BLOG

DDoS attack examples: The biggest Distributed Denial of Service Attacks in history

Jun 6, 2026

Cyber attacks are not just theoretical, some of the biggest DDoS attack examples in history show how quickly a website or service can be knocked offline when attackers coordinate massive traffic from botnets. If you run a SaaS platform, ecommerce store, or even a content site, you need to know what these attacks look like, what they cost, and what you can do to reduce the fallout.

This post breaks down the biggest distributed denial of service attacks, why they happened, and what practical steps you can take to improve resilience through layered technical controls and better user behaviour, including cyber security awareness training and phishing simulations.

Key takeaways

  • DDoS attacks can peak at multi-terabit scale.
  • Even global brands and infrastructure providers have been hit.
  • Attackers commonly use botnets and amplification techniques.
  • Your best defence is layered: infrastructure, monitoring, and people.
  • Awareness training and phishing simulations support resilience by reducing the human attack surface.
Biggest DDoS attacks ever

The biggest DDoS attacks in history (quick summary)

YearTargetPeak sizeNotable method
2016Dyn (DNS provider)Massive botnetMirai IoT botnet
2018GitHub1.35 TbpsMemcached amplification
2020AWS customer2.3 TbpsCLDAP reflection
2022+Multiple25+ million rps (HTTP)Layer 7 floods

Why DDoS attack examples matter for businesses

When you see headlines about 1.35 Tbps or 2.3 Tbps attacks, it is easy to assume the problem is too big to matter to smaller organisations. The truth is, most businesses do not need a multi-terabit attack to suffer real damage. A sustained attack can create costly downtime, lost sales, SLA penalties, and brand damage.

More importantly, attackers increasingly mix tactics. A DDoS attack might be used as a distraction while criminals launch phishing campaigns or attempt lateral movement. That is why phishing simulations and continuous training matter, the technical side is not enough.

A timeline of major DDoS attack examples

Dyn DNS attack (2016)

The 2016 attack on Dyn disrupted access to major sites, including Twitter and Netflix, because it hit DNS infrastructure. It was fuelled by the Mirai botnet, which leveraged poorly secured IoT devices.

Why it matters today: IoT security is still inconsistent, and many organisations do not have visibility into what devices are connected to their networks.

GitHub DDoS attack (2018)

GitHub was hit by a peak 1.35 Tbps DDoS attack. The attackers used a memcached amplification technique, meaning they could send small requests that generated huge responses.

What you can learn: attackers are constantly evolving methods to maximise impact for minimal effort.

AWS 2.3 Tbps attack (2020)

Amazon reported mitigating a 2.3 Tbps attack against an AWS customer in 2020. It was one of the largest volumetric attacks publicly disclosed at the time.

Key lesson: cloud-hosted does not mean invulnerable. You still need to plan for incident response.

HTTP DDoS attacks (2022 and beyond)

Recent years have seen record-breaking HTTP DDoS attacks measured in tens of millions of requests per second, targeting APIs and web apps.

Why it is dangerous: these attacks can look like normal traffic, making them harder to detect.

What these attacks have in common

1. Botnets and compromised devices

Most major DDoS attacks rely on huge numbers of compromised devices. Attackers recruit IoT devices, outdated systems, and anything with weak credentials.

2. Amplification

Amplification attacks allow criminals to magnify their output. Techniques like memcached amplification make DDoS attacks far more potent.

3. Weak monitoring

Many organisations detect the problem only when customers complain or the site goes down.

How to reduce risk after seeing these DDoS examples

Build a layered defence

  1. Use a DDoS mitigation provider or CDN-based protection.
  2. Implement WAF rules and rate limiting.
  3. Monitor traffic patterns and set alert thresholds.
  4. Practice incident response runbooks.
  5. Strengthen user behaviour with cyber security awareness training.

Treat staff as part of your security perimeter

DDoS attacks often run alongside phishing and credential stuffing. When staff recognise suspicious emails, unusual login prompts, or account takeover attempts, incidents get contained faster.

This is where phishing simulations and ongoing training programmes play a crucial role.

Conclusion

DDoS attacks are getting bigger, but the business impact often comes down to preparation and response speed. By learning from major DDoS attack examples, you can harden your infrastructure, tighten monitoring, and reduce the risk that a bad actor can take down your services or distract your team while they attack elsewhere.

Bottom line: Combine technical controls with strong human security habits.

Ready to make your organisation more resilient?

Book a demo to see how our security awareness training and phishing simulations can support your cyber resilience strategy.

Latest insights

How to build an effective security awareness & training programme from scratch

Jul 3, 2026

How to build an effective security awareness & training programme from scratch

Jul 3, 2026

Security Awareness Training ROI: How to measure and prove the value to leadership

Phishing emails Boxphish

Jul 3, 2026

What is Business Email Compromise (BEC)? A complete 2026 guide for businesses

Ready to transform your cyber culture? Book a demo today!