Note that the resources required to launch that attack were relatively small. From the cloudflare article:
it is possible that the attacker used only a single server running on a network that allowed source IP address spoofing
So perhaps one technically adept attacker, which isn't quite so surprising.