Four Billion Requests: The DDoS Campaign That Followed Our Meta Abuse-Ad Reporting

Cloudflare’s dashboard showed roughly four billion edge requests across the attack window. The flood first targeted one investigation, moved to our homepage when blocked, and returned weeks later.

Roughly four billion requests.

That is what Cloudflare’s HTTP Traffic dashboard showed across the selected attack window after AI Weekly reported on Meta’s advertising pipeline for nudify apps and serious child-safety allegations.

Not four million. Four billion.

The first attack began at 02:42 UTC on August 22—just 33½ hours after we updated our investigation into Meta advertising partner GatherOne.

It did not hit the site indiscriminately. It hammered that exact article.

In the final retained sample of 100,000 requests, 95,603 targeted the investigation. Almost 95,000 used randomized query strings to bypass caching. More than 33,000 were POST requests, and over 95,000 arrived without a referrer. The traffic came from thousands of addresses.

The attack exhausted all 4,096 available Nginx worker connections, generated roughly 41 GB of logs and drove the server’s 75 GB disk to 100% usage. Tens of thousands of requests ended in server errors. Backups and production jobs failed.

Cloudflare showed approximately four billion requests at its edge. The number is vastly larger than our origin count because traffic blocked or absorbed by Cloudflare never reached our server—and therefore never entered our Nginx logs.

Call it what it was: a massive attack.

Our reporting covered findings by the Tech Transparency Project. Meta’s own disclosures named GatherOne or related company Hongkong Gather Wisdom as advertiser and payer for 210 Facebook pages that collectively ran roughly 30,800 AI and face-swap advertisements.

Forty-three pages ran more than 7,600 ads for apps that TTP verified could digitally undress women. Ads from 179 pages were removed by Meta for violating sexual-content policies.

One advertised app, BAfter, contained an explicitly pornographic sharing area. Six Google Play reviewers alleged that it contained sexual images or videos of children.

Those allegations did not prove that GatherOne created, possessed or knowingly promoted child sexual abuse material. We corrected our reporting to make that distinction explicit. GatherOne said it had zero tolerance for such content, suspended new advertising accounts involving nudify services and terminated access for the entity associated with BAfter. Meta said it banned the app.

Then came the flood.

When we defended the article, the campaign moved to our homepage. On August 24, a second wave generated approximately 2.5 million requests at our origin from 14,290 IP addresses. It peaked at 176,152 requests per minute—nearly 3,000 every second. It included 771,000 POST requests and caused approximately 2.43 million server errors.

The same attack patterns returned again in September.

On September 6, hundreds of requests from 509 different IP addresses converged on the original article within three hours. On September 9, another wave produced thousands of origin requests and more than 3,600 server failures while Cloudflare blocked additional traffic upstream.

We have no evidence that Meta, GatherOne, Hongkong Gather Wisdom or any named advertising partner launched, ordered or knew about these attacks. We are not accusing them.

We are stating the facts:

We published an investigation. Someone flooded that exact investigation. When it was defended, the traffic moved to our homepage. Weeks later, it returned.

Four billion requests are not criticism. They are not a rebuttal. They are infrastructure being weaponized against reporting.

Whoever did it failed.

The investigation remains online. The evidence remains public. And we are not shutting up.