Executive Summary
In early 2025, a wave of Distributed Denial-of-Service (DDoS) attacks targeting the technology sector marked a significant shift in cyberattack patterns, according to Gcore's Q1–Q2 2025 Radar report. Attack volumes surged by 41% year-on-year, with the largest observed DDoS flood peaking at 2.2 Tbps—surpassing previous records set in 2024. Threat actors employed multi-layered strategies and protracted campaigns, specifically targeting technology companies with sophisticated, high-bandwidth assaults that caused operational disruptions, service outages, and reputational harm across multiple organizations. This evolution reflects attackers’ growing technical prowess and focus on critical service providers.
The incident is particularly relevant as the threat landscape pivots towards the tech sector and away from previous gaming-centric targets. This trend underscores broader risks for infrastructure providers and the need for adaptive DDoS defenses in the face of escalating attack complexity and regulatory expectations.
Why This Matters Now
This surge in tech-focused DDoS attacks highlights a critical and urgent risk shift: sophisticated attackers are now prioritizing technology infrastructure, putting core digital services and supply chains at increased risk of severe business disruption and regulatory non-compliance.
Attack Path Analysis
Attackers initiated a large-scale DDoS campaign by exploiting exposed cloud application surfaces or weak perimeter controls (Initial Compromise). They attempted to maximize the effect by leveraging misconfigured or over-permissive service roles, aiming to abuse privileged network paths or amplify the attack's scale (Privilege Escalation). Lateral Movement was conducted through east-west traffic flows within cloud and multi-cloud environments to broaden the disruption. For Command & Control, attackers coordinated the attack using covert or distributed communications to maintain traffic flow and control botnets or attack sources. There was limited exfiltration, but attempts may have included data siphoning amidst the noise (Exfiltration). Ultimately, the primary impact was service degradation, loss of availability, and potential collateral damage to interdependent services (Impact).
Kill Chain Progression
Initial Compromise
Description
Attackers targeted exposed or poorly protected cloud infrastructure endpoints, launching volumetric DDoS traffic to overwhelm gateways and services.
Related CVEs
CVE-2025-59718
CVSS 9.8An authentication bypass vulnerability in Fortinet products allows unauthenticated remote attackers to gain administrative access via crafted SAML messages.
Affected Products:
Fortinet FortiOS – 7.0.0 to 7.0.12, 7.2.0 to 7.2.5
Fortinet FortiProxy – 7.0.0 to 7.0.12, 7.2.0 to 7.2.5
Fortinet FortiSwitchManager – 7.2.0 to 7.2.2
Exploit Status:
exploited in the wildCVE-2025-59719
CVSS 9.8An authentication bypass vulnerability in Fortinet's FortiWeb allows unauthenticated remote attackers to gain administrative access via crafted SAML messages.
Affected Products:
Fortinet FortiWeb – 6.3.0 to 6.3.19, 6.4.0 to 6.4.2, 7.0.0 to 7.0.1
Exploit Status:
exploited in the wildCVE-2025-53770
CVSS 9.8A critical vulnerability in Microsoft SharePoint allows remote code execution via specially crafted requests.
Affected Products:
Microsoft SharePoint Server – 2019, Subscription Edition
Exploit Status:
exploited in the wildCVE-2025-53771
CVSS 9.8A critical vulnerability in Microsoft SharePoint allows remote code execution via specially crafted requests.
Affected Products:
Microsoft SharePoint Server – 2019, Subscription Edition
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Endpoint Denial of Service
Network Denial of Service
Acquire Infrastructure: Web Services
Compromise Infrastructure: Botnets
Phishing
Application Layer Protocol: Web Protocols
Data Encoding
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Incident Response Plan
Control ID: 12.10.1
NYDFS 23 NYCRR 500 – Business Continuity and Disaster Recovery
Control ID: 500.16
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Ensure Availability of Business-Critical Services
Control ID: EN-4
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Primary DDoS target with 41% attack volume increase, requiring enhanced egress security, threat detection capabilities, and zero trust segmentation for critical infrastructure protection.
Computer Games
Previously top DDoS target now second-most attacked sector, needing robust multicloud visibility, anomaly response systems, and inline IPS protection against sophisticated attacks.
Telecommunications
Critical infrastructure vulnerable to 2.2 Tbps-scale attacks, requiring encrypted traffic capabilities, east-west security controls, and secure hybrid connectivity for service continuity.
Financial Services
High-value target for multi-layered DDoS attacks demanding comprehensive threat detection, cloud firewall protection, and compliance with PCI/NIST security frameworks.
Sources
- Tech Overtakes Gaming as Top DDoS Attack Target, New Gcore Radar Report Findshttps://thehackernews.com/2025/09/tech-overtakes-gaming-as-top-ddos.htmlVerified
- Gcore Radar report reveals 41% surge in DDoS attack volumeshttps://gcore.com/press-releases/gcore-radar-ddos-attack-trends-q1-q2-2025Verified
- Two Fortinet vulnerabilities are being exploited in the wild - patch nowhttps://www.itpro.com/security/two-fortinet-vulnerabilities-are-being-exploited-in-the-wild-patch-nowVerified
- We're witnessing an urgent and active threat - Microsoft SharePoint 'ToolShell' vulnerability is being attacked globallyhttps://www.windowscentral.com/software-apps/were-witnessing-an-urgent-and-active-threat-microsoft-sharepoint-toolshell-vulnerability-is-being-attacked-globallyVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
CNSF controls such as Zero Trust Segmentation, east-west traffic security, egress enforcement, and centralized multicloud visibility would have limited the DDoS attack's spread, isolated critical workloads, and enabled faster detection and response, thus minimizing operational impact.
Control: Cloud Firewall (ACF)
Mitigation: Inbound attacks are blocked at the perimeter, reducing initial exploitation risk.
Control: Zero Trust Segmentation
Mitigation: Strict segmentation prevents attackers from leveraging elevated permissions or accessing additional network segments.
Control: East-West Traffic Security
Mitigation: Lateral attack spread is contained and anomalous movement is quickly identified.
Control: Threat Detection & Anomaly Response
Mitigation: Suspicious command channels or botnet behaviors are detected and disrupted in real time.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorized data flows to external endpoints are blocked or flagged.
Operators gain immediate insight into attack scope and impacted assets, enabling swift response and containment.
Impact at a Glance
Affected Business Functions
- Online Services
- Customer Support
- Internal Communications
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive customer data due to prolonged service outages and possible unauthorized access during DDoS attacks.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce cloud-native perimeter controls and cloud firewalling to block external DDoS attempts.
- • Implement zero trust segmentation across workloads and applications to constrain attack amplification and lateral spread.
- • Monitor east-west and multicloud traffic with centralized visibility for early detection of abnormal flows.
- • Apply strict egress filtering and outbound policy enforcement to stop unauthorized exfiltration.
- • Leverage real-time threat detection and anomaly response to rapidly identify and disrupt botnet coordination and attack activities.



