Okay, so that was terrifying. 😅 I run a small SaaS for team collaboration, and yesterday we got one of those ransom notes saying "pay X amount or we'll take your site down." I thought it was a bluff, but an hour later, our login page was completely unreachable.
I panicked and called Cloudflare support. The good news is that once I got through (after about 20 minutes on hold), the person was really helpful. They confirmed the attack was hitting our origin IP and helped me double-check that all our traffic was properly proxied through them. The attack basically bounced off. Our site stayed up for users already on the platform, which was a huge relief.
But that 20-minute wait during an active attack felt like forever. My heart was just pounding. I'm super grateful Cloudflare's protection worked like everyone says it does, but has anyone else had to contact their support during an actual DDoS? Is that a typical wait time? I'm wondering if I should have used the ticket system instead of calling, or if there's something I can set up now to be even more prepared for next time.