DigiCert UltraDDoS Biannual Report 2025

DigiCert UltraDDoS Biannual Report 2025
DigiCert’s UltraDDoS Protect report shows a sharp decline in DDoS activity in the first half of 2025, with attackers increasingly favoring short, low-volume, single-target campaigns after enforcement actions such as Operation PowerOff disrupted major DDoS-for-hire services. Financial Services was the most targeted industry, while Saudi Arabia, the United States, and Sweden saw the highest attack volumes, highlighting a shift toward more focused disruption amid a rebuilding phase for threat actors. #UltraDDoSProtect #OperationPowerOff #DigiCert #FinancialServices #SaudiArabia #Sweden

Keypoints

  • Annual and biannual cybersecurity reports typically begin with an introduction that explains the scope, data source, reporting period, and mitigation context, followed by an executive summary that highlights the most important shifts, statistics, and threat trends.
  • The report structure here includes sections for stats at a glance, attack statistics and trends, attack-type comparisons, attack vectors, targeted industries, affected countries, source countries, and a company overview, which is a common layout for DDoS intelligence reports.
  • For January through June 2025, UltraDDoS Protect recorded 15,260 DDoS attacks, an 84.37% decrease year over year, indicating a major contraction in attack volume compared with the same period in 2024.
  • The report links the decline to two main factors: tuning by the DigiCert SOC to reduce nuisance alerts and global law enforcement disruption of DDoS-for-hire services and botnets, especially Operation PowerOff.
  • Despite fewer attacks overall, the largest event was still substantial at 813.39 Gbps and 71+ Mpps, showing that rare high-impact incidents remain a serious risk for organizations lacking mitigation capacity.
  • Nearly 73% of attacks were in the 0.0–0.5 Gbps range, and attacks above 100 Gbps fell by more than 94%, reinforcing the trend toward lower-bandwidth activity and away from mass volumetric campaigns.
  • Attack duration was generally short: nearly 10,000 attacks lasted under 10 minutes, while long-duration attacks were uncommon, suggesting a preference for rapid disruption, probing, or low-cost nuisance attacks.
  • Unique-style attacks dominated the period, accounting for 87.80% of activity, while carpet bombing dropped to 12.20%, a 94.75% year-over-year decline that signals a tactical shift away from broad multi-IP targeting.
  • Monthly patterns show carpet bombing steadily losing share from 33% in January to just over 3% in June, while unique attacks rose above 95% by June, emphasizing a clear change in attacker behavior.
  • Attack vectors were simpler overall: Total Traffic led with 42.94%, followed by UDP and TCP ACK, while DNS Amplification dropped to 4.44%, indicating reduced reliance on previously common amplification techniques.
  • Most attacks used a single vector, with 70.22% relying on one vector and 29.78% using multiple vectors, suggesting that simpler campaigns were more common than complex multi-vector operations.
  • Financial Services was the most targeted industry, accounting for 47.18% of attacks, followed by IT/Technical Services and Communication Service Providers; together, these three sectors represented over 80% of observed activity.
  • The industry data suggests adversaries are concentrating on critical digital infrastructure and services with high operational sensitivity and business impact potential.
  • Saudi Arabia was the most attacked country at 29.66%, followed by the United States and Sweden, reflecting both regional conflict dynamics and geopolitically motivated targeting patterns.
  • The United States generated the most observed source traffic at 39.24%, likely due to abuse of U.S.-based botnets and VPS infrastructure, while China, Colombia, Russia, and Vietnam also ranked prominently as source locations.
  • The report’s recurring theme is that the DDoS threat landscape is in a transitional phase: overall attack volume is down, but adversaries are still active, adapting tactics, and focusing on shorter, more targeted disruption.
  • Key takeaways include the importance of maintaining mitigation readiness, monitoring for low-volume but frequent attacks, and preparing for rapid changes in vector, duration, and targeting patterns as threat actors rebuild capacity.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)

Download Report from Github