this post was submitted on 13 Aug 2026
196 points (99.5% liked)
Technology
87279 readers
4138 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
It's late and I'm tired so my math could be wrong but if they downloaded 195 TB in 40 minutes then the attacker is working with an internet connection that is at least 81.25 Gigabytes (not bits) per second. That isn't a script kiddie. That's serious business.
From what I am understanding, it was a 40 minute window when the malicious model was available to download in the repositories. After it was downloaded, they had all the time until it was detected in the organization to exfiltrate the data, which was potentially weeks or months.
Download doesn't necessarily mean that they dumped everything on their local PC - they could just upload everything from all those servers to an S3 bucket or whatever.
That way the bottleneck would be either the ingress of the hyperscalers or the egress of the attacked company (which probably uses the hyperscalers anyway). I probably could also do that this way with my humble home Internet connection on a semi reliable WiFi....