DDoS Threat Landscape Report

MazeBolt’s Take on Akamai’s DDoS Report

DDoS attacks are running longer, hitting more vectors simultaneously, and increasingly powered by AI, according to Akamai’s research 

MazeBolt’s latest DDoS Threat Landscape Report breaks down what that means for organizations that think their defenses are covered. Here are some of the report’s insights: 

How DDoS Attack Vectors are Changing 

The median DDoS attack duration increased 738% globally between 2024 and 2025. In EMEA, the figure was 1,033%: attacks that once lasted three minutes now run for over half an hour.  

The reason is not just more powerful infrastructure. Attacks have evolved into persistent, multi-vector campaigns that pivot between HTTP floods, DNS amplification, and protocol exploits, sometimes staying active long enough to find and exploit configuration gaps that a shorter attack would never surface. 

AI is a significant factor. Botnets now mimic legitimate browser behavior with enough precision to defeat traditional detection. Attacks adapt to mitigation strategies mid-execution. AI-generated attack vectors follow no known pattern, which means testing against a library of known attack signatures does not tell you whether your defenses will hold against what is actually being used. 

Deployed DDoS Protection Is Not the Same as Proving It Works 

Akamai identifies validation as a core requirement for DDoS protection to function, not an optional enhancement. But the report stops short of addressing the frequency problem. Configuration drift, infrastructure changes, and new attack vectors mean that a protection validated periodically (rather than continuously) is not a protection that remains valid. 

The gap between having a defense and knowing it works is where most organizations are exposed. MazeBolt’s own research data shows that CISOs are testing less than 1% of their attack surface. A misconfiguration that survives a three-minute burst may not survive a 34-minute multi-vector campaign built to keep probing the same surface. 

The API Visibility Gap Is Also a DDoS Visibility Gap 

Akamai reports that 65% of API security incidents in financial services stem from misconfigurations, not sophisticated techniques. Of financial services organizations, 96% reported at least one API security incident in the past 12 months. An undocumented or unreviewed API endpoint is also an unvalidated DDoS target, and persistent multi-vector campaigns are built to find exactly those gaps. 

What DDoS Attacks Reported in the News Have Confirmed 

The quarterly incident data across AprilMay, and June 2026 illustrates these patterns in practice: API-targeted attacks on social platforms, DDoS used as a smoke screen in a $290 million crypto exploit, low-and-slow traffic distributed across 1.2 million IP addresses to evade threshold detection, and sustained campaigns against civic and public safety infrastructure. 

In each case, the question is not whether the attack was sophisticated. It is whether the targeted organization’s defenses had ever been validated against the method used. 

Continuous DDoS validation across the full attack surface is the only way to close that gap. To learn more, read the full DDoS Threat Landscape Report – June 2026. 

Key Takeaways from Recent DDoS Attacks 

  • DDoS attacks are longer, multi-vector, and increasingly AI-powered 
  • Having protection and knowing it works are not the same thing 
  • Most organizations are testing less than 1% of their attack surface 
  • Configuration drift means validated defenses go stale fast 
  • Continuous DDoS validation across the full attack surface is the only way to close the gap 

Frequently Asked Questions About Akamai’s DDoS Report

AI-powered methods, legacy system vulnerabilities, and rapid digital expansion have enabled attackers to run persistent, multi-vector campaigns that stay active long enough to find and exploit configuration gaps.

Point-in-time testing confirms coverage at a single moment but cannot account for configuration drift, new attack vectors, or the multi-surface campaigns that characterize attacks today.

An unvalidated API endpoint is also an unvalidated DDoS target, and 65% of API security incidents in financial services stem from misconfigurations rather than sophisticated attacks.

Financial services remains the most targeted sector, with banking absorbing 60% of web attacks and 83% of API endpoint attacks directed at the industry.

It means running nondisruptive simulations across the full attack surface on an ongoing basis, so configuration gaps and coverage drift are identified before attackers find them.

Stay Updated.
Get our Newsletter*

Recent posts