{
  "schemaVersion": "1.0",
  "dataset": "ddos-threat-reports",
  "title": "Public DDoS threat reports",
  "description": "Who publishes recurring DDoS threat data, what each one can actually see, and the methodology caveat that comes with it. Headline figures are deliberately not reproduced.",
  "lastUpdated": "2026-08-15",
  "license": "Free to reuse with attribution to ddosmitigationguide.com; source citations must be preserved.",
  "sources": [
    {
      "id": "cf-reports",
      "title": "Cloudflare DDoS report archive",
      "publisher": "Cloudflare",
      "url": "https://blog.cloudflare.com/tag/ddos-reports/",
      "accessedDate": "2026-08-15",
      "notes": "Verified as the index of the quarterly series; latest edition read for this release was 2025 Q4, published 5 February 2026."
    },
    {
      "id": "netscout-report",
      "title": "NETSCOUT DDoS Threat Intelligence Report",
      "publisher": "NETSCOUT",
      "url": "https://www.netscout.com/threatreport",
      "accessedDate": "2026-08-15"
    },
    {
      "id": "enisa-tl",
      "title": "ENISA Threat Landscape",
      "publisher": "ENISA",
      "url": "https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape",
      "accessedDate": "2026-08-15"
    }
  ],
  "changelog": [
    {
      "date": "2026-08-15",
      "note": "Initial release: five recurring publishers, scope and caveat recorded rather than headline metrics."
    }
  ],
  "rowCount": 5,
  "data": [
    {
      "publisher": "Cloudflare",
      "report": "Quarterly DDoS Threat Report",
      "cadence": "quarterly",
      "observationScope": "Traffic across Cloudflare’s own network and customer base",
      "methodologyCaveat": "Weighted towards web-facing properties that use Cloudflare. A change in the series can reflect a change in who bought the service rather than a change in the threat.",
      "url": "https://blog.cloudflare.com/tag/ddos-reports/"
    },
    {
      "publisher": "NETSCOUT",
      "report": "DDoS Threat Intelligence Report",
      "cadence": "semi-annual",
      "observationScope": "Service-provider telemetry visible to NETSCOUT’s ATLAS infrastructure",
      "methodologyCaveat": "Carrier-weighted rather than web-weighted, which makes it strong on volumetric and network-layer trends and a different sample from a CDN-derived report.",
      "url": "https://www.netscout.com/threatreport"
    },
    {
      "publisher": "Google Cloud",
      "report": "Incident and record disclosures",
      "cadence": "event-driven",
      "observationScope": "Attacks against Google Cloud customers and infrastructure",
      "methodologyCaveat": "Published when a record or notable incident occurs rather than on a schedule, so absence of a post is not evidence of a quiet period.",
      "url": "https://cloud.google.com/blog/products/identity-security/"
    },
    {
      "publisher": "CISA",
      "report": "Alerts and advisories",
      "cadence": "event-driven",
      "observationScope": "US critical-infrastructure reporting and coordinated disclosures",
      "methodologyCaveat": "Advisory rather than statistical: strong for mechanism and mitigation guidance, not a measurement of attack volume.",
      "url": "https://www.cisa.gov/news-events/cybersecurity-advisories"
    },
    {
      "publisher": "ENISA",
      "report": "ENISA Threat Landscape",
      "cadence": "annual",
      "observationScope": "European incident reporting and open-source analysis",
      "methodologyCaveat": "Synthesises other people’s reporting rather than measuring traffic directly, so it inherits the sampling biases of its inputs — which it generally states.",
      "url": "https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape"
    }
  ]
}