DDoS Attackers Increase Targeting of Global Financial Sector, According to FS-ISAC and Akamai Report

In This Article:

Financial sector is the top industry for volumetric DDoS attacks; sophisticated, precision-targeted threats are growing

RESTON, Va., June 10, 2025 /PRNewswire/ -- FS-ISAC, the member-driven, not-for-profit organization that advances cybersecurity and resilience in the global financial system, and Akamai Technologies, Inc. (NASDAQ: AKAM), the cybersecurity and cloud computing company that powers and protects business online, today released their joint annual report analyzing the strategic threat posed by the escalating number and sophistication of distributed denial-of-service (DDoS) attacks and their impact on customer trust, operations, and profitability in the financial services sector.

Akamai Technologies, Inc. logo (PRNewsfoto/Akamai Technologies, Inc.)
Akamai Technologies, Inc. logo (PRNewsfoto/Akamai Technologies, Inc.)

The report, From Nuisance to Strategic Threat: DDoS Attacks Against the Financial Sector found that in 2024, the financial services sector was the top target of volumetric DDoS attacks, which aim to overwhelm the target with sheer traffic. DDoS attacks on financial firms' application programming interfaces (APIs) and customer-facing websites are on the rise as well. These precision-targeted attacks are difficult to detect because they mimic legitimate user behavior, which indicates a new level of skill among cybercriminals.

The joint report details attack data by region, with profiles of the sector's most prolific attackers. It also provides a DDoS Maturity Model that financial firms can leverage to evaluate their current capabilities and practices to prepare for DDoS attacks, as well as fundamental cyber practices for managing DDoS threats.

"DDoS attacks are becoming increasingly sophisticated, evolving from simple network flooding to targeted, multidimensional assaults that exploit intricate vulnerabilities across the entire supply chain," said Teresa Walsh, FS-ISAC's Chief Intelligence Officer and Managing Director, EMEA. "As threat tactics continue to evolve, we must ensure our technical defenses evolve and our people, tools, and processes work seamlessly together. It is critical that we harden our infrastructure, and foster a culture of continuous vigilance and collaboration, to protect continuity and customer trust."

Key findings highlight the shifting dynamics of DDoS threats — from the increasing use of DDoS-for-hire services to regional surges in activity — underscoring the urgent need for advanced, adaptive defense strategies. Highlights of the report include:

  • DDoS attacks on the financial sector have increased disproportionately compared to other industries. The sector remained the leading target for volumetric DDoS attacks year over year, with a major spike in October 2024.

  • DDoS attacks are increasing in frequency, and cybercriminals are exploiting today's high bandwidths and greater computational resources to launch more adaptable, powerful, and cost-effective DDoS attacks.

  • Application-layer DDoS attacks against the financial sector increased 23% between 2023 and 2024. The adoption of APIs in financial services has expanded the sector's threat surface, and malicious actors have evolved their tactics in response.

  • The widespread use of DDoS-for-hire services targeting the financial sector disguises attackers, making it difficult to identify the cybercriminal's motivation and develop mitigation plans.

  • Ongoing geopolitical tensions, particularly the Israel-Hamas and Russia-Ukraine wars, have fueled a surge in hacktivism.

  • DDoS attacks on the financial services sector increased significantly in the Asia-Pacific region, accounting for 38% of all volumetric DDoS attacks, up from 11% in 2023.