Dataset
Public DDoS threat reports
Who publishes recurring DDoS threat data, what each one can actually see, and the methodology caveat that comes with it. Headline figures are deliberately not reproduced.
- Rows
- 5
- Last updated
- 2026-08-15
- Schema version
- 1.0
Public DDoS threat reports
| Publisher | Report | Cadence | Observation scope | Methodology caveat | Source |
|---|---|---|---|---|---|
| Cloudflare | Quarterly DDoS Threat Report | quarterly | Traffic across Cloudflare’s own network and customer base | Weighted towards web-facing properties that use Cloudflare. A change in the series can reflect a change in who bought the service rather than a change in the threat. | blog.cloudflare.com/tag/ddos-reports |
| NETSCOUT | DDoS Threat Intelligence Report | semi-annual | Service-provider telemetry visible to NETSCOUT’s ATLAS infrastructure | Carrier-weighted rather than web-weighted, which makes it strong on volumetric and network-layer trends and a different sample from a CDN-derived report. | netscout.com/threatreport |
| Google Cloud | Incident and record disclosures | event-driven | Attacks against Google Cloud customers and infrastructure | Published when a record or notable incident occurs rather than on a schedule, so absence of a post is not evidence of a quiet period. | cloud.google.com/blog/products/identity-security |
| CISA | Alerts and advisories | event-driven | US critical-infrastructure reporting and coordinated disclosures | Advisory rather than statistical: strong for mechanism and mitigation guidance, not a measurement of attack volume. | cisa.gov/news-events/cybersecurity-advisories |
| ENISA | ENISA Threat Landscape | annual | European incident reporting and open-source analysis | Synthesises other people’s reporting rather than measuring traffic directly, so it inherits the sampling biases of its inputs — which it generally states. | enisa.europa.eu/topics/cyber-threats/threat-landscape |
Sources
- Cloudflare DDoS report archive
Cloudflare · accessed 2026-08-15
Verified as the index of the quarterly series; latest edition read for this release was 2025 Q4, published 5 February 2026.
- NETSCOUT DDoS Threat Intelligence Report
NETSCOUT · accessed 2026-08-15
- ENISA Threat Landscape
ENISA · accessed 2026-08-15
What changed
- 2026-08-15Initial release: five recurring publishers, scope and caveat recorded rather than headline metrics.
Reuse: Free to reuse with attribution to ddosmitigationguide.com; source citations must be preserved.