On the evening of 11 August 2026, one of our customers became the target of one of the largest attacks we have ever seen directed at our infrastructure. Because we provide that customer’s connection to the internet, the impact hit us directly as well, and a few hours later the attacker turned against our own services too. We already published a technical postmortem as a PDF on this incident. In this post, we want to walk through what actually happened over those three days in more depth, why handling an attack of this size took as long as it did, and what we have changed in our infrastructure since.