests per minute—nearly 3,000 every second. It included 771,000 POST requests and caused approximately 2.43 million server errors.
The same attack patterns returned again in September.
On September 6, hundreds of requests from 509 different IP addresses converged on the original article within three hours. On September 9, another wave produced thousands of origin requests and more than 3,600 server failures while Cloudflare blocked additional traffic upstream.
We have no evidence that Meta, GatherOne, Hongkong Gather Wisdom or any named advertising partner launched, ordered or knew about these attacks. We are not accusing them.
We are stating the facts:
We published an investigation. Someone flooded that exact investigation. When it was defended, the traffic moved to our homepage. Weeks later, it returned.
Four billion requests are not criticism. They are not a rebuttal. They are infrastructure being weaponized against reporting.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Following AI Weekly's report on Meta's advertising partner GatherOne and allegations concerning nudify apps, a massive DDoS campaign ensued, generating approximately four billion HTTP requests over multiple waves. The initial attack began 33.5 hours after publication, targeting the exact investigative article with randomized query strings to bypass caching and a high volume of POST requests. The attack overwhelmed server resources, including exhausting all 4,096 Nginx worker connections and filling the server disk to 100% capacity, causing tens of thousands of server errors and failures in backups and production jobs. Cloudflare's edge network absorbed much of the traffic, indicating a significantly larger volume than what reached the origin server. Subsequent waves targeted the homepage and returned weeks later with similar patterns. The campaign leveraged thousands of IP addresses and generated millions of requests per minute at peak. No evidence links the named companies to the attack, which appears to be an infrastructure weaponization against investigative reporting.
Potential Impact
The DDoS campaign caused severe resource exhaustion on AI Weekly's origin server, including maxing out Nginx worker connections, filling disk storage to capacity, generating tens of thousands of server errors, and causing failures in backups and production jobs. The attack disrupted normal website operations and availability, particularly affecting the investigative article and later the homepage. Cloudflare mitigated much of the traffic at the edge, preventing even greater impact on the origin infrastructure.
Defensive Guidance
Cloudflare's edge network absorbed and blocked a significant portion of the attack traffic, reducing the load on the origin server. AI Weekly defended the targeted article and homepage by leveraging Cloudflare's mitigation capabilities. No official patch or fix applies as this is a DDoS campaign rather than a software vulnerability. Continued use of robust DDoS protection services and monitoring for attack patterns is recommended. There is no indication that the named companies are responsible or that further action against them is warranted based on this incident.
Technical Details
- Source Type
- Subreddit
- blueteamsec+AskNetsec+Information_Security
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":33,"reasons":["external_link","newsworthy_keywords:campaign","non_newsworthy_keywords:meta","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["campaign"],"foundNonNewsworthy":["meta"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6aa2c3648744ddd5a6cc1c3a
Added to database: 09/10/2026, 14:49:08 UTC
Last enriched: 09/10/2026, 14:49:36 UTC
Last updated: 09/10/2026, 17:37:36 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.