20.5 million DDoS attacks blocked during Q1 2025

Cloudflare blocked 20.5 million Distributed Denial of Service (DDoS) attacks during the first quarter of 2025, according to the company’s latest quarterly threat report. This represents a 358% year-over-year (YoY) increase and a 198% quarter-over-quarter (QoQ) increase. For context, Cloudflare blocked 21.3 million DDoS attacks across all of 2024; the Q1 2025 total alone is 96% of that figure.

Of those 20.5 million blocked attacks, 16.8 million were network-layer DDoS attacks — a 397% QoQ and 509% YoY increase. HTTP-based DDoS attacks also rose, albeit more modestly, with a 7% QoQ and 118% YoY increase.

The figures also include roughly 700 "hyper-volumetric" attacks exceeding 1 Tbps or 1 billion packets per second (Bpps) — an average of about eight per day. Cloudflare says all of these attacks were detected and mitigated by its autonomous defenses.

Targeted by 20.5 million DDoS attacks, up 358- year-over-year- Cloudflare’s 2025 Q1 DDoS Threat Report-OG

A sustained multi-vector campaign

About 6.6 million of the network-layer attacks Q1 targeted Cloudflare's own infrastructure. These were part of an 18-day multi-vector campaign blending SYN flood attacks, Mirai botnet-generated traffic, and SSDP amplification attacks. A further 6.9 million targeted hosting and service providers using Cloudflare's Magic Transit service.

DDoS attacks by quarter

The campaign appears to reflect a broader shift in attacker behavior. Meanwhile, attacks continue to spill over into Q2. In the latter half of April, Cloudflare says its systems detected an intense campaign with dozens of hyper-volumetric attacks. The largest peaked at 4.8 Bpps and 6.5 Tbps, with surges typically lasting 35 to 45 seconds. The packet rate is the highest ever publicly disclosed — around 52% larger than the prior 3.15 Bpps record — while the bandwidth figure matches the largest publicly known DDoS attack to date.

The attacks in that Q2 campaign originated from 147 countries and targeted a hosting provider protected by Magic Transit. Cloudflare's network blocked all of them.

DDoS attacks targeting Cloudflare’s network

Who is behind the attacks?

Threat actor attribution remains murky: most targeted Cloudflare customers said they didn’t know who attacked them. Among those who did, competitors topped the list at 39%, a share consistent with the previous quarter and common in the gaming and gambling sector. State-level or state-sponsored actors were blamed by 17%, with a similar share pointing to disgruntled users or customers. About 11% said they had self-inflicted the attack, while another 11% reported extortion; 6% cited former or disgruntled employees.

BLOG-2834 Image 2

On the network layer, SYN floods remain the most common L3/4 vector, followed by DNS floods. Mirai-launched attacks moved into third place, displacing UDP floods. On the application layer, over 60% of HTTP attacks were attributed to known botnets, 21% carried suspicious HTTP attributes, 10% were botnets impersonating browsers, and the remainder were generic floods and cache-busting efforts.

Among the notable shifts, CLDAP (Connectionless Lightweight Directory Access Protocol) reflection and amplification attacks surged 3,488% QoQ. CLDAP runs over UDP, which allows attackers to spoof source addresses and abuse servers to amplify traffic toward victims. Similarly, ESP (Encapsulating Security Payload) reflection and amplification attacks rose 2,301% QoQ, exploiting misconfigured systems in IPsec deployments.

Hyper-volumetric DDoS attacks

Short and small — but still damaging

Despite the rise in headline-grabbing hyper-volumetric events, most DDoS attacks remain small. Some 99% of Layer 3/4 attacks in Q1 stayed under 1 Gbps and 1 Mpps, while 94% of HTTP attacks were under 1 million requests per second (Mrps). Still, even small floods can easily saturate typical unprotected Internet links or crash an under-provisioned server.

Most attacks are also short-lived: 89% of L3/4 attacks and 75% of HTTP attacks end within 10 minutes. The largest attacks can be even shorter — the 35-second bursts seen in April are an example. These durations leave no room for human response, since an analyst would likely only receive an alert after the attack is over. Even when brief, such attacks can cause outages lasting days. This makes always-on, in-line automated mitigation with generous capacity essential.

Still, hyper-volumetric HTTP attacks (over 1 Mrps) doubled their representation in Q1, with 6 out of every 100 HTTP attacks exceeding that threshold. On the network layer, roughly 1 in 100,000 attacks broke the 1 Tbps or 1 Bpps barrier.

4.8 Bpps UDP flood attack

Example attack

One illustrative case targeted a US-based hosting provider using Magic Transit that offers web, VoIP, and game servers. The attack zeroed in on port 27015, a port associated with multiplayer gaming servers, particularly Valve's Source engine titles like Counter-Strike: Global Offensive and Team Fortress 2. The customer faced multiple hyper-volumetric attacks, which Cloudflare's defenses blocked automatically.

6.5 Tbps UDP flood attack

Geographic shifts

The ranking of most-attacked locations changed meaningfully in Q1. Germany climbed four spots to become the single most attacked country. Turkey rose 11 places into second. China slipped two spots to third, while Hong Kong held steady. India rose four, Brazil remained unchanged, and Taiwan dropped four. The steepest decline was in the Philippines, down six positions. South Korea and Indonesia each rose two spots.

Top threat actors

Hetzner & OVH still top the HTTP DDoS source charts

Attack origin data for HTTP DDoS in 2025 Q1 shows a familiar set of providers at the top. Germany’s Hetzner (AS24940) again ranked first, followed by France’s OVH (AS16276), US-based DigitalOcean (AS14061), and another German host, Contabo (AS51167).

The rest of the top 10 mixes cloud providers and telecom operators: ChinaNet Backbone (AS4134) and Tencent (AS132203) from China, Austria’s Drei (AS200373), and three US networks — Microsoft (AS8075), Oracle (AS31898), and Google Cloud Platform (AS396982). The makeup of this list underscores how hosting and cloud infrastructure, whether deliberately abused or simply compromised, continues to be a primary vector for launching DDoS attacks.

To help providers clean up their networks, Cloudflare operates a free DDoS Botnet Threat Feed for Service Providers. More than 600 organizations have enrolled. The feed lists IP addresses within an operator’s ASN that Cloudflare has observed launching HTTP DDoS attacks. Access requires a free Cloudflare account, ASN authentication via PeeringDB, and fetching the intelligence through the API.

Top source ASNs

Industry leaderboard sees gambling and airlines climb

The quarterly ranking of the most targeted industries saw several notable shifts. Gambling & Casinos rose four places to become the most attacked industry. Telecommunications, Service Providers and Carriers dropped one spot, while Information Technology & Services moved up a single position and Internet fell two. Gaming and Banking & Financial Services each inched up one spot.

Bigger movers included the Cyber Security industry, which jumped 37 places, and Manufacturing, Machinery, Technology & Engineering, which rose 28 spots. Retail slipped one place. The steepest climb belonged to Airlines, Aviation & Aerospace, which leapt 40 spots to enter the top 10 at number ten.

Map of top 10 most attacked industries in 2025 Q1

Attack sources are shifting geographically

The geographic breakdown of the largest attack sources also changed quarter over quarter. Hong Kong moved up three spots to take the number one position, displacing Indonesia, which dropped to second. Argentina climbed two spots to third, Singapore fell two to fourth, and Ukraine slipped one to fifth.

Brazil and Thailand both made strong gains, each rising seven places to sixth and seventh respectively. Germany moved up two spots to eighth. Vietnam posted the most dramatic gain among the top 10, jumping 15 positions to ninth, while Bulgaria rounded out the list with a two-spot drop to tenth.

Map of top 10 largest sources of DDoS attacks in 2025 Q1

Proactive defense and free tools

Cloudflare’s stance is that reactive protection — adopting DDoS defenses only after an attack hits — is increasingly inadequate. The company’s data indicates that organizations running always-on, automated protection fare better against both known and novel threats.

The company offers unmetered and unlimited DDoS mitigation to all customers, underpinned by a network that spans 335 cities with 348 Tbps of capacity, and continues to provide free botnet identification tools to help the wider Internet community dismantle attack infrastructure.