If you think DDoS attacks are just an occasional nuisance that slows down websites, the numbers might change your mind. According to Gcore's data, 47.1 million DDoS attacks hit the global internet in 2025—averaging about 1.5 attacks per second. Meanwhile, Cloudflare alone blocked 20.5 million DDoS attacks in Q1 2025, a figure representing 96% of their entire 2024 total.
This isn't random traffic fluctuation. DDoS has become the internet's "background radiation"—constantly present, steadily intensifying, and increasingly difficult to defend against.
The largest recorded DDoS attack so far reached 31.4 Tbps, sustained for just 35 seconds. The number sounds abstract, but put it this way—it's roughly equivalent to every household broadband connection in the world sending data simultaneously to a single server, non-stop.
The growth curve behind this is even more unsettling: just 14 months ago, the record stood at 3.8 Tbps. That means attack scale grew 726% in a year and a half—and the primary driver of this exponential surge is AI.
In a Network World interview, Carlos Morales, SVP of Arbor Cloud at NETSCOUT, highlighted three critical shifts:
NETSCOUT recently announced doubling its Arbor Cloud DDoS mitigation capacity from 15 Tbps to 33 Tbps, distributed across 16 global scrubbing centers. This expansion partly comes from acquiring DigiCert's DDoS and WAF services in May this year.
But NETSCOUT itself admits this isn't the endgame—Morales stated "this won't be a one-time buildout, there will likely be more bandwidth upgrades ahead." Translated: attackers' budgets always outpace defenders'.
MazeBolt's statistics show that each minute of DDoS downtime costs an average of $22,000 (roughly $1.32 million per hour). The irony? Renting a DDoS-for-hire service costs as little as $38 per hour. Attackers can cost your business over $22K per minute for less than a cup of coffee—the attacker-to-defender cost ratio is a staggering 1:3158.
For budget-constrained SMEs and startups, building 30+ Tbps defense infrastructure in-house is obviously unrealistic. Cloud-based protection becomes the only viable path, but that also means handing your lifeline to a third party—when attacks outscale their capacity, who catches you?
NETSCOUT's strategy is clear: counter AI-powered attacks with automation and speed. "You can't rely on human speed, but you can rely on human judgment. Let technology handle speed and response," Morales said.
This means future DDoS defense will increasingly depend on AI-driven analytics engines—making filtering decisions in milliseconds as attacks unfold, while maintaining enough intelligence to distinguish genuine user traffic from malicious requests. For websites and services requiring round-the-clock protection, this "AI vs AI" paradigm is no longer optional—it's essential.
When attackers use AI to coordinate hundreds of thousands of devices flooding 30+ Tbps of traffic, human monitoring simply cannot react fast enough. Lafa System's AI-powered auto-ops can activate defense mechanisms in milliseconds, switch WAF rules in real-time, and auto-scale CDN capacity—you don't need a round-the-clock security team, let AI guard every minute for you.