Gcore Radar report reveals 150% surge in DDoS attacks year-on-year
Luxembourg, Luxembourg, Mon, Mar 24, 2026, CyberNewswire
Luxembourg, Luxembourg, Mon, Mar 24, 2026, CyberNewswire
Gcore data highlights a threat landscape defined by newfound automated attack capabilities, scale, and frequency
Gcore , a global infrastructure and software provider for AI, cloud, network, and security solutions, announced the findings of its Q3-Q4 2025 Gcore Radar report on DDoS attack trends.
The report reveals increasing attack volumes, sophisticated tactics, and changes in attack locations driven by evolving botnet infrastructure.
Total number of attacks grew to 1300K in Q4 2025 from 512K in Q4 2024 , indicating a new phase of scale and frequency in DDoS activity. Attack volumes surged to 12 Tbps in Q4 , a sixfold increase highlighting unprecedented growth in attack capabilities. 75% of network-layer attacks lasted less than one minute , while application-layer attacks showed a shift toward longer durations. Technology remains the most targeted sector, accounting for 34% of attacks, followed by financial services (20%) and gaming (19%). Geographic patterns show a strong concentration of attack sources in Latin America , with Mexico and Brazil together accounting for 55% of observed activity.
New Drivers of DDoS Attack Growth and Intensity
DDoS attack volumes and scale have reached new levels, with a sixfold increase from 2.2 Tbps to 12 Tbps, reflecting the rapid escalation of attack capabilities.
Several structural factors are causing DDoS attack numbers to grow:
Broader access to attack tools Expansion of insecure IoT ecosystems Geopolitical and economic instability Increasing sophistication of attack techniques
Network-layer Attacks Continue to Increase
Network-layer attacks accounted for 82% of all observed incidents in the current period, a significant 20% increase from the last report.
The report reveals increasing attack volumes, sophisticated tactics, and changes in attack locations driven by evolving botnet infrastructure.
This surge reflects the economics of cybercrime: network-layer attacks are cheaper and easier to execute, making them an attractive option for attackers seeking to cause disruption.
Recent Data Reveals Shifts in Attack Duration and Sophistication
Network-layer DDoS attacks became shorter in duration, with most attacks (75%) lasting less than one minute. Only 2% of attacks extended beyond ten minutes, indicating a continued shift toward intense, short-lived bursts.
Application-layer DDoS attacks followed an opposite trajectory, with medium-duration attacks becoming more common as 64% of attacks exceeded 10 minutes.
Attackers increasingly relied on automation to execute large-scale campaigns, reflecting a transition to more deliberate, business-impact-focused attacks, including account takeover attempts and direct manipulation of application workflows.
Attackers Target Digitally Intensive Sectors for Maximum Disruption
Attacks concentrated on several key sectors, including technology (34%), financial services (20%), and gaming (19%). These sectors are favored targets because service availability is critical, and disruption can generate immediate operational or financial impact.
The continued growth of attacks targeting the technology sector reflects its foundational role in today’s digital economy. As digital ecosystems become increasingly interconnected and cloud-dependent, attackers prioritize infrastructure-layer targets capable of generating broad disruption.
The Americas Dominate Geographical Distribution of Attack Sources
The geographic distribution of attack sources shows a strong concentration in the Americas, with Mexico accounting for 31% of network-layer observed traffic, followed by Brazil (24%) and the United States (20%).
The US remains prevalent for application layer attacks as well, at 23% representation. The American dominance of network-layer attacks is attributed to the AISURU botnet, which affects networks and device ecosystems in these countries.
Effective protection requires globally distributed capacity, both in regions with high traffic demand and in regions that are frequent sources of attack activity.
To access the full report, visit Gcore Radar Report Q3-Q4 2025 .
Gcore is a global infrastructure and software provider for AI, cloud, network, and security solutions. Headquartered in Luxembourg, Gcore operates its own sovereign infrastructure across six continents, delivering ultra-low latency and compliance-ready performance for mission-critical workloads.
Its AI-native cloud stack combines software innovation with hyperscaler-grade functionality, enabling enterprises and service providers to build, train, and scale AI across public, private, and hybrid environments.
By integrating AI, compute, networking, and security into a single platform, Gcore accelerates digital transformation and empowers organizations to unlock the full potential of AI-driven services.
Based on reporting by Cyber Security News.
