Q1 2025 DDoS report: operating through repeated attack waves

Plan handovers, capacity monitoring and policy records for repeated attack waves.

Contents of this article

Campaigns are different from individual peaks

Cloudflare’s April 27, 2025 report described an 18-day multi-vector campaign against its infrastructure. It also included observations from April; distinguish those updates from the first-quarter reporting period.

Handovers need business context

Repeated waves can affect different protocols and entry points. Record affected domains or ports, user symptoms, active policies and the next review time. A generic note that protection is enabled leaves the next operator without an actionable picture.

Preserve the reason for each change

Place policy changes and business metrics on one timeline, with the operator, scope and rollback condition. Limit emergency partner exceptions to the required service and time window, then review them after the incident.

Prepare for the next wave

After a quiet period, review false positives, resource peaks and alert delays. Repeated weaknesses may call for fixing exposed origins, missing ports or application capacity before increasing the protection tier.

References

Cloudflare Q1 2025 DDoS report

Related products and onboarding

View products and onboarding information

Back to industry insights Contact technical support