Cloudflare Blocks 7.3 Tbps DDoS Attack
- A hosting provider was targeted by a massive distributed denial of service (DDoS) attack in May 2025, peaking at 7.3 Tbps, according to Cloudflare.
- The DDoS assault, 12% larger than the previous record, delivered 37.4 TB of data in just 45 seconds.
- Cloudflare's 'Magic Transit' service, designed for network-layer protection, was employed by the targeted customer.
Cloudflare stopped a colossal 7.3 Tbps
Record-Breaking DDoS Attack Reaches 7.3 Tbps, Cloudflare Mitigates
A hosting provider was targeted by a massive distributed denial of service (DDoS) attack in May 2025, peaking at 7.3 Tbps, according to Cloudflare. The cybersecurity firm successfully mitigated the DDoS attack, which aimed to overwhelm servers and disrupt services.
The DDoS assault, 12% larger than the previous record, delivered 37.4 TB of data in just 45 seconds. This volume equates to approximately 7,500 hours of HD video streaming or 12.5 million JPEG images.

Source: Cloudflare
Cloudflare’s ‘Magic Transit‘ service, designed for network-layer protection, was employed by the targeted customer. The attack originated from 122,145 IP addresses spanning 161 countries, with significant concentrations in Brazil, Vietnam, Taiwan, China, Indonesia, and Ukraine.
Attackers used “garbage” data packets across numerous destination ports, averaging 21,925 ports per second and peaking at 34,517 ports per second. This tactic aims to overwhelm firewalls and intrusion detection systems. Cloudflare reported that it mitigated the DDoS attack without manual intervention.

Source: Cloudflare
Cloudflare’s anycast network, distributed across 477 data centers in 293 locations, dispersed the attack traffic. The network uses real-time fingerprinting and intra-data center gossiping for intelligence sharing and automated rule creation.
While UDP floods accounted for nearly all (99.996%) of the attack volume, other vectors were also present. These included QOTD reflection, Echo reflection, NTP amplification, Mirai botnet UDP flood, Portmap flood, and RIPv1 amplification. these vectors exploited legacy or misconfigured services,perhaps probing for weaknesses.
Cloudflare included indicators of compromise (iocs) from this attack in its DDoS Botnet Threat Feed. This free service helps organizations proactively block malicious IP addresses.Cloudflare encourages organizations at risk of DDoS attacks to subscribe to the feed.
What’s next
As DDoS attacks continue to evolve in scale and complexity, proactive measures like threat feeds and robust network protection services will be crucial for organizations to defend against these threats.
