← All posts

DDoS in the terabit era — the threat landscape in numbers

Data center corridor with orange-lit server racks — cover of the KAEMI Cyber Report 2026: DDoS in the terabit era

With the KAEMI Cyber Report 2026 we present our own analysis of the global threat landscape. The data basis is the published research of Cloudflare — the network that carries a substantial share of the world's internet traffic and on which our managed services are built. Here we summarise the key numbers and findings on DDoS in the terabit era, bots, APIs and DNS — with a focus on what they mean for your organisation's resilience.

How much has the DDoS threat really grown?

Cloudflare mitigated 47.1 million DDoS attacks in 2025 — up 121 percent on 2024 and more than three times the 2023 figure. The first half of 2026 shows this has become the steady state: another 23.2 million mitigated attacks, roughly 128,000 per day on average. Mitigated HTTP DDoS requests alone added up to 29.64 trillion in the half-year. Anyone still treating DDoS as a rare exception in their risk planning is working from an outdated picture.

Why are 35 seconds the new nightmare scenario?

The largest attack ever measured reached 31.4 terabits per second in December 2025 — and was over after 35 seconds. That is not an outlier but a tactic: 90.6 percent of all attacks last less than ten minutes. At the same time the extremes are becoming a series: terabit-scale attacks jumped from 130 in the first quarter of 2026 to 805 in the second — a sixfold increase. The Christmas campaign of the Aisuru/Kimwolf botnet — at times one to four million compromised devices, mostly Android TV boxes — delivered 902 hypervolumetric attacks in just 13 days.

The consequence is uncomfortable but clear: when attacks are over in seconds, human reaction stands no chance. On-demand rerouting, manually activated scrubbing centres and phone-based escalation chains are structurally too late. What is needed is an always-on architecture that detects and mitigates attacks autonomously at the network edge — in seconds, with no one having to intervene. And for the acute case: our DDoS emergency response at stop-ddos.team is available around the clock.

Why does the most dangerous traffic often stay invisible?

In parallel with the volume escalation, the quiet attack is becoming professionalised. 31.2 percent of all application traffic comes from bots — 93 percent of it unverified and thus potentially malicious. The typical application-layer attack respects protocols, stays below rate limits and looks like pleasing growth in the logs. Its effect only shows up in the numbers: rising infrastructure costs, falling conversion, distorted analytics. On top of that comes a new category: AI crawlers already account for 20 percent of verified bot traffic, and agentic AI traffic grew by 1,500 percent within a year.

The picture is even starker for interfaces: APIs carry 60 percent of dynamic HTTP traffic, yet machine-led discovery finds on average 33 percent more active endpoints than the organisation itself has documented — shadow APIs that nobody protects because nobody knows them. And the window is shrinking towards zero: in the documented extreme case, only 22 minutes passed between the publication of an exploit proof-of-concept and the first observed attack attempt. No patch process is that fast — the practical way out is virtual patching at the network edge, as we run it in our managed application security service.

Why is DNS the underestimated attack vector?

DNS floods were the single most common vector in the second quarter of 2026, accounting for 40 percent of all network-layer attacks: if name resolution fails, every service above it becomes unreachable — no matter how well protected it is itself. At the same time, the integrity of name resolution remains patchy: around 80 percent of all DNS queries concern domains without a DNSSEC signature, even though Germany's BSI has recommended signing for years. On modern DNS platforms, DNSSEC is one click; the real work is the decision to prioritise it.

What decision-makers should check now

Germany was among the three most attacked countries worldwide in the fourth quarter of 2025, and with the NIS2 obligations at the latest, availability is a leadership topic. Three review questions from the report for your next risk board:

  • Does DDoS appear as a distinct scenario in your business continuity plan — including a communication plan for customers, partners and regulators?
  • Is your protection always-on, with a rehearsed runbook — or does your operation still rely on manual rerouting in an emergency?
  • Do you rehearse the emergency under realistic conditions, with management and business units at the table rather than only in the NOC?

The report's most important observation: whether an organisation survives an attack unscathed is decided long before the attack — in the architecture and in the responsibilities. The full KAEMI Cyber Report 2026 with all sources will be published shortly. If you want to check your own environment against these patterns: as a Cloudflare partner we run DDoS protection, WAAP and DNS security as a managed service — the entry point is a no-obligation first conversation with a look at your real traffic.

Want to protect your web apps and APIs from flaws like this for good?

KAEMI implements and manages WAF, DDoS protection, bot and API management on the Cloudflare platform — as a managed service.