Quick Summary
The Securityish Brief
Cloudflare’s Q4 2025 report reveals a dramatic increase in DDoS attacks, with 47.1 million incidents recorded, more than double the 2024 total. The UK notably climbed 36 places to become the sixth-most targeted country, indicating a troubling trend for businesses in the region.
The largest attack of the quarter was executed by the Aisuru-Kimwolf botnet, which primarily consists of malware-infected Android TVs. This attack, dubbed “The Night Before Christmas,” began on December 19 and reached a staggering 31.4 Tbps, targeting both Cloudflare customers and its infrastructure.
Cloudflare noted that the size and frequency of attacks surged, with the scale of large attacks increasing by over 700% compared to late 2024. Attackers are now favoring quick, high-volume bursts over prolonged floods, with some incidents concluding in under two minutes.
Many of these attacks are attributed to large botnets formed from compromised devices like routers and cameras, as well as the misuse of cloud-hosted virtual machines. This shift in tactics underscores the evolving nature of DDoS threats.
Financial services remain a primary target, exacerbated by geopolitical tensions, including attacks claimed by pro-Russian hacktivists NoName057(16) against UK government websites. The UK’s robust telecom and cloud infrastructure makes it particularly vulnerable to disruptions.
Common targets of DDoS attacks include telecom providers, IT service firms, and gaming sites, where outages can lead to significant financial losses and customer dissatisfaction. Most attacks have focused on Layer 3 and Layer 4 protocols.
To combat these threats, Cloudflare emphasizes the importance of automated systems capable of detecting and mitigating attacks in real time, as human responses may be too slow to effectively counteract rapid surges in traffic.
- Cloudflare reported 47.1 million DDoS attacks in 2025, more than double the previous year.
- The Aisuru-Kimwolf botnet executed a record 31.4 Tbps attack during the holiday season.
- The UK became the sixth-most targeted country for DDoS attacks, rising 36 places in the rankings.
- Financial services and telecom sectors remain primary targets for DDoS attacks.
- Automated systems are recommended for real-time detection and mitigation of DDoS threats.
Key Takeaways
- Review your organization’s DDoS mitigation strategies to ensure they are up-to-date and effective.
- Consider implementing automated systems that can detect and respond to DDoS attacks in real time.
- Monitor traffic patterns closely to identify unusual spikes that may indicate an ongoing attack.
- Educate employees about the risks of compromised devices and the importance of securing IoT devices.
- Engage with cybersecurity experts to assess vulnerabilities in your infrastructure and improve defenses.
Key Terms & Concepts
- DDoS Attack: In this article, a DDoS attack refers to a distributed denial-of-service attack that overwhelms a target with traffic to disrupt its services.
- Botnet: A botnet is a network of compromised devices, often used to launch coordinated attacks like DDoS.
- Layer 3 and Layer 4 Attacks: These refer to specific types of DDoS attacks that target the network and transport layers of the internet protocol stack.
- Aisuru-Kimwolf: Aisuru-Kimwolf is a botnet primarily composed of malware-infected Android TVs, responsible for significant DDoS attacks.
- NoName057(16): NoName057(16) is a group of pro-Russian hacktivists known for claiming responsibility for attacks on UK government websites.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.