In November 2025, Cloudflare automatically mitigated a 31.4 Tbps DDoS attack - the largest ever recorded, roughly six times bigger than the biggest attack of 2024 (Cloudflare, Q4 2025 DDoS Threat Report). It lasted 35 seconds. That single burst capped a year in which Cloudflare blocked 47.1 million DDoS attacks, up 121% year over year, NETSCOUT logged more than 8 million attacks in each half of 2025 across 203 countries (NETSCOUT, DDoS Threat Intelligence Report 2H 2025), and a single IoT botnet, Aisuru, drove close to a third of all DDoS traffic on some backbones (Arelion, 2026 DDoS Report). This analysis consolidates data from Cloudflare, NETSCOUT, Gcore, Arelion, Microsoft Azure, ENISA, Europol, and eight other primary sources into one reference set.
TL;DR
- The largest DDoS attack ever recorded hit 31.4 Tbps in November 2025 and lasted 35 seconds (Cloudflare, Q4 2025 DDoS Threat Report).
- Cloudflare mitigated 47.1 million DDoS attacks in 2025, up 121% year over year and 236% since 2023, averaging 5,376 every hour (Cloudflare, Q4 2025 DDoS Threat Report).
- About 42% of attacks used two to five distinct vectors, complicating detection and mitigation (NETSCOUT, 2H 2025 Report).
- NETSCOUT recorded more than 8 million DDoS attacks in each half of 2025 across 203 countries (NETSCOUT, 2H 2025 Report).
- The Aisuru botnet drove roughly 33% of DDoS traffic on Arelion’s backbone (Arelion, 2026 DDoS Report).
- Microsoft Azure blocked a 15.72 Tbps attack, the largest ever observed in the cloud (Microsoft Azure, 2025).
- Technology overtook gaming as the top target, with 30% of attacks versus gaming’s 19% (Gcore, Radar H1 2025).
- DDoS made up 77% of the 4,875 cyber incidents ENISA tracked across the EU (ENISA, Threat Landscape 2025).
- About one in three Cloudflare customers surveyed in Q2 2025 faced a ransom DDoS threat (Cloudflare, Q2 2025 DDoS Threat Report).
- Operation PowerOFF seized 53 DDoS-for-hire domains and data on 3M-plus user accounts (Europol; US DOJ, 2026).
1. Record-Breaking Attack Sizes
The ceiling on DDoS firepower moved almost every quarter of 2025. Attack sizes grew more than 700% compared with the largest attacks of late 2024, topping out at 31.4 Tbps (Cloudflare, Q4 2025 DDoS Threat Report). The pattern is consistent: a small number of hyper-volumetric floods, most lasting under a minute, now dwarf anything the internet routinely handled two years ago, and the packet-rate records climbed just as fast as the bit-rate ones.
| Metric | Value | Source |
|---|---|---|
| Largest DDoS attack ever recorded | 31.4 Tbps (35 seconds), Nov 2025 | Cloudflare, Q4 2025 DDoS Threat Report |
| Highest packet-rate attack on record | 14.1 billion packets/sec, Q3 2025 | Cloudflare, Q3 2025 DDoS Threat Report |
| Largest cloud DDoS ever observed | 15.72 Tbps + 3.64 Bpps, Oct 24 2025 | Microsoft Azure, 2025 |
| 2025 volumetric record progression | 7.3 -> 11.5 -> 22.2 -> 29.7 Tbps | Cloudflare, Q2-Q3 2025 Reports |
| Payload of the 7.3 Tbps attack | 37.4 TB delivered in 45 seconds | Cloudflare, Q2 2025 DDoS Threat Report |
| Largest attack on Gcore’s network | 6 Tbps + 5.3 Bpps (gaming host) | Gcore, October 2025 |
| Q1 2025 packet-rate record | 4.8 Bpps, alongside a 6.5 Tbps flood | Cloudflare, Q1 2025 DDoS Threat Report |
The records are less about any one target than about available firepower. When a botnet can generate 30-plus Tbps on demand, every organization inherits the same worst case. For the broader defensive picture, see our cybersecurity statistics for 2026.
2. Attack Volume and Frequency
Raw counts rose even faster than peak sizes. Cloudflare mitigated 47.1 million DDoS attacks in 2025, a 121% jump year over year and a 236% increase since 2023 (Cloudflare, Q4 2025 DDoS Threat Report). Two independent telemetry networks corroborate the surge: NETSCOUT crossed 8 million attacks in each half-year, and Gcore measured a 41% rise in the first half alone. The scale is now industrial rather than episodic.
| Metric | Value | Source |
|---|---|---|
| Total DDoS attacks mitigated, 2025 | 47.1 million (+121% YoY) | Cloudflare, Q4 2025 DDoS Threat Report |
| Average attacks mitigated per hour | 5,376 (3,925 network + 1,451 HTTP) | Cloudflare, Q4 2025 DDoS Threat Report |
| Growth in attacks, 2023 to 2025 | +236% | Cloudflare, Q4 2025 DDoS Threat Report |
| Q1 2025 attacks (year over year) | 20.5 million (+358%) | Cloudflare, Q1 2025 DDoS Threat Report |
| Q3 2025 attacks (year over year) | 8.3 million (+40%) | Cloudflare, Q3 2025 DDoS Threat Report |
| Global attacks, 1H 2025 | 8,062,971 | NETSCOUT, 1H 2025 Report |
| Global attacks, 2H 2025 | 8 million+ across 203 countries | NETSCOUT, 2H 2025 Report |
| Gcore attack volume, H1 2025 | 1.17 million (up from 969K, +41%) | Gcore, Radar H1 2025 |
Cloudflare and NETSCOUT count different traffic, so their totals will never match precisely; the value is directional agreement, and both point sharply up. The rising floor matters more than the headline records for most defenders.
3. Attack Anatomy: Layers, Vectors, and Duration
Most DDoS traffic is small, fast, and network-layer, even as the giants grab headlines. 99% of network-layer attacks stayed under 1 Gbps, and 89% ended within 10 minutes (Cloudflare, Q1 2025 DDoS Threat Report). Short bursts are a deliberate tactic: they can knock a service offline before automated mitigation fully engages, then vanish before responders trace them. Multi-vector attacks that rotate protocols mid-flood are increasingly the norm.
| Metric | Value | Source |
|---|---|---|
| Network-layer share of attacks, Q4 2025 | 78% (34.4M attacks, tripled vs 2024) | Cloudflare, Q4 2025 DDoS Threat Report |
| Network-layer attacks under 1 Gbps | 99% | Cloudflare, Q1 2025 DDoS Threat Report |
| Network-layer attacks ending within 10 min | 89% (75% for HTTP) | Cloudflare, Q1 2025 DDoS Threat Report |
| Top network-layer vector, Q3 2025 | UDP floods (+231% QoQ) | Cloudflare, Q3 2025 DDoS Threat Report |
| Mirai-class share of network-layer attacks | ~2 of every 100 | Cloudflare, Q3 2025 DDoS Threat Report |
| Attacks using 2 to 5 distinct vectors | ~42% | NETSCOUT, 2H 2025 Report |
| Average attack duration, 1H 2025 | 18 minutes 24 seconds | NETSCOUT, 1H 2025 Report |
There is a split personality here: brief network-layer floods dominate by count, while NETSCOUT’s longer average duration reflects sustained, adaptive campaigns against high-value targets. Defenders need to plan for both the 40-second spike and the 18-minute grind.
4. Botnets and Attack Infrastructure
One name defined 2025’s record book. The Aisuru botnet, built from more than 500,000 compromised IoT and Android devices, drove roughly a third of the DDoS traffic on Arelion’s backbone (Arelion, 2026 DDoS Report; Krebs on Security, 2025). Aisuru is a Turbo Mirai-class botnet assembled from consumer routers, cameras, DVRs, and streaming boxes running default or outdated firmware, and it was behind most of the year’s hyper-volumetric floods.
| Metric | Value | Source |
|---|---|---|
| Aisuru botnet compromised devices | 500,000+ IoT and Android devices | Krebs on Security, 2025 |
| Aisuru share of DDoS traffic (Arelion network) | ~33% | Arelion, 2026 DDoS Report |
| Aisuru-Kimwolf infected Android TVs | 1 to 4 million | Cloudflare, Q4 2025 DDoS Threat Report |
| Aisuru hyper-volumetric attacks, 2025 YTD (thru Q3) | 2,867 | Cloudflare, Q3 2025 DDoS Threat Report |
| ”Night Before Christmas” campaign | 902 hyper-volumetric attacks over 18 days | Cloudflare, Q4 2025 DDoS Threat Report |
| Peak HTTP request rate (Aisuru-Kimwolf) | 200 million+ requests/sec | Cloudflare, Q4 2025 DDoS Threat Report |
| Aisuru hosts repurposed as residential proxies | ~300,000 | Krebs on Security, 2025 |
| RapperBot botnet reach before takedown | 80+ countries | US DOJ, 2025 |
Source: Krebs on Security - Aisuru Botnet Blankets US ISPs in Record DDoS
The economics shifted late in the year: Aisuru’s operators began renting infected devices as residential proxies, a quieter and more durable revenue stream than extortion. That pivot signals compromised-IoT infrastructure is now a general-purpose criminal utility, not just a DDoS cannon.
5. Who Gets Hit: Industries and Regions
The target list widened well beyond the usual gaming and gambling suspects. Technology overtook gaming as the most-attacked sector, absorbing 30% of DDoS attacks against gaming’s 19% (Gcore, Radar H1 2025). Cloudflare’s own ranking put telecommunications, IT, gambling, and gaming at the top in Q4, while AI and generative-AI providers became a fast-rising target as their services grew business-critical.
| Metric | Value | Source |
|---|---|---|
| Top targeted industry (share of attacks) | Technology, 30% (gaming 19%) | Gcore, Radar H1 2025 |
| Most-targeted sectors, 2H 2025 | Government, finance, telecom, transport, hospitality | NETSCOUT, 2H 2025 Report |
| Most-attacked country and climbers, Q4 2025 | China #1; Hong Kong +12 (to #2), UK +36 (to #6) | Cloudflare, Q4 2025 DDoS Threat Report |
| Most-attacked region, 1H 2025 | EMEA, 3.27 million attacks | NETSCOUT, 1H 2025 Report |
| Top attack-source countries, Q4 2025 | Bangladesh, Ecuador, Indonesia | Cloudflare Radar, Q4 2025 |
| AI / GenAI company attack surge, Sept 2025 | +347% month over month | Cloudflare, Q3 2025 DDoS Threat Report |
| DDoS share of EU cyber incidents | 77% of 4,875 incidents | ENISA, Threat Landscape 2025 |
| Ideology-driven incident objectives (EU) | ~80% | ENISA, Threat Landscape 2025 |
Source: Gcore - Radar Report Reveals 41% Surge in DDoS Attack Volumes
Gaming remains a prime target because matchmaking, login, and game-server endpoints are latency-sensitive and easy to disrupt, and rivals sometimes pay to knock competitors offline. For the hardware side of that ecosystem, see our PC gaming hardware statistics for 2026. ENISA’s data shows the EU picture skews toward ideology, not profit motive.
6. Ransom DDoS, Hacktivism, and Takedowns
DDoS is increasingly a tool of extortion and politics, not just disruption. In Q2 2025, about one in three surveyed Cloudflare customers reported a ransom DDoS threat, with such reports up 68% quarter over quarter (Cloudflare, Q2 2025 DDoS Threat Report). On the ideological side, ENISA attributed 96.2% of EU DDoS incidents to hacktivist activity, and pro-Russian crews kept a punishing operational tempo across Europe.
| Metric | Value | Source |
|---|---|---|
| Customers threatened or hit by ransom DDoS, Q2 2025 | ~1 in 3 respondents | Cloudflare, Q2 2025 DDoS Threat Report |
| Growth in ransom DDoS reports, Q2 2025 | +68% quarter over quarter | Cloudflare, Q2 2025 DDoS Threat Report |
| Hacktivist-driven share of EU DDoS incidents | 96.2% | ENISA, Threat Landscape 2025 |
| NoName057(16) average daily targets | ~50 unique targets | Bitsight, 2025 |
| La Poste outage from hacktivist DDoS | ~3 days (Dec 22, 2025) | SOCRadar, 2025 |
| Operation PowerOFF domains seized | 53 domains, data on 3M+ accounts | Europol; US DOJ, 2026 |
| Booter/stresser platforms shut down (Dec 2025) | 27 | Europol, 2025 |
Source: Europol - Law Enforcement Shuts Down 27 DDoS Booters
Ransom DDoS often bundles with data-theft extortion, blurring the line with classic ransomware crews. For that adjacent threat, see our ransomware statistics for 2026; the social-engineering entry point is covered in our phishing statistics for 2026. Takedowns dent capacity but rarely end it, as NoName057(16) rebuilt quickly after Operation Eastwood.
7. The DDoS Protection Market and Cost of Downtime
Defensive spending is scaling with the threat, though it lags the attackers. The DDoS protection and mitigation market is estimated near $5.4 billion for 2026, growing at a double-digit CAGR toward $10-11 billion by the early 2030s (Mordor Intelligence; MarketsandMarkets, 2026). The business case is simple arithmetic: even a short outage can cost more than a year of protection for a mid-sized firm.
| Metric | Value | Source |
|---|---|---|
| DDoS protection market size, 2026 | ~$5.4 billion (estimate) | Mordor Intelligence; MarketsandMarkets, 2026 |
| Market CAGR, 2026 onward | ~12% to 15% | Mordor Intelligence; MarketsandMarkets, 2026 |
| Projected market, early 2030s | $10 to 11 billion | Mordor Intelligence; MarketsandMarkets, 2026 |
| Enterprise downtime cost | $100,000 to $540,000+ per hour | Ponemon Institute (most recent available) |
| Small-business downtime cost | $8,000 to $74,000 per hour | Industry estimates, 2025 |
| Widely cited IT downtime benchmark | ~$5,600 per minute | Gartner (most recent available) |
Market and downtime-cost figures come from firms that scope “DDoS protection” differently, so treat any single dollar amount as directional; we cross-referenced Mordor Intelligence and MarketsandMarkets and flag the older Ponemon and Gartner benchmarks accordingly. The through-line is unambiguous: attack economics favor the offense, since renting a booter cost as little as 10 euros while defending against one runs into six figures per hour.
Summary: DDoS Attacks by the Numbers
| Metric | Value | Source |
|---|---|---|
| Largest DDoS attack ever recorded | 31.4 Tbps (35 seconds), Nov 2025 | Cloudflare; Krebs on Security, 2025 |
| Highest packet-rate attack on record | 14.1 billion packets/sec | Cloudflare, Q3 2025 DDoS Threat Report |
| Largest cloud DDoS ever observed | 15.72 Tbps, Oct 2025 | Microsoft Azure, 2025 |
| Total DDoS attacks mitigated, 2025 | 47.1 million (+121% YoY) | Cloudflare, Q4 2025 DDoS Threat Report |
| Average attacks mitigated per hour | 5,376 | Cloudflare, Q4 2025 DDoS Threat Report |
| Global attacks, 1H 2025 | 8,062,971 | NETSCOUT, 1H 2025 Report |
| Global attacks, 2H 2025 | 8 million+ across 203 countries | NETSCOUT, 2H 2025 Report |
| Gcore attack volume, H1 2025 | 1.17 million (+41%) | Gcore, Radar H1 2025 |
| Growth in attack size vs late 2024 | +700% | Cloudflare, Q4 2025 DDoS Threat Report |
| Ransom DDoS reports growth, Q2 2025 | +68% quarter over quarter | Cloudflare, Q2 2025 DDoS Threat Report |
| Network-layer attacks ending within 10 min | 89% | Cloudflare, Q1 2025 DDoS Threat Report |
| Average attack duration, 1H 2025 | 18 min 24 sec | NETSCOUT, 1H 2025 Report |
| Aisuru share of DDoS traffic (Arelion) | ~33% | Arelion, 2026 DDoS Report |
| Aisuru compromised devices | 500,000+ | Krebs on Security, 2025 |
| Top targeted industry | Technology, 30% (gaming 19%) | Gcore, Radar H1 2025 |
| DDoS share of EU cyber incidents | 77% of 4,875 | ENISA, Threat Landscape 2025 |
| Customers hit by ransom DDoS, Q2 2025 | ~1 in 3 | Cloudflare, Q2 2025 DDoS Threat Report |
| Operation PowerOFF domains seized | 53 (3M+ accounts exposed) | Europol; US DOJ, 2026 |
| DDoS protection market, 2026 | ~$5.4 billion | Mordor Intelligence; MarketsandMarkets, 2026 |
| Enterprise downtime cost | $100,000-$540,000+ per hour | Ponemon Institute (most recent available) |
Methodology and Sources
We aggregated data from primary DDoS telemetry reports, vendor mitigation disclosures, government press releases, and analyst market research published mainly in 2025 and 2026; where market or cost estimates diverged, we cross-referenced at least two firms and flagged ranges rather than picking one number.
- Cloudflare - 2025 Q4 DDoS Threat Report - blog.cloudflare.com
- Cloudflare - 2025 Q3 DDoS Threat Report - blog.cloudflare.com
- Cloudflare - 2025 Q2 DDoS Threat Report - blog.cloudflare.com
- Cloudflare - 2025 Q1 DDoS Threat Report - blog.cloudflare.com
- NETSCOUT - DDoS Threat Intelligence Report (1H and 2H 2025) - netscout.com
- Gcore - Radar DDoS Attack Trends Report (H1 2025) - gcore.com
- Arelion - 2026 DDoS Report - prnewswire.com
- Microsoft Azure - Record 15.72 Tbps DDoS mitigation, 2025 - techcommunity.microsoft.com
- Krebs on Security - Aisuru botnet reporting, 2025 - krebsonsecurity.com
- ENISA - Threat Landscape 2025 - enisa.europa.eu
- Europol - Operation PowerOFF booter takedowns, 2025-2026 - europol.europa.eu
- US Department of Justice - DDoS-for-hire and RapperBot actions, 2025 - justice.gov
- Bitsight - NoName057(16) threat intelligence, 2025 - bitsight.com
- Mordor Intelligence - DDoS Protection Market - mordorintelligence.com
- MarketsandMarkets - DDoS Protection and Mitigation Market - marketsandmarkets.com
Data watch: Cloudflare publishes DDoS threat reports every quarter, so a 2026 Q1 edition is due shortly after this update; NETSCOUT issues half-yearly reports, with its 1H 2026 edition expected mid-year; Gcore, Arelion, and ENISA release annual or semi-annual updates through 2026. We will fold those in as they land.
Last updated: July 16, 2026. We review and update this page quarterly as new data is published.