Independent incident-cost research, read by IR and resilience teams pricing downtime.Sponsor this site →
Incident Type: DDoS · Updated July 2026

DDoS Attack Cost: What Denial of Service Incidents Cost in 2026

$120K
Low-end SMB impact
$2M+
Enterprise impact
$50K/mo
Enterprise mitigation

A Distributed Denial of Service (DDoS) attack floods a target with traffic to make it unavailable to legitimate users. Unlike ransomware or breaches, DDoS attacks do not exfiltrate data, but they cause direct revenue loss through downtime and can be used as a pressure tactic alongside ransomware (triple extortion). DDoS attack cost varies enormously based on duration, organisation revenue, and whether the target has mitigation in place.

Cost Components

Cost CategoryRangeNotes
Revenue loss during attack$0-$1M+Scales with hourly revenue and attack duration
Bandwidth overage charges$0.05-$0.50/GB overageWithout DDoS scrubbing, ISP charges apply
Emergency mitigation service$10K-$100KOne-time emergency on-ramp without existing contract
On-call engineering time$5K-$50KSenior engineers during multi-hour attack
Ransom DDoS demand (if present)$5K-$500K in cryptoAttackers demand payment to cease attack
Reputation and customer trust$20K-$200KPR, customer communication, SLA credits
Post-incident hardening$10K-$150KInfrastructure changes, scrubbing service setup

Types of DDoS Attack and Cost Profiles

Attack TypeMethodCost Profile
Volumetric floodSaturate bandwidth with high-volume traffic (UDP floods, DNS amplification)Low cost without mitigation; completely blocked with scrubbing
Protocol attack (SYN flood)Exhaust state tables on firewalls and load balancersModerate cost; server infrastructure damage possible
Application layer (Layer 7)HTTP floods targeting specific endpoints; hard to distinguish from legitimate trafficHighest cost per Gbps; bypasses simple mitigation
Ransom DDoS (RDDoS)Volumetric attack with ransom demand to ceaseAdd $5K-$500K extortion demand to base attack cost

Mitigation Cost vs Incident Cost

Cloud-based DDoS scrubbing services prevent most of the revenue and downtime cost at a fraction of the expected incident cost:

ProviderEntry TierEnterprise TierCoverage
Cloudflare$20/mo (Magic Transit from $0.05/MB)$50K-$200K/yrLayer 3-7, unlimited mitigation on enterprise
AWS ShieldStandard: FreeAdvanced: $3K/mo + data transferLayer 3-7 for AWS resources
Akamai (Prolexic)Custom enterprise pricing$50K-$300K/yrNetwork-level and app-layer scrubbing
Cloudflare (Magic Transit)Starts at $1K/mo$20K-$100K/yrNetwork-level full BGP diversion

What DDoS Testing Costs

Authorised DDoS testing is priced per engagement by a short list of pre-approved partners, and neither AWS nor Microsoft publishes a rate card for it. What both publish instead are the rules, and the rules are what actually set the size of the bill: you may only simulate against resources you own, the test has to be run by a named partner, and the traffic is capped well below what a real attack delivers. A test is a scoped consulting engagement plus the protection subscription it requires, not a metered service you buy by the gigabit.

Platform ruleAWSMicrosoft Azure
Who may run the testAn AWS Partner Network partner pre-approved by AWS: NCC Group plc, RedWolf Security, Red Button, Safedash AnalyticsAn approved Microsoft testing partner: MazeBolt, Red Button, RedWolf (Red Button is Public cloud only)
What may be targetedA resource registered as a Protected Resource in an AWS account you own and subscribed to AWS Shield AdvancedAn Azure-hosted public IP in your own subscription, validated by the partner, protected under Azure DDoS Protection
Traffic ceiling20 Gbps; 5 million packets per second against CloudFront, 50,000 packets per second against any other resource type; 50,000 requests per secondSet by the partner engagement; Microsoft advises testing in staging or off-peak hours
Going outside the rulesA vendor that is not pre-approved, or a test above the technical limits, needs an exception form submitted at least 14 days before the test dateNot offered; only the three approved partners may simulate

The practical budget has three lines, and only one of them is the test itself. First, the protection subscription the platform requires before it will let you test at all (AWS Shield Advanced, or an Azure DDoS Protection plan). Second, the partner engagement, which is quoted rather than listed: Microsoft's documentation describes Red Button's controlled attack stage as typically three to six hours of multi-vector traffic, wrapped in a planning session beforehand and a written test report afterwards, so it is billed as a project rather than by attack volume. Third, the staging environment you run it against, if you follow the advice not to test in production.

Anything cheaper than that is usually not a test. Booter and stresser services sell traffic against a target on request and do not verify that you own it. In the UK, section 3 of the Computer Misuse Act 1990 makes an unauthorised act done with intent to impair the operation of a computer an offence carrying up to ten years' imprisonment on indictment, and that applies to traffic you commissioned against your own supplier, your own CDN edge, or a shared host, none of which you own outright.

Sources, checked 7 September 2026: AWS DDoS Simulation Testing policy · Azure DDoS Protection simulation testing · Computer Misuse Act 1990 s.3

Notable DDoS Events

EventYearScaleImpact
Dyn DNS DDoS (Mirai botnet)20161.2 TbpsAmazon, Netflix, Twitter, GitHub, NY Times disrupted; millions lost in e-commerce revenue
GitHub DDoS (Memcached amplification)20181.35 TbpsRecord at the time; GitHub mitigated in 10 minutes via Akamai Prolexic
AWS DDoSFeb 20202.3 TbpsLargest ever at time; mitigated by AWS Shield Advanced
Cloudflare mitigated attack20245.6 TbpsLargest on record; 13,000 source IPs; mitigated automatically

Frequently Asked Questions

How much does a DDoS attack cost?
$120K at the low end for an SMB without mitigation, up to $2M or more for a large enterprise experiencing multi-hour L7 attacks. This range covers revenue loss, bandwidth costs, emergency mitigation, and post-incident hardening.
What is Ransom DDoS (RDDoS)?
RDDoS is when an attacker threatens a DDoS attack (or launches one) and demands cryptocurrency payment to stop. Common demands range from $5,000 to $500,000 in Bitcoin. Unlike ransomware, paying does not guarantee the attack stops, and many RDDoS operators simply take payment and continue.
Is DDoS cheaper to mitigate than to absorb?
Almost always yes. A Cloudflare or AWS Shield subscription at $300-$3,000/month will prevent a large percentage of DDoS revenue loss. The break-even is very fast for any organisation with meaningful web-based revenue.
How much does DDoS testing cost?
There is no published price. Both AWS and Microsoft only permit simulated DDoS testing against resources you own, run by a named pre-approved partner (NCC Group, RedWolf, Red Button or Safedash Analytics on AWS; MazeBolt, Red Button or RedWolf on Azure), and neither the platforms nor the partners publish a rate card. The budget is the partner engagement, quoted as a project, plus the protection subscription the platform requires before it will allow a test (AWS Shield Advanced, or an Azure DDoS Protection plan). AWS also caps a simulation at 20 Gbps, 50,000 requests per second, and 50,000 packets per second against non-CloudFront resources, so a test deliberately runs smaller than a real attack. Checked 7 September 2026.
Is authorised DDoS testing the same as using a stresser service?
No. Authorised testing is scoped to infrastructure you own, is pre-approved by the platform, and is run by a partner the platform has vetted. Booter and stresser services sell attack traffic without verifying ownership of the target. In the UK, section 3 of the Computer Misuse Act 1990 makes an unauthorised act intended to impair the operation of a computer an offence carrying up to ten years' imprisonment on indictment.
How is DDoS different from a service outage?
A DDoS is an externally caused, deliberate availability attack. A service outage may be internal or external, intentional or accidental. DDoS impacts availability only; it does not inherently compromise data. An outage caused by DDoS is both a security incident and an availability incident.
IncidentCost.com is an independent educational resource. All cost figures are drawn from published industry research including IBM's Cost of a Data Breach Report, Ponemon Institute Cost of Insider Risks Report, Verizon Data Breach Investigations Report, Atlassian incident management research, and PagerDuty incident surveys. This site is not affiliated with IBM, Ponemon Institute, Verizon, Atlassian, PagerDuty, or any security vendor. Figures are for educational and planning purposes only.