{"id":8229,"date":"2021-01-21T09:20:36","date_gmt":"2021-01-21T09:20:36","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-2752\/"},"modified":"2026-04-10T08:23:16","modified_gmt":"2026-04-10T08:23:16","slug":"ddos-attacks-surpass-10-million-mark-for-the-first-time-in-2020","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2021\/01\/21\/ddos-attacks-surpass-10-million-mark-for-the-first-time-in-2020\/","title":{"rendered":"DDoS Attacks Surpass 10-Million Mark for the First Time in 2020"},"content":{"rendered":"<p><strong>For the first time since the dawn of the internet, the annual number of DDoS attacks has exceeded 10 million. Germany was the target of the largest EMEA-region attack.<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>The<br \/>\n<a title=\"https:\/\/u7061146.ct.sendgrid.net\/ls\/click?upn=4tNED-2FM8iDZJQyQ53jATUU7OzYmApYmFV-2Fpvbq3-2B3Ta-2BsAZaBSwf6dO7XAVo2t-2BNv_Ax_a-2BWxTQtMOYT-2Bt8Ki1f8mYP9Rpipad5nchaGtlijovl5-2FfTV9564kWHRNu4JmwWUXM7eRwb-2BHZBnjobHdH6-2BFXMlg89Yx6TDriLKSjgwNnDX8CCmJfj-2FZ25\" href=\"https:\/\/u7061146.ct.sendgrid.net\/ls\/click?upn=4tNED-2FM8iDZJQyQ53jATUU7OzYmApYmFV-2Fpvbq3-2B3Ta-2BsAZaBSwf6dO7XAVo2t-2BNv_Ax_a-2BWxTQtMOYT-2Bt8Ki1f8mYP9Rpipad5nchaGtlijovl5-2FfTV9564kWHRNu4JmwWUXM7eRwb-2BHZBnjobHdH6-2BFXMlg89Yx6TDriLKSjgwNnDX8CCmJfj-2FZ25D4yYwxgIrTYRN-2FnrKJ7K1jgkbaw9e-2F8c0u7gouYyGR5gAb9h51QksnErUHjw3SVJWQoC-2FjC5hczQKIuabtfr-2FwQGZsi-2B4SF4QDBfUr6y0bl92JWYaXN9AWQzaYmMFyzrYRdaQUrk5zztKRtSj1c2uc-2FxcnWy2Je9zhuj0e9uN1tfl0dAOYVhTg7twJHlzJ82jAQTzruw5Ci2Etup5OZZObArdvkbyjQfdcjkW4Pxx9PQwpp-2BQiV0U-3D\">ATLAS Security Engineering and Response Team (ASERT) of NETSCOUT<\/a><br \/>\nrecorded 10,089,687 Distributed-Denial-of-Service (DDoS) attacks in 2020  &#8211;  nearly 1.6 million more than the 8.5 million attacks observed in 2019. In Germany alone, 445,000 DDoS attacks were recorded last year, up from 162,000 in 2019. This included the largest EMEA-region attack ever observed, peaking at 586 Gbps.<\/p>\n<p>Network services provider NETSCOUT has now distilled the most critical insights.<\/p>\n<div id=\"attachment_2753\" style=\"width: 212px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-2753\" class=\"wp-image-2753\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/01\/securitytoday-DDoS-2020-700x933.jpg\" alt=\"securitytoday-DDoS-2020\" width=\"202\" height=\"269\" srcset=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/01\/securitytoday-DDoS-2020-700x933.jpg 700w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/01\/securitytoday-DDoS-2020-250x333.jpg 250w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/01\/securitytoday-DDoS-2020.jpg 768w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/01\/securitytoday-DDoS-2020-120x160.jpg 120w\" sizes=\"auto, (max-width: 202px) 100vw, 202px\" \/><p id=\"caption-attachment-2753\" class=\"wp-caption-text\">DDoS attacks surged globally during the first lockdown in early March, according to the report. Source: iStock \/ Anastasiia_New<\/p><\/div>\n<p><strong>Remote Work Environments &amp; Lockdowns: A Cybercriminal\u2019s Paradise<\/strong><\/p>\n<p>Cybercriminals exploited the shift from corporate networks  &#8211;  protected by enterprise-grade firewalls  &#8211;  to home-office setups secured only by consumer-grade networking devices. By more than doubling the number of readily available IoT-specific malware samples, attackers dramatically accelerated the pace of DDoS activity.<\/p>\n<p>Monthly DDoS attacks consistently surpassed 800,000 starting with the March 2020 lockdown. May saw the highest volume, with <a href=\"https:\/\/u7061146.ct.sendgrid.net\/ls\/click?upn=4tNED-2FM8iDZJQyQ53jATUU7OzYmApYmFV-2Fpvbq3-2B3TZxY-2BrVdVxe81VCfrtd-2FN8K1E1G_a-2BWxTQtMOYT-2Bt8Ki1f8mYP9Rpipad5nchaGtlijovl5-2FfTV9564kWHRNu4JmwWUXM7eRwb-2BHZBnjobHdH6-2BFXMlg89Yx6TDriLKSjgwNnDX8CCmJfj-2FZ25D4yYwxgIrTYRN-2FnrKJ7K1jgkbaw9e-2F8c0u7gouYyGR5gAb9h51QksnErUHjw3SVJWQoC-2FjC5hczQKIuabtfr-2FwQGZsi-2B4SF1QQJV-2BxTPEhmg6lE4gKYGKYeqGqtHazm4fkLWLEcwNL9a5-2BO-2F6ykNCivs3-2BJraLF7B0TvGKM11S0xeY9DsYhv6VfQsjzHPppxZ6b2qPtBoR9SiI7KG0YtKAuTJ5aJTvYQnQsZXurzSRBFEzQrCEA2Q-3D\">929,000 DDoS attacks<\/a>. Cable and wireless broadband providers bore the brunt of these attacks. Other top targets included critical infrastructure sectors such as e-commerce, online learning, and healthcare.<\/p>\n<p><strong>Financial Services &amp; Healthcare Under Siege<\/strong><\/p>\n<p>In mid-August, the threat actor Lazarus Bear Armada (LBA) launched a global, ongoing campaign of DDoS extortion attacks. According to ASERT, the campaign persists because victims failed to pay the original ransom demand. While LBA initially targeted financial services, cybercriminals quickly expanded their focus to major healthcare organizations  &#8211;  including firms involved in COVID-19 testing and vaccine development.<\/p>\n<p>As the COVID-19 pandemic extends into 2021, threat actors will inevitably identify and exploit new attack vectors targeting vulnerabilities exposed by the global crisis. It is essential to continuously reassess the status quo of deployed security solutions  &#8211;  and adapt them proactively to evolving threats.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2>Key Facts<\/h2>\n<p><strong>Damage Volume:<\/strong> Cybercrime causes over \u20ac8 trillion in global damages annually.<\/p>\n<p><strong>Skills Shortage:<\/strong> More than 3.5 million cybersecurity professionals are missing worldwide.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>What are the most common cyber threats facing businesses?<\/h3>\n<p>According to the BSI (Federal Office for Information Security) Situation Report, ransomware, phishing, DDoS attacks, and supply-chain compromises rank among the most frequent threats. German companies face additional regulatory risks  &#8211;  including GDPR and the upcoming NIS2 Directive.<\/p>\n<h3>How much should a company invest in cybersecurity?<\/h3>\n<p>Industry experts recommend allocating 10 to 15 percent of the IT budget to cybersecurity. According to Bitkom, German companies average 14 percent. Crucially, it\u2019s not just the amount  &#8211;  but the strategic distribution across prevention, detection, and response  &#8211;  that matters.<\/p>\n<h3>Does every company need a CISO?<\/h3>\n<p>Not every organization requires a full-time Chief Information Security Officer  &#8211;  but every company must assign clear, board-level accountability for IT security. SMEs can leverage external or virtual CISOs (vCISOs). With NIS2, management accountability for cybersecurity becomes legally mandated.<\/p>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2021\/01\/25\/post_id-2629\/\">Home Office Security Gap: On the Trail of Cybercriminals<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/05\/post_id-3821\/\">secIT by Heise 2026: The Security Roadshow for Admins and IT Decision-Makers<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/05\/post_id-3819\/\">DsiN Annual Conference 2026: Digital Security in a Connected Society<\/a><\/li>\n<\/ul>\n<h3>More from the MBF Media Network<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.mybusinessfuture.com\" target=\"_blank\" rel=\"noopener\">More IT security trends at mybusinessfuture.com<\/a><\/li>\n<li><a href=\"https:\/\/www.cloudmagazin.com\" target=\"_blank\" rel=\"noopener\">Cloud &amp; infrastructure news at cloudmagazin.com<\/a><\/li>\n<\/ul>\n<p style=\"text-align: right;\"><em>Header Image Source: Adobe Stock \/\u00a0<\/em><span class=\"blue bleu-de-france-text\" data-t=\"detail-panel-content-author-name\"><a class=\"blue bleu-de-france-text\" href=\"https:\/\/stock.adobe.com\/de\/contributor\/204993612\/profit-image?load_type=author&amp;prev_url=detail\" target=\"_blank\" rel=\"noopener\">profit_image<\/a><\/span><\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li>For the first time since the internet\u2019s inception, the annual number of DDoS attacks has surpassed the 10-million mark.<\/li>\n<li> According to the report, DDoS attacks surged globally during the first lockdown in early March.<\/li>\n<li>While the LBA campaign initially targeted financial services, the responsible cybercriminals soon broadened their focus to major healthcare enterprises  &#8211;  including firms involved in\u2026<\/li>\n<li>The ATLAS Security Engineering and Response Team (ASERT) of NETSCOUT recorded 10,089,687 Distributed-Denial-of-Service (DDoS) attacks in 2020.<\/li>\n<\/ul>\n<p style=\"text-align: right;\">\n<p><strong>Fact:<\/strong> According to Mandiant, the average attacker dwell time inside a compromised network is 10 days.<\/p>\n<p><strong>Fact:<\/strong> Per the Allianz Risk Barometer 2025, cyberattacks are the top business risk worldwide.<\/p><\/p>\n","protected":false},"excerpt":{"rendered":"For the first time since the dawn of the internet, the annual number of DDoS attacks has exceeded 10 million. Germany was the target of the largest EMEA-region attack. &nbsp; The ATLAS Security Engineering and Response Team (ASERT) of NETSCOUT recorded 10,089,687 Distributed-Denial-of-Service (DDoS) attacks in 2020 &#8211; nearly 1.6 million more than the 8.5 [&hellip;]","protected":false},"author":55,"featured_media":2756,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"ddos attacks","_yoast_wpseo_title":"","_yoast_wpseo_metadesc":"DDoS attacks exceed 10 million in 2020\u2014discover how to protect your network from record-breaking threats. Learn more now.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":"","_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":"","footnotes":""},"categories":[251],"tags":[],"class_list":["post-8229","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"wpml_language":"en","wpml_translation_of":2752,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8229","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=8229"}],"version-history":[{"count":3,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8229\/revisions"}],"predecessor-version":[{"id":10415,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8229\/revisions\/10415"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/2756"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=8229"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=8229"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=8229"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}