August 6, 2026
What 2025 Attack Traffic Reveals About the Changing Nature of Cyber Risk
Billions of Blocked Requests Tell a Story That Goes Beyond Attack Volume

By CDNetworks
5 min read
Billions of Blocked Requests Tell a Story That Goes Beyond Attack Volume
Cybersecurity reports often lead with the largest number available.
Billions of malicious requests. Terabit-scale DDoS attacks. Millions of automated requests every day.
These figures communicate scale, but scale alone does not explain what security teams are dealing with.
The more consequential signal from 2025 was the consistency with which attackers operated across different layers of the digital environment. Network infrastructure, web applications, user accounts, and APIs were targeted through campaigns designed to blend into ordinary traffic, remain active over time, and move between attack methods.
Based on traffic observed and mitigated by the CDNetworks security platform during 2025, four areas deserve particular attention: DDoS attacks, web application attacks, automated bot activity, and API abuse.
Together, the data shows why enterprise security strategies must account for persistence, automation, behavioral context, and coordinated protection across multiple layers.
Terabit-Scale DDoS Attacks Have Become a Repeatable Scenario
In 2025, CDNetworks blocked 227.37 million network-layer DDoS attack requests.
Among those attacks, 329 exceeded 1 Tbps. The largest reached 1.55 Tbps. Application-layer DDoS activity also showed a strong regional concentration, with 67.45% of observed traffic attributed to the Asia-Pacific region.
The important finding is the frequency of these large attacks.
A terabit-scale event can no longer be treated solely as an exceptional scenario reserved for a crisis-response exercise. When hundreds of attacks cross the 1 Tbps threshold within a year, high-capacity mitigation becomes part of routine availability planning.
Network-layer capacity is only one part of the problem.
Layer 7 attacks can overwhelm login pages, search functions, APIs, checkout processes, and other resource-intensive application journeys without exhausting network bandwidth. An organization may therefore withstand a large Layer 3 or Layer 4 attack while still experiencing disruption at the application layer.
Attackers can also shift techniques during the same campaign. Volumetric traffic may create the initial pressure, while application requests target the services that are most expensive to process.
This makes coordination essential. DDoS defense must connect network-layer mitigation with application visibility, behavioral analysis, traffic management, and automated response.
Web Attacks Are Persistent, Diverse, and Easy to Underestimate
CDNetworks blocked 21.51 billion web application attack requests during 2025.
Nearly 60% of those requests were observed during the second half of the year. HTTP protocol anomalies accounted for 45% of the total activity.
This pattern suggests continuous pressure against public-facing digital services, rather than a single campaign or short-lived seasonal spike.
HTTP protocol anomalies can include malformed, unexpected, or non-standard requests intended to test how applications, servers, proxies, and other infrastructure components respond to unusual conditions.
Some anomalous requests may appear insignificant when reviewed individually. Their meaning becomes clearer when they are evaluated alongside the targeted endpoint, session history, response behavior, request frequency, and user context.
That distinction matters because modern applications rarely operate as isolated websites. They depend on distributed architectures, third-party integrations, authentication services, APIs, and cloud infrastructure. A request that appears harmless at one control point may carry greater significance when viewed as part of a broader sequence.
Security teams therefore need more than static request inspection. They need enough context to determine whether unusual traffic represents a configuration issue, automated reconnaissance, exploitation activity, or part of a coordinated attack.
Bot Management Now Requires Business Context
Automated traffic has become a normal part of the internet.
Search engines, monitoring services, AI agents, price-comparison platforms, content aggregators, and accessibility tools may all access websites through automated systems. Malicious operators use similar automation for credential attacks, scraping, account abuse, inventory hoarding, and fraud.
In 2025, 74% of the bot traffic classified by CDNetworks was attributed to bad bots. E-Commerce and Retail accounted for 24% of observed bot activity.
CDNetworks also observed an average of 1.64 million AI bot requests per day. Data scraping and content retrieval represented 72.67% of the recorded AI bot activity.
These figures should be interpreted carefully.
Bad bots and AI bots are not interchangeable categories. AI-related traffic may include legitimate search activity, user-initiated retrieval, commercial data collection, or repeated access to proprietary content. The risk depends on who operates the bot, what information it accesses, how frequently it returns, and what effect it has on the business.
A binary bot-versus-human classification is therefore insufficient.
Organizations need policies that distinguish between approved automation, tolerated automation, unwanted commercial access, and clearly malicious behavior. Those policies may vary by endpoint and business model.
An e-commerce company, for example, may permit search crawlers to index product pages while restricting automated access to pricing APIs, inventory data, customer accounts, or checkout functions.
The key questions become:
Who is operating the automated agent?
What is it attempting to access?
Does the activity align with the organization's commercial and security policies?
What operational, financial, or intellectual-property impact does the activity create?
Effective bot management depends on answering these questions continuously, rather than applying the same action to every automated request.
API Attacks Often Look Technically Valid
APIs present a particularly difficult detection challenge because malicious requests do not always contain obvious technical abnormalities.
CDNetworks blocked an average of more than 15 billion malicious API requests per month during 2025. That is equivalent to over 500 million requests per day, based on a 30-day month.
Authentication bypass accounted for 18.8% of observed API attacks. Low-frequency, long-duration API attacks continued for an average of 21.7 days.
The duration is as significant as the volume.
Many security controls are designed to identify sharp changes, high request rates, or recognizable exploit patterns. Attackers can reduce their visibility by distributing requests across accounts, IP addresses, devices, and longer periods.
An individual API call may use valid syntax. It may come from an authenticated account, target a legitimate endpoint, and remain below a conventional rate limit.
Risk becomes visible only when the request is connected to identity, authorization, sequence, historical behavior, and business intent.
Consider an account that performs a permitted action hundreds of times across several weeks. Each request may be technically authorized, yet the combined behavior could indicate scraping, credential abuse, promotion exploitation, inventory manipulation, or unauthorized data collection.
API security therefore requires runtime and behavioral context. Schema validation, authentication, and request inspection remain important, but they cannot independently identify every form of business-logic abuse.
The Common Pattern: Attacks Are Becoming Harder to Separate From Normal Activity
The four datasets describe different attack surfaces, but they point toward the same operational challenge.
Attack traffic frequently resembles legitimate traffic.
Application-layer DDoS requests may follow normal user journeys. Web attacks may appear as unusual but syntactically acceptable requests. Bots may perform activities that also have legitimate commercial uses. API abuse may occur through authenticated sessions and approved endpoints.
This places greater pressure on security teams to understand behavior, rather than relying entirely on isolated indicators.
The most effective defenses will connect several forms of context:
- Infrastructure and network conditions
- Application and API behavior
- User, device, and session identity
- Request sequences over time
- Endpoint sensitivity and business purpose
- The operational impact of allowing or blocking traffic
These signals must also be evaluated quickly enough to support automated mitigation. Manual investigation remains valuable, but it cannot independently manage billions of requests or campaigns that continuously change tactics.
What Enterprise Security Teams Should Prioritize
The 2025 data suggests several practical priorities for security leaders.
First, organizations should plan for repeated high-volume DDoS events. Mitigation capacity, upstream connectivity, application resilience, and incident procedures should be validated under realistic conditions.
Second, network, application, bot, and API defenses should operate as a coordinated system. Attackers do not organize their campaigns according to internal security-product boundaries.
Third, behavioral baselines should be established for sensitive user journeys and API operations. Login, registration, search, checkout, payment, account recovery, and data-access workflows require particular attention.
Fourth, bot policies should reflect business intent. Organizations need to decide which automated agents are trusted, which are conditionally permitted, and which should be challenged, restricted, or blocked.
Finally, security programs should examine activity over longer time horizons. Low-frequency attacks can remain active for weeks, accumulating risk while avoiding controls optimized for sudden spikes.
From Attack Volume to Operational Understanding
Large numbers attract attention, but the deeper lesson from 2025 lies in how attacks are being conducted.
They are persistent. They are automated. They frequently cross infrastructure and application layers. Many are designed to operate within patterns that appear technically legitimate.
For enterprise security teams, resilience will depend on the ability to combine scale with context. That means seeing how traffic behaves across networks, applications, APIs, identities, and time, then responding before suspicious activity becomes operational disruption.
The objective is not simply to block more requests.
It is to make better decisions about which requests pose risk, which activities support the business, and how protections should adapt as the distinction between them becomes harder to identify.
The figures in this article are drawn from the 2025 CDNetworks State of Web Application and API Protection Report and reflect traffic observed and mitigated by the CDNetworks security platform during 2025.