New research has revealed an 82% surge in Distributed Denial of Service (DDoS) attack frequency between 2023 and 2024.
This is according to an insights report from the Zayo Group, which found that attack volume almost doubled from 90,000 incidents in 2023 to 165,000 in 2024.
This was driven by cyber-criminals leveraging AI and expanding adoption of IoT devices to launch faster, more persistent, and more complex attacks.
“We’re seeing attackers use larger botnets of compromised IoT devices and AI to drastically increase the scale of attacks,” said Max Clauson, senior vice president of Network Connectivity at Zayo.
“As the sophistication of DDoS attacks continues to grow, cyber-criminals are finding ways to exploit cloud services, higher bandwidth availability, and new vulnerabilities in software and network protocols.
“Both the public and private sector need to invest heavily in DDoS mitigation to continue to protect critical infrastructure and ensure long-term data security.”
In terms of sectors, finance say the largest year-on-year growth in attack volume of all sectors, surging from 3.5% in 2023 to representing 7% of all attacks in 2024.
Telecommunications, however, is still the most targeted sector, but other industries are catching up. In 2024, telecommunications represented 42% of all observed incidents, down from 48% of all attacks in 2023.
Healthcare saw a 223% growth in the total number of attacks year-on-year, and manufacturing continues to explode as a large-scale target, with the average attack size growing 257% from 2023 to 2024.
Cloud and software as a service (SaaS) firms experienced a rise in attacks as well, accounting for 11% of all attacks with more than 19,000 throughout the year – 15,740 of which occurred in the second half of 2024 alone.
Recommended reading
- DDoS Attacks Surged 56% in H2 2024
- 2024 Saw the Biggest DDoS Attack On Record, Says Cloudflare
- DDoS Platforms Seized in Worldwide Crackdown
As DDoS attacks proliferate, the financial toll remains significant.
At $6,000 (£4,743) per minute, and an average attack lasting 39 minutes, businesses lose nearly $234,000 (£185,000) per incident.
Cyber-criminals remain opportunistic in strategically timing their attacks to maximise disruption, with the majority occurring during business hours.
There is also an expected rise in DDoS-as-a-Service, enabling individuals with limited technical skills to conduct attacks, which could result in a greater number of attacks and a wider variety of attack methods.
DDoS attacks are an inescapable reality for organisations, regardless of industry or size.
The financial, operational, and reputational damages caused by these attacks can be devastating, forcing businesses to divert critical resources to mitigation and recovery.
As AI and automation continue to shape the threat landscape, proactive and scalable DDoS protection is more essential than ever.





