Understanding the Recent DDoS Attack Against Read the Docs

Read the Docs experienced a record-breaking DDoS attack in June 2026, peaking at 5.5 million requests per minute. The incident highlighted the limitations of traditional IP-based rate limiting against sophisticated, distributed botnets.
Why it matters
As AI crawlers and automated scrapers become more prevalent, infrastructure providers face increasing challenges in maintaining availability against high-volume, adaptive traffic.
In mid-to-late June 2026, Read the Docs experienced the largest and most sophisticated distributed denial-of-service (DDoS) attack in our history. At its peak, our infrastructure was hit with over 5.5 million requests per minute , about 100 times our normal baseline traffic.
The incident lasted for nearly ten days, testing our infrastructure, our edge defenses, and our incident response processes. Unlike simpler traffic floods we've seen in the past, this attack was more distributed, it adapted to our defenses rapidly, and it purposefully attacked areas that bypassed caching.
Now that our small ops team is back to sleeping at normal hours, we wanted to walk through the anatomy of this kind of attack, why our existing rate limiting only partially mitigated it, and what strategies actually helped us (mostly) maintain availability throughout the attack.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in