Distributed Denial-of-Service (DDoS) attacks have escalated dramatically, with recent incidents surpassing 1 terabit per second (Tbps), highlighting the growing capabilities of cybercriminals and the vulnerabilities of global internet infrastructure.
In September 2025, Cloudflare reported mitigating a massive 11.5 Tbps DDoS attack. This attack, primarily a UDP flood, originated from compromised resources within the Google Cloud Platform and lasted approximately 35 seconds. Despite its brevity, the sheer volume of the attack underscored the potential for significant disruption. ([cybersecuritynews.com](https://cybersecuritynews.com/record-breaking-ddos-attack-11-5-tbps/?utm_source=openai))
Shortly thereafter, another unprecedented attack occurred. FastNetMon, a DDoS detection solutions provider, identified and helped mitigate an attack targeting a major DDoS scrubbing vendor in Western Europe. This assault reached a staggering 1.5 billion packets per second (1.5 Gpps), making it one of the most intense packet-rate floods ever publicly disclosed. The attack was primarily a UDP flood, originating from a vast botnet of compromised customer-premises equipment (CPE), including IoT devices and routers, spread across more than 11,000 unique networks worldwide. ([cybersecuritynews.com](https://cybersecuritynews.com/1-5-gpps-ddos-attack/?utm_source=openai))
These incidents are part of a concerning trend. In October 2022, the Fodcha DDoS botnet resurfaced with enhanced capabilities, including the ability to generate over 1 Tbps of traffic and attack more than 100 targets daily. The botnet leveraged a network of over 60,000 daily active bot nodes, demonstrating the increasing scale and sophistication of DDoS threats. ([cybersecuritynews.com](https://cybersecuritynews.com/fodcha-ddos-botnet-now-capable-of-1tbps-power/?utm_source=openai))
More recently, in December 2025, the Aisuru botnet set a new world record by launching a 29.7 Tbps DDoS attack. This hyper-volumetric network-layer attack targeted multiple sectors, including telecommunications providers, gaming platforms, hosting companies, and financial services firms. The attack utilized a UDP “carpet bombing” technique, hammering approximately 15,000 destination ports per second while randomizing packet attributes to evade static filtering. ([cybersecuritynews.com](https://cybersecuritynews.com/29-7-tbps-ddos-attack/?utm_source=openai))
These escalating DDoS attacks underscore the urgent need for robust, automated defense mechanisms capable of detecting and mitigating such large-scale threats in real-time. Organizations must prioritize the security of their infrastructure, implement comprehensive monitoring systems, and collaborate with cybersecurity experts to stay ahead of these evolving threats.