Site navigation

Record 7.3 Tbps DDoS Attack Blocked

Graham Turner

,

Largest DDoS attack
Cloudflare blocked the largest DDoS attack on record in Q2 2025 as hyper-volumetric threats surged and ransom-driven campaigns spiked.

Cloudflare says it mitigated the largest Distributed Denial-of-Service (DDoS) attack ever recorded during the second quarter of 2025, as new data reveals a sharp rise in the scale and sophistication of digital assaults.

The record-breaking attack – documented in the company’s 2025 Q2 DDoS threat report peaked at 7.3 terabits per second (Tbps) and 4.8 billion packets per second (Bpps), amid a broader surge in “hyper-volumetric” DDoS attacks – those so large they risk overwhelming even well-provisioned infrastructure.

While the total number of DDoS attacks dropped significantly compared to Q1 — which was dominated by an intense 18-day campaign against Cloudflare’s own network and other critical infrastructure – he second quarter of the year still saw a staggering 7.3 million attacks. That figure is down from 20.5 million in Q1, but remains 44% higher than the same period in 2024.

Crucially, Cloudflare says the intensity of attacks is escalating, with more than 6,500 hyper-volumetric DDoS events detected and automatically blocked in Q2. That equates to 71 such attacks per day. The rise includes more frequent assaults exceeding 1 Tbps and 1 billion packets per second – previously rare thresholds that are fast becoming more common.

HTTP-based DDoS attacks also climbed 9% from the previous quarter, reaching 4.1 million. Although lower-level Layer 3/4 attacks dropped 81% quarter-on-quarter to 3.2 million, they remain a potent threat, particularly to organisations without dedicated protection. The report warns that even “small” attacks – often below 500 Mbps – can cripple unprotected servers if timed correctly.

June was the busiest month of the quarter, accounting for nearly 38% of all recorded DDoS activity. Among the notable targets was an independent Eastern European news outlet that came under attack after reporting on a Pride parade — a sign, Cloudflare suggests, of the continued weaponisation of DDoS tactics in response to politically sensitive content.

Ransom-motivated DDoS also made a comeback in Q2, with the proportion of Cloudflare customers reporting ransom threats increasing by 68% compared to the first quarter. In June alone, around a third of those affected said they had received threats or experienced ransom-based attacks.

Telecommunications, internet service providers, and infrastructure firms were the most targeted sectors in the quarter. The gaming and gambling industries also remained high on attackers’ lists — with many victims attributing the source of attacks to direct competitors. In survey responses, 71% of DDoS victims said they did not know who was behind the attack, but among those who did, 63% pointed to commercial rivals. A further 21% blamed state-sponsored actors.

Geographically, the most-attacked customer regions were China, Brazil, Germany, India, and South Korea, with Russia and Azerbaijan making unexpected jumps into the top ten. These rankings reflect where Cloudflare customers are billed, rather than nations being directly targeted.

Indonesia was the leading source of attack traffic, followed by Singapore and Hong Kong, though Cloudflare is careful to note that this refers to where botnet nodes or VPN endpoints were located — not the actual origin of the attackers.

A similar picture emerges when examining the networks responsible: Austrian ISP Drei overtook Germany’s Hetzner to become the largest source of HTTP-based DDoS attacks, with DigitalOcean in second place. Most of the top offenders were hosting providers offering cloud-based virtual machines — the backbone of modern botnets, which Cloudflare estimates are up to 5,000 times more powerful than older IoT-based variants.

The report also highlights a resurgence in older, under-the-radar attack methods. These include floods exploiting legacy protocols such as RIPv1 and VxWorks, or targeting platforms like the open-source shooter game Teeworlds. Attacks using these vectors increased between 70% and 385% quarter-over-quarter, underscoring how threat actors continue to experiment with niche or outdated technologies to evade standard defenses.

Cloudflare says most DDoS attacks remain short in duration, often lasting under a minute — a tactic designed to cause disruption before automated systems can fully respond. The 7.3 Tbps attack, for instance, lasted just 45 seconds. Nonetheless, these rapid bursts are capable of crippling infrastructure, particularly when timed during periods of peak usage.


Recommended reading


Despite the growing threat, Cloudflare insists that many of the attacks detailed in its report were automatically mitigated using its autonomous defense systems. The company offers all its customers — including small sites — free, unmetered DDoS protection. It has also expanded its ISP DDoS Botnet Threat Feed, a free API service that enables over 600 participating internet providers worldwide to identify and dismantle botnet nodes on their networks.

As of mid-2025, Cloudflare has already blocked 27.8 million DDoS attacks — more than its entire volume for the whole of 2024. With the threat landscape continuing to evolve rapidly, the company reiterated its call for organisations to shift away from reactive defense strategies and embrace always-on protection.

“Even so-called ‘small’ attacks are dangerous,” the report concludes. “And as hyper-volumetric attacks become more frequent, only real-time, proactive defense will stand up to the speed and scale of modern DDoS campaigns.”

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data