Quarterly Review · July 2026

DDoS Threat Landscape Report

Executive Summary

DDoS attacks now operate across multiple vectors simultaneously, and are increasingly powered by AI: not just to amplify volume, but to generate novel attack vectors, attempt to bypass defenses in real time, and mimic legitimate traffic with enough precision to defeat traditional detection.

Akamai’s 2026 Attack Trends in Financial Services report finds that the financial services industry remains the most targeted industry for DDoS, with attack duration up 738% globally and a 1,033% increase in EMEA alone. Banking bears the heaviest load within financial services: 60% of web attacks and 83% of API endpoint attacks that target the sector are hitting the banking industry.

Akamai’s data raises a number of key questions that do not get fully addressed. Where the report stops short, the analysis in this report reflects MazeBolt’s perspective and analysis. Some of the points covered include:

  • Validating DDoS defenses now requires simulation of AI-generated attacks. Akamai’s recommended approach to DDoS validation focuses on exercises and stress tests against known attack patterns. But if attackers use AI to find new paths through your environment, testing against known patterns won’t find them.
  • AI changes what attacks can do, not just how fast they run. Attacks are flexible and adapt to mitigation strategies. An AI-driven attack will find and exploit a misconfiguration that conventional defenses may miss entirely.
  • Having DDoS protection and knowing it works are not the same thing. Akamai identifies validation as a requirement for DDoS protection to function optimally. But configuration drift means that if a protection is validated using traditional periodic point-in-time testing, it will quickly become outdated.
  • Akamai’s discussion of the API visibility gap is part of the DDoS visibility gap. APIs are part of the DDoS attack surface, and 65% of API security incidents stem from misconfigurations, not sophisticated attacks. An endpoint that has never been validated for DDoS is exactly the exposure that multi-vector campaigns are built to find.
  • The 738% increase in attack duration creates problems with validation. Persistent, multi-day attacks find misconfigurations that point-in-time DDoS pen testing never surfaces.
  • Multi-vector campaigns expose the limits of single-surface testing. Today’s attacks combine HTTP floods, DNS amplification, and protocol exploits simultaneously. Testing one layer at a time says nothing about whether the full surface holds.

Akamai’s data points consistently toward a discrepancy the report identifies but does not address: having DDoS protection is not the same as knowing it works.

Validating AI Defenses Requires Simulating AI Attacks

Akamai’s threat analysis of AI’s role in DDoS is specific:

  • AI used by botnets to mimic legitimate browser behavior “with near-perfect accuracy to defeat traditional defenses,” evading detection at scale
  • AI-empowered operators that dynamically pivot to transparent browser impersonation, to bypass defenses when volumetric approaches fail
  • A “strategic move” from simple automation to agentic AI autonomy; malicious agents perform deep contextual analysis and adapt to mitigation strategies

The implication

What Akamai’s assessment doesn’t address is the fact that AI-generated attack vectors don’t follow known patterns. These attacks are engineered to bypass the rules, signatures, and thresholds that existing protections are built around.

Akamai’s validation steps are oriented toward known attacks: exercises and stress tests that validate what defenses do, against scenarios already in the testing library. None of this tells an organization whether its protections will hold against AI-generated vectors designed to circumvent exactly the defenses being validated.

If attackers can automatically identify and prioritize the most promising attack paths through your specific environment, validation that relies on known attack patterns will not find those paths. Testing against never-before-seen, AI-generated attack vectors is key to knowing if defenses will hold.

Today’s DDoS attacks can involve known attack vectors or AI-generated attack vectors, and they can be orchestrated either by human beings or by AI:

AI Amplifies Existing Risks

AI Amplifies Existing Risks

Akamai’s treatment of AI’s impact describes a fundamental shift from automation to agentic autonomy: AI doesn’t just execute attacks faster, but rather, it navigates complex applications, performs deep contextual analysis, and makes decisions independently.

Akamai reports that AI is being used to:

  • Empower botnets that mimic legitimate browser behavior with near-perfect accuracy
  • Generate functional exploits upon vulnerability disclosure
  • Harvest proprietary data at massive scale; in one observed case, hitting close to 7,000 hostnames and 37,000 unique paths in less than 7 days

Akamai describes AI enabling real-time adaptation to mitigation strategies mid-attack. On the defensive side, the report notes that AI-assisted development (referred to as “vibe coding”) is accelerating shadow API sprawl, with development cycles shortening in ways that leave new endpoints undocumented and unreviewed.

The implication

An AI-driven attack can find and exploit a misconfiguration that a traditional attack would miss entirely. This means that DDoS defenses need to be validated not “just” against the conventional, known attack vectors running at higher speed, but also against the actual, new behaviors that AI-powered attacks enable.

Having Protection and Knowing It Works Are Not the Same

Akamai’s mitigation guidance identifies three requirements for making DDoS protection actually function:

  • Validating that capabilities are sufficient against current peak attacks
  • Conducting exercises to confirm notification and response processes work
  • Stress testing to verify systems are covered and capabilities are operational

These are not presented as optional enhancements to a service provider relationship. They are the conditions under which the service provider delivers protection.

The implication

There’s a discrepancy that the report identifies but does not close: frequency of validation. Stress testing and exercises are described as requirements. But configuration drift, infrastructure changes, new attack vectors, and multi-vector campaigns mean that a protection validated once is not a protection that remains valid.

Protections fail because they are incorrectly configured, only periodically validated, and have drifted since they were last tested.

Bottom line: The standard that the report sets requires continuous validation to meet. Point-in-time DDoS pen testing, which confirms coverage at a single moment, leaves the vulnerabilities that develop undetected.

A Question of Visibility

Akamai’s findings on API visibility reveal a problem that goes deeper than inventory management. Open banking integrations, AI system dependencies, and fintech partnerships are accelerating API sprawl to the point where, in mature markets, banks report portfolios so large that security teams cannot confirm how many active endpoints they have.

While 77% of financial services IT and security leaders report having a full API inventory, only 27% also know which of those APIs return sensitive data. The consequences are measurable: 96% of financial services respondents reported at least one API security incident in the past 12 months, the highest rate of any industry. Of those incidents, 65% were attributed to misconfigurations, not sophisticated attacks.

The API visibility gap Akamai documents is also a DDoS visibility gap. APIs are part of the DDoS attack surface, and an endpoint whose DDoS protection has never been validated is exactly the kind of exposure that persistent, multi-vector campaigns are built to find. A shadow API (an endpoint nobody is watching) is also an unvalidated DDoS target. A zombie API (an endpoint that should have been retired) is also a protection rule that is no longer aligned with the infrastructure it was built to defend.

The implication

The primary driver of failures across both API security and DDoS protection is the same: not novel attack techniques, but the inability to see whether protections are correctly configured and still valid. The problem most organizations need to resolve is not the sophistication of their protection. It is their visibility into whether that protection is working across the full attack surface, including the parts that have expanded, changed, or never been tested.

How DDoS Attack Duration Impacts Defense

The median DDoS attack duration increased 738% globally between 2024 and 2025. In EMEA, the most targeted region for financial services DDoS, the increase was 1,033%: from 3 minutes to 34 minutes.

Akamai attributes this shift to AI-powered methods, legacy system flaws, and rapid digital banking expansion. The report describes the underlying shift as a move from simple volumetric attacks to “persistent, sequential multi-vector, multi-surface, multi-day campaigns” that pivot among web, DNS, and infrastructure floods. DDoSaaS platforms and IoT botnets like Kimwolf, which controlled over 3 million compromised devices before its dismantling, provided the sustained capacity that makes these campaigns viable.

Akamai frames extended duration not as a byproduct of scale but as a structural feature of how attacks are now built: campaigns designed to sustain pressure, pivot through vectors, and stay active long enough to compound the damage.

The implication

Akamai’s list of causes points directly at configuration and coverage gaps: legacy system flaws and rapid digital expansion are not novel attack techniques; they are configuration and coverage gaps that attackers are now able to exploit for longer time periods. A misconfiguration that survives a 3-minute burst may not survive a 34-minute multi-vector campaign that keeps probing the same surface.

Akamai calls for “adaptive defense strategies.” Meeting that standard requires knowing what the current defense state actually is:

  • Which vectors are covered
  • Which protections have drifted
  • Which legacy exposures have never been validated

Organizations that have never tested their protections under sustained, multi-vector conditions are relying on coverage that has never been proven at the durations now routinely sustained.

Multi-Vector Attacks and Coverage Gaps

Akamai documents DDoS campaigns that are simultaneously volumetric and application-layer:

  • Combining HTTP floods and DNS amplification in coordinated waves
  • Exploiting protocol edge cases like HTTP/2 vulnerabilities alongside infrastructure floods
  • Running as persistent, multi-surface, multi-day operations

Specific hacktivist groups targeted financial APIs and login portals at the same time, and others used DDoS as a smoke screen for more destructive parallel operations. The attack surface spans web applications, API endpoints, DNS infrastructure, and AI model infrastructure, each with its own distinct vulnerability profile.

The implication

Point-in-time DDoS pen testing cannot address this, in two ways. First, coverage: a test conducted against one layer at a single point in time says nothing about whether protections across the full surface are correctly configured. Real attacks don’t respect that boundary. Second, even full-surface testing has a shelf life.

Drill Down into Top Attacks in Q2 2026

The attacks documented in Akamaiˇs report are not theoretical. The following incidents, reported publicly during Q2 2026, illustrate some of the patterns that Akamai’s data describes:

  • Multi-vector campaigns
  • API-targeted disruption
  • DDoS used as a smoke screen for deeper operations
  • Low-and-slow traffic distributed across millions of IPs to evade threshold-based detection

In each case, the question is not whether the attack was sophisticated – it is whether the targeted organization’s defenses were validated against the method used.

The top attacks in Q2 are described here:

Add Your Heading Text Here

About MazeBolt

MazeBolt RADAR™ the only secure and on-demand DDoS testing solution that provides full visibility into your live network’s DDoS vulnerabilities across every attack point without requiring downtime. The patented RADAR solution allows global enterprises, for the first time, to reliably remediate DDoS vulnerabilities that lead to damaging downtime.

RADAR provides unparalleled visibility into defense configurations, empowering organizations to prevent attacks entirely and maintain uninterrupted business continuity.