2025 DDoS Attack Volumes More Than Doubled

Cloudflare mitigated 47.1 million DDoS attacks in 2025, more than double the prior year's figure. Combined with growth seen the year before, the total number of attacks has jumped 236% since 2023. Averaged out, Cloudflare's systems automatically blocked 5,376 attacks every hour during 2025 — 3,925 at the network layer and 1,451 HTTP-based attacks.

Network-Layer Attacks Triple

The largest growth came from network-layer attacks, which more than tripled year over year to 34.4 million, up from 11.4 million in 2024. A substantial portion — roughly 13.5 million — were aimed at infrastructure protected by Cloudflare Magic Transit and Cloudflare's own network during an 18-day campaign in Q1. Of those, 6.9 million targeted Magic Transit customers while 6.6 million hit Cloudflare directly. That campaign used multiple vectors including SYN floods, Mirai-generated attacks, and SSDP amplification. It was significant enough that Cloudflare only became aware of the full scope while preparing its Q1 threat report.

By Q4 2025, total attacks grew 31% quarter over quarter and 58% versus 2024. Network-layer attacks drove the increase, accounting for 78% of all DDoS traffic. HTTP DDoS attack counts stayed level, but attack rates reached heights not seen since the 2023 HTTP/2 Rapid Reset campaign.

The "Night Before Christmas" Campaign

Starting Friday, December 19, 2025, the Aisuru-Kimwolf botnet launched a sustained bombardment against Cloudflare infrastructure and customers with hyper-volumetric HTTP DDoS attacks exceeding 20 million requests per second (Mrps). The botnet, primarily composed of an estimated 1 to 4 million malware-infected Android TVs, continued the campaign throughout the quarter.

Cloudflare's autonomous defenses logged and mitigated 902 hyper-volumetric attacks during the campaign: 384 packet-intensive, 329 bit-intensive, and 189 request-intensive. That averages to roughly 53 attacks per day. The average peak sizes during the campaign were 3 billion packets per second (Bpps), 4 Tbps, and 54 Mrps. The maximum rates hit 9 Bpps, 24 Tbps, and 205 Mrps.

Record-Setting Attack Sizes

The campaign was one element of a broader trend. Q4's hyper-volumetric attacks increased 40% compared to Q3, and over the full year the size of these attacks grew more than 700% compared to late 2024. The largest single attack lasted 35 seconds and peaked at 31.4 Tbps. Like the others, it was detected and neutralized automatically by Cloudflare's mitigation systems.

The largest attacks primarily targeted customers in the Telecommunications, Service Providers, and Carriers industry, followed by Gaming and Generative AI providers. Cloudflare's own infrastructure was also hit by HTTP floods, DNS attacks, and UDP floods.

Attack Focus by Industry and Geography

Telecom, service providers, and carriers were the most-targeted industry overall in Q4, displacing Information Technology & Services from that position. Gambling & Casinos ranked third, and Gaming took fourth. Computer Software and Business Services made notable climbs within the top ten. The common factor among targets: critical infrastructure, backbone services, or businesses highly sensitive to latency and downtime in real-time financial terms.

On the geographic front, China, Germany, Brazil, and the United States ranked among the top five targets. Hong Kong jumped twelve places to become the second most-attacked location. The United Kingdom rose 36 places to land at number six. Vietnam stayed at seven, followed by Azerbaijan, India, and Singapore.

Attack Sources Shift

Bangladesh replaced Indonesia as the largest source of DDoS attacks in Q4, dropping Indonesia to third after a year at the top. Ecuador rose to second. Argentina climbed an extraordinary twenty places to fourth, and Hong Kong took fifth. Ukraine, Vietnam, Taiwan, Singapore, and Peru rounded out the top ten sources.

Cloud and Telco Infrastructure Largely Responsible

The top attack source networks read like a list of major Internet infrastructure providers. Cloud computing platforms feature heavily — including DigitalOcean (AS 14061), Microsoft (AS 8075), Tencent (AS 132203), Oracle (AS 31898), and Hetzner (AS 24940) — underscoring the connection between easily provisioned virtual machines and high-volume traffic generation. These cloud sources are concentrated in the United States. The rest of the top ten consists largely of Asia-Pacific telecommunications providers from Vietnam, China, Malaysia, and Taiwan.

The diversity of source networks reflects the distributed nature of modern botnets, with traffic often routed through thousands of autonomous system numbers (ASNs). To help providers identify and shut down abusive IPs and accounts, Cloudflare maintains a free DDoS Botnet Threat Feed for Service Providers; over 800 networks worldwide have signed up for the feed.