Q1 2025 DDoS report: operating through repeated attack waves
Plan handovers, capacity monitoring and policy records for repeated attack waves.
Contents of this article
Campaigns are different from individual peaks
Cloudflare’s April 27, 2025 report described an 18-day multi-vector campaign against its infrastructure. It also included observations from April; distinguish those updates from the first-quarter reporting period.
Handovers need business context
Repeated waves can affect different protocols and entry points. Record affected domains or ports, user symptoms, active policies and the next review time. A generic note that protection is enabled leaves the next operator without an actionable picture.
Preserve the reason for each change
Place policy changes and business metrics on one timeline, with the operator, scope and rollback condition. Limit emergency partner exceptions to the required service and time window, then review them after the incident.
Prepare for the next wave
After a quiet period, review false positives, resource peaks and alert delays. Repeated weaknesses may call for fixing exposed origins, missing ports or application capacity before increasing the protection tier.
References
Cloudflare Q1 2025 DDoS report
