New findings from Cloudflare’s Q4 2025 DDoS report reveal a sharp escalation in the scale and sophistication of global cyberattacks, with Ercan Aydin, AVP for the Middle East, Türkiye and Africa at Cloudflare, warning that adaptive, autonomous defences are now essential to protect critical digital infrastructure.
Cloudflare, a security, performance and reliability company helping to build a better Internet, has announced its Q4 2025 DDoS Report. The report offers a comprehensive analysis of the evolving Distributed Denial of Service (DDoS) threat landscape, based on data from the Cloudflare network, one of the largest in the world.
Key Findings:
- DDoS attacks surged by 121% in 2025, reaching an average of 5,376 attacks automatically mitigated every hour.
- In the final quarter of 2025, Hong Kong jumped 12 places to become the second most DDoS-attacked location globally. The United Kingdom also rose sharply, climbing 36 places to rank sixth.
- Infected Android TVs, part of the Aisuru-Kimwolf botnet, bombarded Cloudflare’s network with hyper-volumetric HTTP DDoS attacks, while telecommunications providers emerged as the most targeted industry.
2025 saw a huge spike in DDoS attacks
In 2025, the total number of DDoS attacks more than doubled to 47.1 million. Attacks have surged in recent years, with volumes increasing by 236% between 2023 and 2025.
Cloudflare mitigated an average of 5,376 DDoS attacks per hour in 2025, including 3,925 network-layer attacks and 1,451 HTTP-based attacks.
Network-layer DDoS attacks more than tripled
Network-layer attacks showed the most significant growth, rising from 11.4 million in 2024 to 34.4 million in 2025. In Q4 2025, they accounted for 78% of all DDoS activity.
‘The Night Before Christmas’ campaign
On 19 December 2025, the Aisuru-Kimwolf botnet launched hyper-volumetric HTTP DDoS attacks exceeding 20 million requests per second (MRPS). The botnet, primarily made up of malware-infected Android TVs, is estimated to comprise between one and four million devices.
Hyper-volumetric attacks
Throughout 2025, Cloudflare recorded a steady increase in hyper-volumetric attacks. In Q4 alone, they rose by 40% quarter on quarter, with attack sizes growing by more than 700% compared with late 2024. One attack peaked at 31.4 Tbps and lasted just 35 seconds.
Most targeted industries and locations
Telecommunications, service providers and carriers were the most attacked industries, followed by IT services, gambling and gaming and software.
China, Hong Kong, Germany, Brazil and the United States remained the most targeted locations globally.
Attack Sources

Bangladesh became the largest source of DDoS attacks in Q4 2025, overtaking Indonesia, which fell to third place. Ecuador moved into second.
Most attacks originated from IP addresses associated with major cloud providers, including DigitalOcean, Microsoft, Tencent, Oracle and Hetzner, highlighting the role of easily provisioned cloud infrastructure.
Ercan Aydin, AVP for the Middle East, Türkiye and Africa at Cloudflare, said: “The scale and frequency of DDoS activity we observed in 2025 underscore how rapidly threat actors are evolving their tactics. From hyper-volumetric attacks to complex multi-vector campaigns, our data shows that safeguarding digital services requires adaptive, autonomous defenses. By proactively leveraging real-time intelligence and mitigation capabilities, we help organisations stay ahead of these escalating threats.”


