We experienced a DDoS attack on one of our clients, specifically to our SFO PoP at around 12:50 UTC which in turn overwhelmed the nodes on this ADN. When we noticed the spike we started to take mitigation acts and sort through the customers that were serving traffic there to find the bad neighbor. At the same time we began bringing on extra emergency capacity to absorb the load. Once the attack was mitigated (around 15:00 UTC) we left the capacity online in case of a resurgence.