A distributed denial-of-service (DDoS) attack is an attempt to make a website, app, game, or online service stop working. Attackers overwhelm it with more traffic or requests than it can handle, causing it to slow down, stop responding, or go offline. It’s like sending an enormous crowd through one entrance so genuine visitors can’t get in.
What does DDoS stand for?
DDoS stands for distributed denial-of-service. "Distributed" means the traffic comes from many devices instead of just one. Attackers often use a botnet, which is a network of infected computers and internet-connected devices they control remotely. Some attacks also trick open internet services into sending much more traffic to the target.
What are the main types of DDoS attacks?
The three main types of DDoS attacks target different parts of an online service. Volumetric attacks overwhelm the internet connection with massive amounts of traffic. Protocol attacks overload the systems that manage network connections. Application-layer attacks repeatedly target a specific part of a website or app, such as a login page, until it stops working. Most DDoS attacks are intended to disrupt a service rather than steal data, although attackers sometimes use the disruption to hide another attack or pressure the victim into paying a ransom.
The details vary, but the aim is always to use up something the service relies on, such as its internet connection or processing power, so genuine users can’t get through. Most DDoS attacks follow five broad stages.
01
A target is chosen
The attacker selects a website, online service, network, game server, or public-facing system. Motives may include extortion, protest, competition, revenge, or simply causing disruption.
02
The attacker gathers traffic
The attacker gathers traffic from many sources. This often comes from a botnet of infected devices, but some attacks also abuse internet services to generate extra traffic.
03
The attacker floods the target
The attacker sends huge numbers of requests or data packets to the target at the same time. Because the traffic comes from many sources, it’s harder to block.
04
The target becomes unavailable
The flood of traffic overwhelms the target's bandwidth, servers, or other resources. As a result, the service slows down, stops responding, or goes offline.
05
Defenders respond
The target’s provider or security team separates the attack traffic from genuine visits, blocks or redirects it, and restores the affected services. They then review what happened and improve their response plan.
What are some real-world DDoS attack examples?
DDoS attacks can disrupt one organization or affect many services that rely on the same internet provider. These examples show how attackers have used infected devices, open internet services, and extremely large floods of traffic.
2016
Dyn and Mirai
Thousands of internet-connected devices infected with Mirai malware flooded Dyn, a company that routed internet traffic for many major websites, with traffic. As a result, many users couldn't access websites including Twitter, Netflix, PayPal, and CNN. The attack showed how insecure internet-connected devices can be turned into a botnet capable of disrupting popular online services. Source: US Department of Justice
2017
Google
Google stopped a massive DDoS attack before it disrupted its services. The attackers abused about 180,000 exposed internet servers to send huge amounts of traffic toward Google. The attack showed why large online services use multiple layers of DDoS protection. Source: Google Cloud
2020
New Zealand Exchange
DDoS attacks disrupted the New Zealand Exchange (NZX) and forced it to halt trading while it addressed network connectivity problems. The incident showed that DDoS attacks can interrupt critical services even without stealing or changing data. Source: NZX
2025
Cloudflare customers
Cloudflare reported blocking a 31.4-terabit-per-second DDoS attack that lasted about 35 seconds. The company also reported a rise in large DDoS attacks during 2025. The incidents showed how quickly modern attacks can grow and why automated DDoS protection is essential. Source: Cloudflare
What are the risks and impacts of DDoS attacks?
A DDoS attack is meant to make a website or online service unavailable. Even after the attack ends, the disruption can continue while systems recover.
Service downtime
Websites, apps, payment systems, games, or business tools may become slow or unavailable. Customers and employees can’t use the service until traffic is filtered and systems recover.
Lost income and productivity
Online businesses may lose sales, bookings, advertising revenue, or paid service time. Employees may also be unable to reach the systems they need for everyday work.
Recovery costs
Organizations may need emergency support from hosting, network, and security providers. They may also spend time investigating the attack, restoring services, and improving capacity and monitoring.
Loss of trust
Service outages can frustrate customers and damage trust. Some attackers also use DDoS attacks to demand a ransom or distract defenders while another cyberattack takes place.
Who is most at risk from DDoS attacks?
Any public-facing service can be targeted, but those that rely on staying online at all times are most at risk.
Gaming communities
Game servers, streamers, esports teams, and individual players can be targeted to disrupt matches or force players offline, especially when a home IP address is exposed.
Small organizations
Smaller businesses, charities, and community sites often have fewer resources to defend against or recover from a DDoS attack.
Online businesses
Retailers, booking services, software platforms, and subscription businesses can lose customers and revenue whenever their websites, apps, or payment systems become unavailable.
Financial services
Banks, payment providers, trading platforms, and exchanges depend on reliable access. Even a temporary outage can interrupt transactions and undermine customer confidence.
Public services
Government websites, healthcare portals, utilities, schools, and transport services may be targeted because disruption affects many people and attracts public attention.
How can you prevent or stop a DDoS attack?
No single tool can stop every DDoS attack. The best protection combines DDoS filtering, monitoring, good preparation, and secure systems.
Use a DDoS protection service
Choose a hosting, cloud, or specialist DDoS protection provider that can block attack traffic before it reaches your website or server.
Monitor normal traffic
Track normal traffic levels and set alerts for sudden changes, repeated errors, and unusual activity. An early warning helps your provider recognize and block an attack faster.
Prepare a response plan
Know who to contact if an attack happens, including your hosting provider, internet provider, and security team. Keep important contact details easy to access.
Strengthen online services
Keep servers and website software updated, remove services you no longer use, and make sure essential parts of the service don’t all depend on a single system.
Secure connected devices
Change default passwords on routers and smart devices, install firmware updates, and replace unsupported equipment. Keep your Mac updated and scan suspicious downloads to reduce botnet malware risk. For broader guidance, see our Mac security guide.
How Intego helps keep your Mac out of known botnets
Intego ONE Antivirus can’t stop a DDoS attack against a website or server. Instead, it can detect and quarantine known malware that attackers could use to add your Mac to a botnet.
Real-time file scanning
Real-time protection checks files when they’re downloaded, opened, or accessed. It can quarantine known Mac malware before it establishes control or carries out further activity.
Manual and custom scans
Run a scan when a download, installer, or email attachment seems suspicious. Custom scans let you check a specific file or folder without scanning the whole Mac.
Scheduled Mac scans
Scheduled scans regularly check your Mac for known malware that may have been missed or introduced since the last scan.
Updated threat definitions
Threat definitions are updated regularly so Intego ONE Antivirus can recognize newly identified malware after it’s added to the known-threat database.
Yes. Launching a DDoS attack against a website, network, or online service without permission is illegal in many countries. Authorized stress testing is different because the system owner gives permission and defines how the test is carried out.
Yes, but it usually requires DDoS protection from a hosting provider, cloud platform, internet provider, or specialist mitigation service. Blocking a few IP addresses or turning on a firewall is unlikely to stop a large attack from many sources.
One well-known example is the 2016 Dyn attack. Attackers used the Mirai botnet to flood Dyn with traffic, disrupting access to websites including Twitter, Netflix, PayPal, and CNN. It showed how a single attack on shared internet infrastructure can affect many online services.
Possible signs include a sudden spike in traffic, unusually slow performance, repeated timeouts, frequent disconnections, or a website becoming unavailable. However, these symptoms can also be caused by legitimate traffic spikes or technical problems. You'll need traffic logs, monitoring tools, or your hosting provider's analysis to confirm whether it's a DDoS attack.
A DDoS attack can last from a few seconds to several days. Some attacks happen in short bursts, while others continue in repeated waves. Recovery time depends on the size of the attack, the type of attack, and how quickly it’s detected and mitigated.
Not directly. A DDoS attack is designed to make a service unavailable, not steal data. However, attackers sometimes launch other attacks at the same time or use the disruption to distract defenders while attempting unauthorized access.
Contact your hosting, cloud, internet, or DDoS protection provider and activate your response plan. Save traffic logs, identify which services were affected, and check for signs of other attacks. Keep customers informed through another communication channel, and review the incident after service is restored to strengthen your defenses.
Intego
Trusted. Proven. Powerful.
Driven by innovation for over 25 years, Intego has provided advanced cybersecurity solutions built to protect what matters most — your data, your privacy, and your devices.
With award-winning antivirus, firewall, VPN, and system optimization tools, Intego combines powerful defense with the simplicity and reliability Mac and PC users expect.