DDoS attacks have surged to new extremes, with terabit-scale attacks now a daily reality, powered by compromised home internet connections, according to a new report from Nokia.
The telecom giant’s 11th annual Threat Intelligence Report found that terabit-scale DDoS attacks are happening five times more frequently and with greater strength, with peaks in the 5 to 10 Tbps range the ‘new normal’, and escalating faster than most alert systems can raise alarms.
Gigabit residential broadband connectivity is amplifying the danger, with Nokia finding that over 100 million residential endpoints, amounting to 4% of the global total, are now available for exploits and malicious uses of bandwidth.
As well as becoming more powerful, DDoS attacks are faster than ever. The report found that 78% of DDoS attacks now end within five minutes, up from 44% in 2024, with 37% wrapping up in under two minutes, highlighting the need for rapid detection and mitigation.
“In light of the rise of industrialised attack tools, millions of insecure IoT endpoints, and organised botnets employing residential proxies, network owners must act now to protect their assets and customers from massive, complex and highly variable DDoS attacks in the 10+ terabit range,” said Jeff Smith, VP and general manager of Nokia Deepfield.
“Security should not be an afterthought; rather, DDoS protection must be built into the network itself, ensuring critical network functions continue uninterrupted.”
Along with skyrocketing DDoS attacks, the report highlights another concerning trend in attackers targeting critical telecom networks with stealthy intrusions.
Over the last year, nearly 2 in 3 telecom operators experienced at least one living-off-the-land attack (which use legitimate tools already in a system to carry out malicious activities), while 32% saw four or more.
By abusing trusted tools, attackers can hide in plain sight, taking advantage of unpatched devices and misconfigurations. In some instances, this can result in hackers reaching sensitive systems such as subscriber data and legal surveillance platforms, as seen in the high-profile Salt Typhoon case.
According to Nokia’s report, such multi-year, low-profile infections have led to major data exposure and forced operators into costly remediation, highlighting the business and reputational risks of long-term, privileged access.
Recommended reading
- Hackers Unleash ‘Company Killing’ DDoS Attack
- DDoS Attacks Surge 2,844% in Conflict Zones, Report Claims
- Report: DDoS Attacks Spike 82% in 2024
Those issues are being exacerbated by insider risk, human error and misconfigurations, said Nokia, with almost 60% of high-cost breaches stemming from insider actions or mistakes, while hygiene gaps are keeping doors open to attackers too, as 76% of vulnerabilities stem from missing patches.
In response, 70% of telecom security leaders now prioritise AI- and ML-based threat analytics, and over half plan to deploy AI for detection within 18 months to tackle both stealthy attack tactics and rapid DDoS campaigns.
“Recent attacks have reached lawful interception systems, leaked sensitive subscriber data and disrupted emergency services,” said Kal De, senior VP for product and engineering at Nokia.
“The industry must fight back through shared threat intelligence, AI-driven detection and response, and crypto-agility, turning interconnected networks from a vulnerability into a source of resilience.”





