Skip to main content

CNiC Solutions

Data center at night representing a surge of DDoS attack traffic across the network in 2026

DDoS attacks more than doubled in 2025, with Cloudflare alone mitigating 47.1 million of them, up 121% in a single year, and blocking a record 31.4 Tbps assault that lasted just 35 seconds. Distributed denial-of-service traffic is now constant background noise on the internet, roughly 1.5 attacks every second. This 2026 reference gathers the DDoS numbers that matter from the primary sources that define the field: Cloudflare, NETSCOUT, and Akamai.

  • 47.1 million DDoS attacks were mitigated in 2025, up 121% year over year and 236% since 2023, per Cloudflare.
  • A record 31.4 Tbps attack set the largest publicly disclosed figure ever, lasting only 35 seconds and driven by the Aisuru-Kimwolf botnet.
  • Most attacks are small and short: 94% stayed under 500 Mbps and 89% of network-layer attacks ended in under 10 minutes.
  • Financial services is the top target for web and API DDoS at about 34% of attacks, with gaming second at 18%, per Akamai.
  • Around 1 in 3 targeted Cloudflare customers reported a ransom DDoS threat in Q2 2025 as extortion went mainstream.
  • NETSCOUT tracked 8 million+ attacks across 203 countries in the second half of 2025, increasingly guided by AI.
  • Hyper-volumetric attacks exploded, with 700+ attacks over 1 Tbps or 1 Bpps in Q1 2025 alone, about eight a day.

What’s in This Report

1How Many DDoS Attacks Are Happening

The clearest fact about DDoS in 2026 is volume. Attacks are not rare, targeted events reserved for banks and governments. They are a constant, automated hum against everything connected to the internet. Cloudflare, which sits in front of a large share of the world’s web traffic, put a hard number on it for 2025.

 

 

Infographic of key 2025 DDoS stats: 47.1M attacks, up 121%, a 31.4 Tbps record, 1.5 attacks per second
Four headline figures that define DDoS activity in 2025 (Source: Cloudflare 2025 DDoS Threat Reports).

 

 

47.1M
DDoS attacks Cloudflare mitigated in 2025, up 121% from the year before and 236% since 2023Source: Cloudflare 2025 Q4 DDoS Threat Report
+358%
Year-over-year surge in Q1 2025, when 20.5 million attacks made it the busiest quarter on recordSource: Cloudflare 2025 Q1 DDoS Threat Report
8M+
DDoS attacks NETSCOUT observed across 203 countries and territories in the second half of 2025Source: NETSCOUT DDoS Threat Intelligence Report, Issue 16

Cloudflare DDoS Attacks Mitigated Per Year

2023 (~14 million)
~14M
2024 (21.3 million)
21.3M
2025 (47.1 million)
47.1M

DDoS volume more than doubled in a single year and rose 236% over two. Source: Cloudflare 2025 Q4 DDoS Threat Report.

Averaged out, 47.1 million attacks in a year works out to about 5,376 every hour, or roughly 1.5 every second, every day, all year. NETSCOUT’s independent count from its ATLAS platform, more than 8 million attacks across 203 countries in just the second half of the year, confirms the same picture from a different vantage point: DDoS is global, automated, and relentless. The two data sets measure different networks, which is why the totals differ, but they agree on direction. The question for any business is no longer whether its infrastructure will be probed, but whether it can absorb a flood when one arrives.

Source: Cloudflare 2025 Q4 DDoS Threat Report | NETSCOUT DDoS Threat Intelligence Report

Protect your business with a DDoS-ready security review

2The Size Records That Keep Breaking

If frequency is the story at the bottom of the market, raw power is the story at the top. Throughout 2025, the record for the largest DDoS attack was broken repeatedly, and the pace of escalation was extraordinary. What would have been an unthinkable attack a year earlier became a routine headline within months.

31.4 Tbps
Largest publicly disclosed DDoS attack on record, lasting just 35 seconds, driven by the Aisuru-Kimwolf botnetSource: Cloudflare 2025 Q4 DDoS Threat Report
205M rps
Peak HTTP request rate recorded, alongside a packet-flood peak of 9 billion packets per secondSource: Cloudflare 2025 Q4 DDoS Threat Report
700+
Hyper-volumetric attacks in Q1 2025 alone, each above 1 Tbps or 1 Bpps, about eight every daySource: Cloudflare 2025 Q1 DDoS Threat Report

The 2025 DDoS Size Record, Broken Again and Again (peak Tbps)

Q1 2025 (5.6 Tbps)
5.6
May 2025 (7.3 Tbps)
7.3
Q3 2025 (29.7 Tbps)
29.7
Q4 2025 (31.4 Tbps)
31.4

The record roughly quadrupled across 2025 as botnet firepower jumped. Source: Cloudflare 2025 DDoS Threat Reports.

The jump between the second and third quarters is the one to notice. A 7.3 Tbps attack in May was, at the time, the largest ever seen. By the third quarter the Aisuru botnet had pushed a single attack to 29.7 Tbps, roughly four times larger, in a matter of months. These record-setting bursts are deliberately brief, often under a minute, because they are designed to overwhelm defenses instantly rather than sustain pressure. A 35-second, 31.4 Tbps hit does not need to last long to take an unprepared target offline. The same fast-moving threat landscape shows up in how quickly attackers now weaponize new vulnerabilities.

Source: Cloudflare 2025 Q3 DDoS Threat Report | Cloudflare on the 7.3 Tbps attack

Harden the network that has to absorb a volumetric flood

3Why Most Attacks Are Small and Short

The record-breaking attacks dominate the news, but they are the exception, not the rule. The overwhelming majority of DDoS events are small, brief, and cheap to launch. That is the single most important nuance in the data, because it changes who is actually at risk.

 

 

Split-panel comparing the 31.4 Tbps record DDoS attack with the typical sub-500-Mbps, under-10-minute attack
The median DDoS attack is small and short, not a terabit-scale giant (Source: Cloudflare 2025).

 

 

94%
Share of network-layer DDoS attacks that stayed below 500 Mbps, well within a small botnet’s reachSource: Cloudflare 2025 DDoS Threat Report
89%
Network-layer attacks that ended in under 10 minutes, over before manual defenses can respondSource: Cloudflare 2025 Q3 DDoS Threat Report
71%
HTTP (application-layer) attacks that also ended in under 10 minutesSource: Cloudflare 2025 Q3 DDoS Threat Report
Attack profile measure Figure Source
Network-layer attacks below 500 Mbps 94% Cloudflare 2025
Network-layer attacks under 10 minutes 89% Cloudflare 2025 Q3
HTTP attacks under 10 minutes 71% Cloudflare 2025 Q3
Duration of the record 31.4 Tbps attack 35 seconds Cloudflare 2025 Q4
Duration of the record 7.3 Tbps attack 45 seconds Cloudflare 2025 Q2

Myth: DDoS is only about record-breaking, terabit-scale attacks. The headline numbers are real, but they describe a tiny fraction of activity. In practice, 94% of network-layer attacks never exceed 500 Mbps and most are over within 10 minutes. A flood of that size is trivial for an attacker to rent, and it is still more than enough to take down a website, store, or application that has no automated mitigation in front of it. The businesses most exposed are not the ones being hit by 31.4 Tbps. They are the ones assuming a small attack could never reach them.

Source: Cloudflare 2025 Q2 DDoS Threat Report | Cloudflare 2025 Q3 DDoS Threat Report

Keep critical infrastructure online when traffic spikes

 

CNiC Solutions — Networking Services

 

4Who Gets Targeted

DDoS attackers are not indiscriminate. The data shows clear preferences by industry and region, shaped by where downtime is most painful and where extortion pays. Financial services has become the standout target, but the picture depends on whether you count network-layer floods or application-layer attacks.

34%
Share of web and API DDoS attacks aimed at financial services, the single most targeted industrySource: Akamai Financial Services Threat Report
18%
Share of DDoS attacks hitting the gaming sector, the second most targeted industrySource: Akamai State of the Internet
+738%
Rise in the median duration of Layer 3 and 4 DDoS attacks on financial firms since 2024Source: Akamai Financial Services Threat Report
Target measure Figure Source
Financial services share of web and API DDoS 34% Akamai
Gaming share of DDoS attacks 18% Akamai
Most attacked network-layer industry Telecom, service providers and carriers Cloudflare 2025
Financial-sector max volumetric attack scale +236% (2024 to 2025) Akamai
Financial-sector median L3/4 attack duration +738% since 2024 Akamai
Most attacked country in Q4 2025 China (then Hong Kong, Germany) Cloudflare 2025 Q4

Two shifts stand out. First, financial services is no longer just frequently attacked, it is attacked harder and for longer: Akamai measured the median duration of network-layer attacks on financial firms climbing 738% since 2024, and maximum attack scale rising 236%. Second, the most targeted network-layer industry in Cloudflare’s 2025 data was telecommunications, service providers, and carriers, the infrastructure that everyone else depends on. When a carrier or hosting provider is the target, every business riding on it can feel the outage, even if it was never the intended victim. That indirect exposure is why DDoS is a concern for organizations that assume they are too small to be worth attacking.

Source: Akamai State of the Internet research | Cloudflare 2025 Q4 DDoS Threat Report

Get always-on monitoring for your business systems

5The New Playbook: Botnets, AI, and Extortion

The reason attack sizes and volumes both jumped in 2025 is that the tooling behind DDoS matured. Massive botnets built from compromised routers, cameras, and IoT devices now supply the raw firepower, cheap rentals put it in anyone’s hands, extortion turns it into a business model, and AI lowers the skill required to run a campaign.

1–4M
Estimated infected hosts in the Aisuru botnet behind 2025’s record attacks, one of the largest ever trackedSource: Cloudflare 2025 Q3 DDoS Threat Report
~33%
Targeted Cloudflare customers who reported a ransom DDoS threat or attack in Q2 2025Source: Cloudflare 2025 Q2 DDoS Threat Report
750–830
Carpet-bombing attacks per day in the second half of 2025, spreading floods across many IPs at onceSource: NETSCOUT DDoS Threat Intelligence Report, Issue 16
Playbook trend Figure or detail Source
Aisuru botnet size 1 to 4 million infected hosts Cloudflare 2025 Q3
Customers reporting ransom DDoS (Q2 2025) ~33% Cloudflare 2025 Q2
Carpet-bombing attacks per day (2H 2025) 750 to 830 NETSCOUT
Hyper-volumetric attacks in one 18-day campaign 902 (about 53 per day) Cloudflare 2025 Q4
Common blended attack vectors DNS amplification, SSDP, SNMP, mDNS, memcached, CLDAP, TCP floods NETSCOUT

Source: NETSCOUT on botnet-driven DDoS in 2H 2025 | Cloudflare on the Aisuru botnet

Build a DDoS response plan with a virtual CIO

6What the Data Means for Small and Midsize Businesses

Read together, the 2025 numbers tell a story that is easy to misread. The record-breaking attacks suggest DDoS is a problem for hyperscalers and banks. The frequency and size distribution say something very different for everyone else.

+121%
Year-over-year growth in total DDoS attacks in 2025, the second straight year of triple-digit increasesSource: Cloudflare 2025 Q4 DDoS Threat Report
5,376
DDoS attacks mitigated per hour in 2025, on average, across Cloudflare’s network aloneSource: Cloudflare 2025 Q4 DDoS Threat Report
203
Countries and territories where NETSCOUT observed DDoS activity in the second half of 2025Source: NETSCOUT DDoS Threat Intelligence Report, Issue 16

The defensive takeaway is not to fear the headline attack. It is to assume the ordinary one. A short, modest flood that arrives without warning is the common case, and the only reliable answer is mitigation that reacts in seconds without a person in the loop. For most organizations that means putting the network, hosting, and continuity plan in the hands of a team that watches them around the clock. The same logic applies to the broader threat landscape, from ransomware to third-party and supply chain attack data, where speed of response consistently separates a contained incident from a costly one.

Source: Cloudflare 2025 Q4 DDoS Threat Report | NETSCOUT DDoS Threat Intelligence Report

Plan for continuity when an attack lands

Full Statistics Table

Statistic Figure Source Year
Total DDoS attacks mitigated 47.1 million Cloudflare 2025
Year-over-year growth in attacks +121% Cloudflare 2025
Growth in attacks since 2023 +236% Cloudflare 2025
Attacks mitigated per hour (average) 5,376 Cloudflare 2025
Q1 attacks and YoY surge 20.5 million (+358%) Cloudflare 2025
Attacks observed across 203 countries 8 million+ (2H) NETSCOUT 2025
Largest attack ever recorded 31.4 Tbps (35 seconds) Cloudflare 2025
Botnet behind the record attack Aisuru-Kimwolf Cloudflare 2025
Peak HTTP request rate 205 million rps Cloudflare 2025
Peak packet rate 9 billion pps Cloudflare 2025
Prior record attack (May) 7.3 Tbps Cloudflare 2025
Q3 record attack (Aisuru) 29.7 Tbps Cloudflare 2025
Hyper-volumetric attacks in Q1 700+ (about 8 per day) Cloudflare 2025
Network-layer attacks below 500 Mbps 94% Cloudflare 2025
Network-layer attacks under 10 minutes 89% Cloudflare 2025
HTTP attacks under 10 minutes 71% Cloudflare 2025
Financial services share of web/API DDoS 34% Akamai 2025
Gaming share of DDoS attacks 18% Akamai 2025
Financial-sector L3/4 attack duration rise +738% since 2024 Akamai 2025
Customers reporting ransom DDoS (Q2) ~33% Cloudflare 2025
Aisuru botnet size 1 to 4 million hosts Cloudflare 2025
Carpet-bombing attacks per day (2H) 750 to 830 NETSCOUT 2025
Hyper-volumetric attacks in one 18-day campaign 902 (about 53/day) Cloudflare 2025

Frequently Asked Questions

How many DDoS attacks happened in 2025?

Cloudflare mitigated 47.1 million DDoS attacks across its network in 2025, a 121% increase over the prior year and a 236% rise since 2023, averaging about 5,376 attacks every hour, or roughly 1.5 every second. The year opened with a record quarter of 20.5 million attacks in Q1 alone, up 358% year over year. Separately, NETSCOUT observed more than 8 million DDoS attacks across 203 countries and territories in the second half of 2025. DDoS is now constant background activity on the internet rather than an occasional event.

What was the largest DDoS attack ever recorded?

The largest publicly disclosed DDoS attack on record peaked at 31.4 terabits per second (Tbps) and lasted just 35 seconds, blocked by Cloudflare in the fourth quarter of 2025 and attributed to the Aisuru-Kimwolf botnet. It capped a year of escalating records: Cloudflare blocked a 7.3 Tbps attack in May 2025 and a 29.7 Tbps attack in the third quarter. The same period produced peaks of 9 billion packets per second and 205 million HTTP requests per second.

How long do most DDoS attacks last?

Most DDoS attacks are short and small, not the record-breaking giants that make headlines. Cloudflare found that 89% of network-layer attacks and 71% of HTTP attacks ended in under 10 minutes, and that 94% of network-layer attacks stayed below 500 megabits per second. The pattern matters because a brief, modest flood is still enough to knock an unprotected website or application offline before anyone can react manually.

Which industries are targeted most by DDoS attacks?

Financial services is the single most targeted industry for web and API DDoS attacks, accounting for about 34% of attacks according to Akamai, with gaming second at roughly 18%. For network-layer attacks, Cloudflare ranked telecommunications, service providers, and carriers as the most attacked sector in 2025, ahead of the internet, IT and services, and gambling and casino industries. Akamai also reported that the median duration of Layer 3 and 4 attacks on financial firms rose 738% since 2024.

What is a ransom DDoS attack and how common is it?

A ransom DDoS attack is extortion: attackers threaten or launch a flood of traffic and demand payment to stop or stay away. It has become common. Cloudflare reported that around a third of its customers targeted by DDoS in the second quarter of 2025 said they were threatened with or hit by a ransom DDoS attack. The trend is amplified by cheap botnet rentals and, per NETSCOUT, AI chat interfaces that walk even unskilled attackers through launching complex campaigns.

Methodology & Sources

The volume, size, duration, industry, country, ransom, and botnet figures come from Cloudflare’s 2025 DDoS Threat Reports (Q1 through Q4), which are based on attacks automatically detected and mitigated across Cloudflare’s global network. Specifically: the 47.1 million annual total, the 121% year-over-year and 236% two-year growth, the 5,376 attacks-per-hour average, the 31.4 Tbps record attack (35 seconds, Aisuru-Kimwolf botnet), the 205 million requests-per-second and 9 billion packets-per-second peaks, the 94% under-500-Mbps and 89%/71% under-10-minute distributions, the 700-plus Q1 hyper-volumetric attacks, the 20.5 million Q1 total (+358%), the 1-to-4-million-host Aisuru estimate, the roughly one-third ransom DDoS figure for Q2 2025, and the 902-attack “Night Before Christmas” campaign are all from Cloudflare. The 8 million-plus attacks across 203 countries in the second half of 2025, the 750-to-830 daily carpet-bombing figure, the blended-vector detail, and the AI-assisted attack trend come from the NETSCOUT DDoS Threat Intelligence Report, Issue 16 (findings from 2H 2025), drawn from its ATLAS global threat intelligence platform. The financial-services share of web and API DDoS (34%), the gaming share (18%), the 738% rise in median Layer 3/4 attack duration, and the 236% rise in maximum volumetric scale for financial firms come from Akamai’s State of the Internet and Financial Services threat research. Only Tier 1 primary telemetry and named vendor reports with disclosed methodology are used. No statistics were invented or estimated beyond the clearly labeled CNiC Solutions analysis, which combines published Cloudflare and NETSCOUT figures. This article is informational and is not a security assessment of any specific business.

 

author avatar
David McFarlene Founder & CEO
David McFarlene is the owner and founder of CNiC Solutions, a trusted IT services and cybersecurity company serving the Houston, TX area. With over 20 years of experience in managed IT, infrastructure design, cloud solutions, and data security, David helps businesses and homeowners stay protected and productive through dependable, personalized technology support. He leads the CNiC Solutions team with a focus on reliability, transparency, and long-term relationships, ensuring clients always have a knowledgeable expert they can trust.
back to blog