An online shop is most vulnerable during the seasonal peak -- exactly when every minute of availability brings the most revenue. And that is exactly when attacks come: in 2025, Cloudflare blocked around 47.1 million (Cloudflare) DDoS attacks, up 121 percent (Cloudflare) year over year. For retail this is not an abstract figure, because according to Akamai 84 percent (Akamai) of the layer-7 DDoS load hit the retail sector. A distributed denial-of-service attack does not break the shop, it makes it unreachable -- cart, login and checkout time out while the bills for servers and advertising keep running. This guide shows how managed DDoS protection, as a fixed building block of ongoing shop maintenance, keeps the shop reachable through the busiest time -- from attack patterns to protection layers to readiness before the peak.
Key takeaways
- DDoS attacks target availability, not data: 47.1 million (Cloudflare) attacks blocked in 2025 mean a 121 percent (Cloudflare) increase -- roughly one and a half attacks every second around the clock.
- Retail is the main target: commerce was the most-attacked industry in 2025, and 84 percent (Akamai) of the layer-7 DDoS load hit the retail sector, often as floods against APIs and checkout during high season.
- The peak attracts attacks: in the 2025 holiday season, malicious bots made up 43 percent (Radware) of shop traffic, up from 31 percent (Radware) the year before -- attack load and buying interest rise at the same time.
- Protection works across several layers: an anycast network absorbs volumetric floods, a web application firewall and rate limiting filter protocol and application attacks, and capacity headroom withstands genuine sales spikes.
- Readiness is built before the peak, not during the attack: filter rules, alerting and an escalation path with agreed response times belong in maintenance, so that not a minute is lost searching in an emergency.
Why DDoS Attacks Hit the Seasonal Peak
German online retail turned over around 83.1 billion euros (bevh) in 2025, and a disproportionate share of that falls in the fourth quarter with Black Friday, Cyber Monday and the Christmas season. In the peak period of October and November 2025, sales grew by 2.9 percent (bevh) year over year -- the first clearly positive Christmas season in years. For attackers this very window is attractive: a shop that goes offline in high season loses not only current orders but also the expensive advertising budget of the campaign days. The pressure to become reachable again fast is at its maximum -- and so is the temptation to give in to extortion in an emergency.
The sheer volume of attacks has been climbing for years. Network-layer attacks tripled in 2025 to 34.4 million (Cloudflare), and in December 2025 -- in the middle of high season -- Cloudflare absorbed the largest publicly documented attack of its kind at 31.4 Tbit/s (Cloudflare). Such hyper-volumetric floods are rare, but they show the direction. For a mid-sized shop, a fraction of that load is enough to bring the server or the uplink to its knees. And because the cost for attackers keeps falling through rentable botnets and simple tools, it is no longer only large corporations in the crosshairs. How quickly downtime minutes turn into real money is clear from a look at the cost of downtime in an online shop.
What a DDoS attack is -- and what it is not
The Three Layers of a DDoS Attack
Not every DDoS attack looks the same. Technically, three layers are distinguished that differ clearly in target and defence -- and effective protection has to cover all three. The following overview contrasts the attack types with the matching defence, as they feed into managed WAF and bot protection.
Volumetric Attacks
Raw bandwidth flood at the network layer, measured in Gbit/s up to Tbit/s. It clogs the line before the server even answers.
Protocol Attacks
Abuse of connection mechanisms such as SYN floods that exhaust server and firewall resources without requesting real content.
Application Attacks (Layer 7)
Mass, real-looking HTTP requests against expensive pages such as search or checkout, hard to separate from genuine traffic.
Anycast Network
Incoming traffic is spread across many locations instead of a single server. Volumetric floods are absorbed in a distributed way where they arise.
Rate Limiting
Limits per address, session or endpoint slow down suspicious request patterns without locking out real customers -- vital for login, search and APIs.
Detection and Alerting
Continuous observation of request rates, error rates and response times flags a starting attack early -- the prerequisite for reacting in time.
Peak Time Is Attack Time
That attacks and buying interest reach their peak in the same window is no coincidence. According to Radware's e-commerce bot report, malicious bots made up around 43 percent (Radware) of shop traffic during the 2025 holiday season -- up from 31 percent (Radware) a year earlier. Counting good and bad bots together, as much as 57 percent (Radware) of traffic came from automated sources, against 49 percent (Radware) the previous year. A considerable part of this automation is harmless, but the boundary between aggressive scraping, bot fraud and a layer-7 attack is fluid. When unusually high traffic arrives during high season anyway, an attack more easily disappears into the noise -- and that is exactly what attackers count on.
The expensive, dynamic parts of a shop are especially in the crosshairs: search, cart, login and the APIs in the background. Akamai counted almost 3 trillion (Akamai) layer-7 DDoS attacks against commerce in 2025, many of them as targeted floods against interfaces during sales peaks. Web and API attacks rose by 9 percent (Akamai) year over year, and 85 percent (Akamai) of surveyed merchants reported at least one API incident in the past year. For maintenance this means: protection must cover not only the homepage but the entire chain up to order completion. How resilient this chain is under a genuine sales spike is clarified by a load test for peak traffic before the season -- so that a legitimate rush is not mistaken for an attack, and vice versa.
Extortion with the threat of an attack
What Downtime in the Peak Really Costs
The maths is uncomfortably simple. A shop that makes a certain turnover on an average day makes a multiple of that on the campaign weekend -- and loses correspondingly more per minute during an outage. Added to this are second and third-order effects: paid advertising budget runs into the void because clicks land on an unreachable page; customers who bounce once buy from a reachable provider instead; and marketplaces and price portals factor availability into their ratings. A single longer outage in high season can thus cost the contribution margin of several normal weeks.
That is why it pays to quantify your own cost of downtime per hour for the peak once -- as a yardstick for how much protection is appropriate. Anyone who knows that one hour of downtime on a campaign day costs a mid four-figure sum values a managed protection layer differently from someone who only sees the base price. Ongoing availability monitoring provides the data basis for this and at the same time detects a starting attack before it hits revenue.
- Protection layers active: anycast distribution, web application firewall and rate limiting are set up and tested.
- Capacity headroom checked: server, database and caching withstand the expected sales spike plus a buffer.
- Critical paths secured: search, login, cart, checkout and the APIs behind them are protected against mass requests.
- Alerting armed: thresholds for request rate, error rate and response time fire early and to the right person.
- Escalation path defined: responsibilities, escalation and agreed response time are settled in writing before the season.
- Communication prepared: text blocks for the status page and for customers are ready in case things do get tight.
How Managed DDoS Protection Works
Managed DDoS protection sits in front of the shop. All incoming traffic runs through an upstream layer that distinguishes between real customers and attack traffic. Volumetric floods are absorbed in a distributed network long before they reach the shop's uplink. Suspicious patterns at the protocol and application layer -- for instance thousands of identical requests per second from one address range -- are throttled or blocked, while normal requests pass through unhindered. Ideally, the shop itself notices nothing of an absorbed attack.
The difference between a basic protection switched on once and a managed solution lies in the ongoing upkeep. Filter rules have to fit the specific shop: an aggressive rate limit that mistakes the newsletter rush on a campaign day for an attack is as harmful as one too lax that lets real floods through. That is why the rules are observed, readjusted and reviewed before every major campaign. This fine-tuning is the actual maintenance share -- related to the ongoing WAF and bot protection, which uses the same mechanisms against fraud and scraping.
| Attack layer | Typical pattern | Risk without protection |
|---|---|---|
| Volumetric (L3/L4) | Bandwidth flood from a rented botnet | Line clogged, shop unreachable for everyone |
| Protocol | SYN flood exhausts connection tables | Server and firewall give up before content loads |
| Application (L7) | Mass requests against search and checkout | Database overloaded, order completion breaks off |
| Extortion (RDoS) | Short outage plus payment demand | Pressure to pay instead of technical defence |
The table shows why a single tool is rarely enough. Each layer needs its own answer, and the layers can be combined -- a volumetric attack as a distraction while a targeted application flood cripples the checkout in parallel. Well-thought-out protection covers this interplay and is maintained as a whole, not as a loose collection of individual measures.
How We Prepare the Shop for the Peak
Peak readiness is a procedure with clear steps that begins weeks before the first campaign day. The goal is that in an emergency not a minute is lost on searching, credentials or coordination -- because everything is settled in advance. An SLA maintenance contract sets the agreed response times and responsibilities, so the reaction does not depend on chance.
- Map the attack surface: which endpoints, APIs and forms are exposed and especially prone to mass requests?
- Set up and test protection layers: arm anycast distribution, web application firewall and rate limiting and verify them with controlled tests.
- Secure capacity headroom: adjust the capacity of server, database and caching to the expected spike plus a buffer.
- Configure alerting: define thresholds for request rate, error rate and response time and couple them to on-call.
- Rehearse the escalation path: run through escalation, approvals and communication blocks once before things get serious.
- Review after the peak: document attack attempts, false alarms and bottlenecks and sharpen the rules for the next season.
The most expensive time to improvise
Detecting Attacks Early: Monitoring as an Early Warning
Protection and detection belong together. Even the best filter layer needs an eye on whether it is working -- and whether a new attack type slips through. Continuous observation of request rates, error rates and response times often flags a starting attack before the first customers see a timeout. Anyone who sets up uptime monitoring properly markedly shortens the time between the start of an attack and the reaction.
What matters is that a notification turns into an action. An alert sitting unread in an inbox at three in the morning helps no one in the peak. That is why we couple detection to a defined emergency support with clear escalation levels: who is informed when, who may tighten protection rules, and from which threshold the highest level applies. This turns a technical signal into a reliable response.
A DDoS attack destroys nothing -- it only takes availability. That is exactly why it is so effective in the seasonal peak and why preparation is so valuable: whoever has filtered, tested and rehearsed beforehand loses minutes in an emergency instead of weeks of revenue.
DDoS Protection Belongs in Ongoing Maintenance
DDoS protection is not a product you buy once and then forget, but a state that wants to be maintained. Attack patterns change, the shop grows, new APIs are added, and every larger campaign shifts the load curve. That is why the protection layer belongs in the same rhythm as updates, backups and monitoring. Closely related are two further building blocks that concern the same attack surface: protecting the checkout against card testing and bot fraud and cleanly rotating API keys and secrets, so that abused credentials do not become a load themselves.
For operators who do not want to start from scratch every season, the obvious answer is a fixed framework: DDoS protection, capacity headroom and alerting as a recurring building block of the maintenance packages, tuned to your own peak curve and your own cost of downtime. It starts with a sober inventory -- which protection layers work today, where are the gaps, and how quickly would someone be on hand in an emergency. This analysis can be requested without obligation, ideally with enough lead time before the next high season.