DDoS attacks more than doubled in 2025, with Cloudflare alone mitigating 47.1 million of them, up 121% in a single year, and blocking a record 31.4 Tbps assault that lasted just 35 seconds. Distributed denial-of-service traffic is now constant background noise on the internet, roughly 1.5 attacks every second. This 2026 reference gathers the DDoS numbers that matter from the primary sources that define the field: Cloudflare, NETSCOUT, and Akamai.
The clearest fact about DDoS in 2026 is volume. Attacks are not rare, targeted events reserved for banks and governments. They are a constant, automated hum against everything connected to the internet. Cloudflare, which sits in front of a large share of the world’s web traffic, put a hard number on it for 2025.

Cloudflare DDoS Attacks Mitigated Per Year
DDoS volume more than doubled in a single year and rose 236% over two. Source: Cloudflare 2025 Q4 DDoS Threat Report.
Averaged out, 47.1 million attacks in a year works out to about 5,376 every hour, or roughly 1.5 every second, every day, all year. NETSCOUT’s independent count from its ATLAS platform, more than 8 million attacks across 203 countries in just the second half of the year, confirms the same picture from a different vantage point: DDoS is global, automated, and relentless. The two data sets measure different networks, which is why the totals differ, but they agree on direction. The question for any business is no longer whether its infrastructure will be probed, but whether it can absorb a flood when one arrives.
Source: Cloudflare 2025 Q4 DDoS Threat Report | NETSCOUT DDoS Threat Intelligence Report
Protect your business with a DDoS-ready security review
If frequency is the story at the bottom of the market, raw power is the story at the top. Throughout 2025, the record for the largest DDoS attack was broken repeatedly, and the pace of escalation was extraordinary. What would have been an unthinkable attack a year earlier became a routine headline within months.
The 2025 DDoS Size Record, Broken Again and Again (peak Tbps)
The record roughly quadrupled across 2025 as botnet firepower jumped. Source: Cloudflare 2025 DDoS Threat Reports.
The jump between the second and third quarters is the one to notice. A 7.3 Tbps attack in May was, at the time, the largest ever seen. By the third quarter the Aisuru botnet had pushed a single attack to 29.7 Tbps, roughly four times larger, in a matter of months. These record-setting bursts are deliberately brief, often under a minute, because they are designed to overwhelm defenses instantly rather than sustain pressure. A 35-second, 31.4 Tbps hit does not need to last long to take an unprepared target offline. The same fast-moving threat landscape shows up in how quickly attackers now weaponize new vulnerabilities.
Source: Cloudflare 2025 Q3 DDoS Threat Report | Cloudflare on the 7.3 Tbps attack
Harden the network that has to absorb a volumetric flood
The record-breaking attacks dominate the news, but they are the exception, not the rule. The overwhelming majority of DDoS events are small, brief, and cheap to launch. That is the single most important nuance in the data, because it changes who is actually at risk.

| Attack profile measure | Figure | Source |
|---|---|---|
| Network-layer attacks below 500 Mbps | 94% | Cloudflare 2025 |
| Network-layer attacks under 10 minutes | 89% | Cloudflare 2025 Q3 |
| HTTP attacks under 10 minutes | 71% | Cloudflare 2025 Q3 |
| Duration of the record 31.4 Tbps attack | 35 seconds | Cloudflare 2025 Q4 |
| Duration of the record 7.3 Tbps attack | 45 seconds | Cloudflare 2025 Q2 |
Myth: DDoS is only about record-breaking, terabit-scale attacks. The headline numbers are real, but they describe a tiny fraction of activity. In practice, 94% of network-layer attacks never exceed 500 Mbps and most are over within 10 minutes. A flood of that size is trivial for an attacker to rent, and it is still more than enough to take down a website, store, or application that has no automated mitigation in front of it. The businesses most exposed are not the ones being hit by 31.4 Tbps. They are the ones assuming a small attack could never reach them.
Source: Cloudflare 2025 Q2 DDoS Threat Report | Cloudflare 2025 Q3 DDoS Threat Report
Keep critical infrastructure online when traffic spikes
DDoS attackers are not indiscriminate. The data shows clear preferences by industry and region, shaped by where downtime is most painful and where extortion pays. Financial services has become the standout target, but the picture depends on whether you count network-layer floods or application-layer attacks.
| Target measure | Figure | Source |
|---|---|---|
| Financial services share of web and API DDoS | 34% | Akamai |
| Gaming share of DDoS attacks | 18% | Akamai |
| Most attacked network-layer industry | Telecom, service providers and carriers | Cloudflare 2025 |
| Financial-sector max volumetric attack scale | +236% (2024 to 2025) | Akamai |
| Financial-sector median L3/4 attack duration | +738% since 2024 | Akamai |
| Most attacked country in Q4 2025 | China (then Hong Kong, Germany) | Cloudflare 2025 Q4 |
Two shifts stand out. First, financial services is no longer just frequently attacked, it is attacked harder and for longer: Akamai measured the median duration of network-layer attacks on financial firms climbing 738% since 2024, and maximum attack scale rising 236%. Second, the most targeted network-layer industry in Cloudflare’s 2025 data was telecommunications, service providers, and carriers, the infrastructure that everyone else depends on. When a carrier or hosting provider is the target, every business riding on it can feel the outage, even if it was never the intended victim. That indirect exposure is why DDoS is a concern for organizations that assume they are too small to be worth attacking.
Source: Akamai State of the Internet research | Cloudflare 2025 Q4 DDoS Threat Report
Get always-on monitoring for your business systems
The reason attack sizes and volumes both jumped in 2025 is that the tooling behind DDoS matured. Massive botnets built from compromised routers, cameras, and IoT devices now supply the raw firepower, cheap rentals put it in anyone’s hands, extortion turns it into a business model, and AI lowers the skill required to run a campaign.
| Playbook trend | Figure or detail | Source |
|---|---|---|
| Aisuru botnet size | 1 to 4 million infected hosts | Cloudflare 2025 Q3 |
| Customers reporting ransom DDoS (Q2 2025) | ~33% | Cloudflare 2025 Q2 |
| Carpet-bombing attacks per day (2H 2025) | 750 to 830 | NETSCOUT |
| Hyper-volumetric attacks in one 18-day campaign | 902 (about 53 per day) | Cloudflare 2025 Q4 |
| Common blended attack vectors | DNS amplification, SSDP, SNMP, mDNS, memcached, CLDAP, TCP floods | NETSCOUT |
AI is lowering the barrier to entry. NETSCOUT reports that conversational AI interfaces are now guiding even unskilled attackers through complex, multi-vector operations, blending techniques like DNS amplification and mixed TCP floods that once required real expertise. Combined with rentable botnets and carpet-bombing that sprays traffic across hundreds of addresses to slip past per-IP defenses, the result is more attacks, launched by more people, hitting more targets. Cloudflare’s late-December “Night Before Christmas” campaign packed 902 hyper-volumetric attacks into 18 days, a reminder that this is now industrial-scale, automated activity.
Source: NETSCOUT on botnet-driven DDoS in 2H 2025 | Cloudflare on the Aisuru botnet
Build a DDoS response plan with a virtual CIO
Read together, the 2025 numbers tell a story that is easy to misread. The record-breaking attacks suggest DDoS is a problem for hyperscalers and banks. The frequency and size distribution say something very different for everyone else.
CNiC Solutions Analysis: the attack you will actually face. Combine two Cloudflare findings and the real small-business risk profile appears. First, 94% of network-layer attacks stay under 500 Mbps and 89% end in under 10 minutes. Second, the network absorbs about 1.5 attacks every second, spread across 203 countries per NETSCOUT. The median DDoS event is therefore not a 31.4 Tbps monster, it is a brief, sub-500-Mbps flood that is cheap to launch and over before a human can react, yet still large enough to take an unprotected site offline. That profile is squarely within reach of any business, which is why automated, always-on mitigation matters more than the size of the record. Calculation and interpretation original to CNiC Solutions, based on Cloudflare 2025 and NETSCOUT Issue 16 figures.
The defensive takeaway is not to fear the headline attack. It is to assume the ordinary one. A short, modest flood that arrives without warning is the common case, and the only reliable answer is mitigation that reacts in seconds without a person in the loop. For most organizations that means putting the network, hosting, and continuity plan in the hands of a team that watches them around the clock. The same logic applies to the broader threat landscape, from ransomware to third-party and supply chain attack data, where speed of response consistently separates a contained incident from a costly one.
Source: Cloudflare 2025 Q4 DDoS Threat Report | NETSCOUT DDoS Threat Intelligence Report
Plan for continuity when an attack lands
| Statistic | Figure | Source | Year |
|---|---|---|---|
| Total DDoS attacks mitigated | 47.1 million | Cloudflare | 2025 |
| Year-over-year growth in attacks | +121% | Cloudflare | 2025 |
| Growth in attacks since 2023 | +236% | Cloudflare | 2025 |
| Attacks mitigated per hour (average) | 5,376 | Cloudflare | 2025 |
| Q1 attacks and YoY surge | 20.5 million (+358%) | Cloudflare | 2025 |
| Attacks observed across 203 countries | 8 million+ (2H) | NETSCOUT | 2025 |
| Largest attack ever recorded | 31.4 Tbps (35 seconds) | Cloudflare | 2025 |
| Botnet behind the record attack | Aisuru-Kimwolf | Cloudflare | 2025 |
| Peak HTTP request rate | 205 million rps | Cloudflare | 2025 |
| Peak packet rate | 9 billion pps | Cloudflare | 2025 |
| Prior record attack (May) | 7.3 Tbps | Cloudflare | 2025 |
| Q3 record attack (Aisuru) | 29.7 Tbps | Cloudflare | 2025 |
| Hyper-volumetric attacks in Q1 | 700+ (about 8 per day) | Cloudflare | 2025 |
| Network-layer attacks below 500 Mbps | 94% | Cloudflare | 2025 |
| Network-layer attacks under 10 minutes | 89% | Cloudflare | 2025 |
| HTTP attacks under 10 minutes | 71% | Cloudflare | 2025 |
| Financial services share of web/API DDoS | 34% | Akamai | 2025 |
| Gaming share of DDoS attacks | 18% | Akamai | 2025 |
| Financial-sector L3/4 attack duration rise | +738% since 2024 | Akamai | 2025 |
| Customers reporting ransom DDoS (Q2) | ~33% | Cloudflare | 2025 |
| Aisuru botnet size | 1 to 4 million hosts | Cloudflare | 2025 |
| Carpet-bombing attacks per day (2H) | 750 to 830 | NETSCOUT | 2025 |
| Hyper-volumetric attacks in one 18-day campaign | 902 (about 53/day) | Cloudflare | 2025 |
The volume, size, duration, industry, country, ransom, and botnet figures come from Cloudflare’s 2025 DDoS Threat Reports (Q1 through Q4), which are based on attacks automatically detected and mitigated across Cloudflare’s global network. Specifically: the 47.1 million annual total, the 121% year-over-year and 236% two-year growth, the 5,376 attacks-per-hour average, the 31.4 Tbps record attack (35 seconds, Aisuru-Kimwolf botnet), the 205 million requests-per-second and 9 billion packets-per-second peaks, the 94% under-500-Mbps and 89%/71% under-10-minute distributions, the 700-plus Q1 hyper-volumetric attacks, the 20.5 million Q1 total (+358%), the 1-to-4-million-host Aisuru estimate, the roughly one-third ransom DDoS figure for Q2 2025, and the 902-attack “Night Before Christmas” campaign are all from Cloudflare. The 8 million-plus attacks across 203 countries in the second half of 2025, the 750-to-830 daily carpet-bombing figure, the blended-vector detail, and the AI-assisted attack trend come from the NETSCOUT DDoS Threat Intelligence Report, Issue 16 (findings from 2H 2025), drawn from its ATLAS global threat intelligence platform. The financial-services share of web and API DDoS (34%), the gaming share (18%), the 738% rise in median Layer 3/4 attack duration, and the 236% rise in maximum volumetric scale for financial firms come from Akamai’s State of the Internet and Financial Services threat research. Only Tier 1 primary telemetry and named vendor reports with disclosed methodology are used. No statistics were invented or estimated beyond the clearly labeled CNiC Solutions analysis, which combines published Cloudflare and NETSCOUT figures. This article is informational and is not a security assessment of any specific business.
Media and press: Journalists and researchers are welcome to cite these statistics with attribution to the original primary sources named above (Cloudflare, NETSCOUT, and Akamai), and to CNiC Solutions for any analysis labeled as original.
Nearly nine in ten organizations (89%) say attackers went after their backups during a ransomware incident,…
The most effective cybersecurity tips are not exotic tools, they are a handful of well-run basics…
The world is short roughly 4.8 million cybersecurity workers, a gap that grew 19% in a…
A message lands in your inbox: a coworker shared a document with you, or your cloud…