45 Seconds Under Siege: Inside Cloudflare’s 7.3 Tbps DDoS Storm
14:57, 03.08.2026
In May 2025, Cloudflare stopped a massive DDoS attack aimed at a hosting provider using its network protection service. At the time, the attack set a public record at 7.3 terabits per second. It pushed 37.4 terabytes of malicious traffic toward one target in only 45 seconds.
To picture that scale, imagine more than 9,000 HD movies, about 9 million songs, or 12.5 million high resolution photos arriving almost at once. Your connection could become unavailable before your team has time to react.
Why UDP Made the Attack So Powerful
Almost all the traffic came through UDP floods. UDP sends data quickly without waiting for confirmation from the receiving device. That speed supports video calls, streaming, and online games, but attackers can exploit it to overwhelm networks.
The campaign also used reflection and amplification. Attackers forged the victim’s IP address and sent requests to third party servers. Those servers delivered their replies to the victim, multiplying the pressure while hiding the original source.
How DDoS Attacks Can Impact Your Business
Our expert view is clear. DDoS attacks are becoming faster, larger, and easier to launch through infected routers, cameras, servers, and other connected devices. Even a brief burst can disrupt sales, customer access, internal systems, and brand trust.
If your business depends on online services, you should treat automated DDoS protection as basic infrastructure, not an optional upgrade. Share this article with your network, follow our social channels, and read our other cybersecurity stories to stay informed.