DDoS Attacks Surge 168% as AI and Geopolitics Fuel a New Wave of Cyber Disruption

    Cyberattacks intensified dramatically in 2025, with distributed denial-of-service (DDoS) activity reaching levels not seen in years. According to the Radware 2026 Global Threat Analysis Report, network-layer DDoS attacks surged 168.2% year on year, while web and application-layer attacks also recorded triple-digit growth.

    The findings paint a stark picture: cyber threats are becoming faster, more automated and increasingly tied to geopolitical conflict.

    Network-Layer Attacks Return at Massive Scale

    Targeting layers 3 and 4 of the OSI model, network-layer DDoS attacks saw peak volumes approach 30 Tbps  signalling a resurgence of brute-force volumetric campaigns.

    In the second half of 2025 alone, the average Radware customer experienced more than 25,351 network-layer DDoS attacks approximately 139 per day. This dramatic escalation marks a clear shift back towards sustained high-volume disruption.

    The technology sector bore the brunt, accounting for 45% of all network-layer DDoS attacks, up sharply from just 8.77% in 2024. Telecommunications and financial services were also heavily targeted, reflecting attackers’ focus on critical infrastructure and high-value digital services.

    Geographically, North America accounted for 63.1% of network-layer attacks, followed by the Middle East (16.1%) and Europe (13.7%).

    Web DDoS Attacks Become Faster and More Frequent

    Application-layer DDoS activity climbed 101.4% year on year, demonstrating that attackers are not only increasing volume, but diversifying their tactics.

    Notably, most high-impact web DDoS attacks now last less than 60 seconds. This compressed attack window renders manual mitigation strategies increasingly ineffective. Instead of relying on massive traffic floods, adversaries are deploying smaller, more frequent bursts designed to slip under traditional detection thresholds. In fact, 94.4% of web DDoS attacks measured under 100,000 requests per second.

    EMEA was the most targeted region, accounting for 57% of global web DDoS activity, while APAC experienced the fastest growth, with a staggering 485% year-on-year increase.

    AI-Powered Automation Accelerates Threat Activity

    The report also highlights the explosive growth of automated and AI-enabled threats. Bad bot activity increased 91.8%, driven by generative AI tools that have significantly lowered the barrier to entry for attackers.

    Within the first six months of 2025, malicious bot traffic had already reached 89.2% of the total volume recorded across all of 2024. Credential stuffing, scraping and account takeover campaigns have become more scalable and adaptive, enabling attackers to industrialise digital fraud.

    North America accounted for 40.7% of malicious bot transactions, followed by APAC (25%), EMEA (19.1%) and Central and Latin America (15.2%).

    Hacktivism and Geopolitics Drive Persistent Disruption

    Beyond automation, geopolitical and ideological tensions remain a primary driver of DDoS activity. Hacktivist campaigns continued at sustained, high volumes throughout 2025.

    Europe accounted for 48.4% of all claimed hacktivist attacks, significantly ahead of the Middle East (17.7%) and Asia (17.5%). Israel (12.2%), the United States (9.4%) and Ukraine (8.9%) were among the most targeted nations, with government services representing 38.7% of claimed attacks.

    The hacktivist group NoName057(16) claimed 4,693 attacks in 2025 the highest recorded volume by a single hacktivist entity to date.

    A Shift Toward Automated Defence

    According to Pascal Geenens, vice president of threat intelligence at Radware, the pace and scale of attacks demand a fundamental shift in defensive strategy.

    Organisations must now deploy automated, real-time mitigation systems capable of responding in seconds not minutes to withstand modern multi-vector campaigns.

    The message from 2025 is clear: DDoS is not fading into the background. It is evolving faster, smarter and more politically charged than ever before.