Cloudflare reported a record-breaking surge in cyberattacks to start 2025, having mitigated 20.5 million Distributed Denial of Service (DDoS) attacks in the first quarter alone—a staggering 358% increase compared to the same period last year.
This unprecedented volume nearly matches the total number of attacks the company blocked throughout all of 2024, highlighting a sharp escalation in both the scale and severity of DDoS threats.
The spike marks a significant shift in the global threat landscape, as attackers launch increasingly sophisticated and large-scale campaigns.

Hyper-Volumetric Attacks
In April 2025, Cloudflare automatically detected and mitigated the largest packet-rate DDoS attack ever recorded, reaching a peak of 4.8 billion packets per second (Bpps). This unprecedented event surpassed the previous record of 3.15 Bpps by approximately 52%.

Unprecedented Global Assault Targets U.S. Hosting Infrastructure
In a sweeping, globally distributed offensive, a U.S.-based hosting provider came under fire from a colossal DDoS barrage sourced from 147 countries. Among the coordinated strikes was a 6.5 terabits-per-second (Tbps) deluge—matching the largest bandwidth attack ever made public—underscoring a new era of scale and persistence in digital threats.
Cloudflare’s Q1 2025 DDoS Threat Report paints a stark picture of today’s cybersecurity battlefield:
“In just three months, the threat environment has reshaped entirely,” the company reported.
“We’ve recorded a 397% surge in network-layer assaults quarter-over-quarter, including nearly 700 ultra-high-volume attacks breaching 1 Tbps or 1 Bpps thresholds.”
Tactics Evolve: From Familiar Methods to High-Pressure Barrages
The analysis points to SYN floods as the dominant attack technique, trailed by DNS-based floods and botnet-driven Mirai variants. SYN floods exploit the foundational TCP handshake, bombarding targets with spoofed connection attempts that leave servers overwhelmed by half-open sessions—crippling systems before any real connection can be established.
This wave of activity not only demonstrates the growing sophistication of threat actors but signals a systemic shift toward frequency, scale, and automation that legacy defenses can no longer absorb.

System administrators can apply protection by configuring iptables rules like the following:

CLDAP Exploitation Surges Nearly 3,500%
One of the most alarming developments this quarter was a staggering 3,488% rise in CLDAP reflection and amplification attacks. CLDAP (Connectionless Lightweight Directory Access Protocol), which operates over UDP, enables threat actors to forge source IP addresses in lightweight queries that elicit disproportionately large replies—redirected at unsuspecting targets.
Shifting Targets and Attack Origins
The report highlighted a geographic and sectoral shift in DDoS targeting. Germany faced the highest volume of attacks, overtaking previous hotspots, while the Gambling & Casinos sector emerged as the top industry under siege.
On the offensive side, Hong Kong led as the dominant origin of attack traffic, with autonomous system Hetzner (AS24940) continuing to generate the most HTTP DDoS traffic globally.

Small Doesn’t Mean Harmless
While hyper-volumetric attacks have surged, the vast majority of Layer 3/4 DDoS attacks remain modest in size—99% fall below 1 Gbps in bandwidth and 1 million packets per second (Mpps).
Still, these low-volume assaults shouldn’t be underestimated. Without proper defenses in place, even smaller-scale attacks can quickly disrupt unprotected servers and saturate network connections.

Fast and Furious: Most Attacks End in Minutes
One striking pattern is the fleeting nature of modern attacks—89% of network-layer assaults and 75% of HTTP DDoS incidents end within just 10 minutes. Even the record-setting 4.8 billion packets-per-second (Bpps) attack lasted less than a minute, underscoring the critical need for real-time, automated defense.
“There’s no time for manual response in today’s DDoS environment,” Cloudflare researchers warned.
“Protection must be always-on, inline, and fully automated—with the scale to absorb attacks without impacting legitimate traffic.”
Proactive Defense: Crowd-Powered Intelligence
To help service providers stay ahead, Cloudflare offers a free DDoS Botnet Threat Feed, already leveraged by over 600 organizations worldwide. This community-driven resource enables providers to quickly identify and shut down malicious accounts operating within their own infrastructure—cutting off attacks at the source.




