A new cybersecurity report reveals alarming trends in distributed denial-of-service (DDoS) attacks, with threat actors launching increasingly sophisticated campaigns that are reshaping the digital threat landscape.
## Record-Breaking Attack Volumes
The latest Gcore Radar report analyzing Q1-Q2 2025 data shows a dramatic 41% year-over-year increase in total attack volume. The most devastating assault reached 2.2 terabits per second (Tbps), breaking the previous 2 Tbps record set in late 2024.
Attack frequency has also intensified significantly. Total incidents climbed from 969,000 in the second half of 2024 to 1.17 million in the first half of 2025—a 21% quarterly increase that underscores the escalating threat environment.
## Technology Sector Becomes Primary Target
In a notable shift, the technology industry now accounts for 30% of all DDoS attacks, overtaking gaming as the most targeted sector. This change reflects attackers’ strategic focus on high-value infrastructure that supports multiple business operations.
Financial services face mounting pressure, representing 21% of attacks as cybercriminals target banks and payment systems for maximum disruption potential. Gaming, while still significant at 19%, has seen its share decrease from 34% as improved defenses take effect.
## Evolving Attack Strategies
Modern DDoS campaigns are becoming more sophisticated through several key developments:
**Extended Duration**: Attacks lasting 10-30 minutes have nearly quadrupled, while brief assaults under 10 minutes decreased by 33%. This shift toward sustained campaigns maximizes operational disruption.
**Multi-Vector Approaches**: Application-layer attacks now comprise 38% of total incidents, up from 28% in late 2024. These complex assaults target web applications and APIs simultaneously, making detection and mitigation more challenging.
**Advanced Techniques**: Attackers increasingly exploit business logic vulnerabilities, affecting e-commerce inventory systems, payment flows, and customer interaction points.
## Root Causes of the Surge
Several factors drive this escalation:
– **Accessible Tools**: Cheap DDoS-for-hire services lower barriers for cybercriminals
– **IoT Vulnerabilities**: Unsecured devices create massive botnets for amplified attacks
– **Global Tensions**: Geopolitical instability fuels targeted cyber campaigns
– **Technical Innovation**: Multi-layered attack methods increase both complexity and impact
## Geographic Attack Patterns
The United States and Netherlands remain primary sources for network-layer attacks, while Hong Kong has emerged as a significant new threat origin, contributing 17% of network-layer and 10% of application-layer incidents.
## Defense Implications
The evolving threat landscape demands comprehensive protection strategies that combine traditional DDoS mitigation with advanced web application and API security. Organizations must implement multi-layered defenses capable of detecting and neutralizing both volumetric attacks and sophisticated application-layer threats.
As cybercriminals continue refining their tactics, businesses across all sectors—particularly technology, financial services, and gaming—must prioritize robust cybersecurity measures to protect their digital infrastructure and maintain operational continuity.
