Trending Topics

NETSCOUT warns DDOS attacks are spreading from enterprises to all sizes – no-one is safe
NETSCOUT’s 2H2025 DDoS Threat Intelligence Report, released today at MWC 2026, provides a stark warning to organisations of all sizes: the explosive growth of DDOS-for-hire services goes hand in hand with a shift to all digitally connected organisations.
“If you look at the last six months of last year, which is what the report focuses on, we are seeing some very worrying things going on around the nature of the attacks that are out there and their complexity,” Darren Anstee, Chief Technology Officer for Security at NETSCOUT, told TechFinitive.
This complexity comes via “the continued evolution of the DDoS-for-hire services that make that possible. We’re seeing some huge botnets now, things like Kimwolf that can generate very high attack traffic volumes and are also now building in relatively sophisticated capabilities into their attacks.”
The AI effect
And then, of course, there’s the AI effect. “On the DDoS side, [AI is]being embedded into the DDoS for higher tools now, which is a further simplification of how they can be used, and a further removal of a barrier to how they can be used fundamentally,” said Anstee.
In essence, this has “democratised” DDOS attacks, he explained. While the on-demand tools have always allowed skilled users to create a multitude of attacks, AI and automation has made it far easier for attackers “to find out what ports are open, what infrastructures are available, what services are there in whatever it is you want to attack”.
Factor in more automation around the nature of the attacks, including spoofing of addresses and how attacks can be randomised and rotated, and Anstee expects to see more “carpet bombing” attacks in the future.
Every business now under attack
The other big trend identified by the report is that all businesses are now under threat: not just the big organisations. So how do they stay safe?
“Understand what your kind of threat surface is and what’s most important to your business in terms of what keeps you running,” said Anstee. “Do you have a web presence that needs to be there? Do you have APIs and portals that you use for B to B connectivity that have to be there?”
Then there are the tools your hybrid workers use to stay connected, whether WebEx or Zoom: all those tools are a potential point of vulnerability.
“Second thing to understand is, what in your digital supply chain are you 100% reliant on?” said Anstee.
“This is something that’s become much more important over the last few years, because you used to find that attackers would go [straight] after their target. Now, if they think that target – say you’re a bank or an insurance company or a government – is well defended, they will go after something that you are dependent upon in your digital supply chain.”
NETSCOUT’s 2H2025 DDoS Threat Intelligence Report is now live, including individual country pages where you can explore region-specific DDoS attack data.
