A glowing shield links cloud servers and gaming devices, illustrating secure cloud gaming across a global network.
Last October, one night of lag took down more than a few matches. On October 6, 2025, outage reports climbed at roughly the same time for Steam, Xbox, PlayStation Network, Epic Games and Riot's League of Legends and Valorant. Almost a year later, that night is the opening example in a TechRadar Pro opinion piece by Matthew Andriani. He argues that the real threat to online gaming isn't just bigger DDoS floods. It's the gap that opens quietly when protections stop matching the systems they're meant to cover.

His argument is worth hearing out. Keep one thing in mind while you do: Andriani is the founder and CEO of MazeBolt, a company that sells DDoS testing and validation. His main recommendation lines up closely with what his company sells. That doesn't make it wrong. It does mean it should be checked against independent evidence, which is what this piece does.

What actually happened in October 2025​

The public record is messier than the "record attack took down gaming" version that circulates.

  • The outages: PC Gamer reported that shortly before 11 p.m. Eastern on October 6, Riot's status pages for League of Legends and Valorant listed "game disconnection issues." Outage reports for Steam, Xbox, PlayStation and Epic spiked around the same time, and Steam had a further brief hiccup the next day.
  • The attribution: PC Gamer also said plainly that a coordinated DDoS against several gaming services was unconfirmed. A Riot spokesperson acknowledged something was happening across multiple companies but wouldn't say what caused it. The timing looked suspicious, but that isn't proof.
  • The 29.6 Tbps number: KrebsOnSecurity reported that on October 6, Aisuru's operators sent about 29.6 Tbps at a single target. That target was a server built specifically to measure large DDoS attacks, and the flood lasted only seconds. Krebs described it as a likely demonstration of what the botnet could do. It was not shown to be the attack that knocked the platforms offline.
  • FastNetMon's figure: FastNetMon's October 8 write-up named Aisuru as the suspected source of a 29.69 Tbps event on October 6. That's where the "29.69" figure in Andriani's piece comes from. The key word is still "suspected."

The honest summary is this. Several major platforms, Microsoft's Xbox network among them, had problems at the same moment Aisuru was showing off record capacity. The two events are linked by timing, not by proof. Andriani says the attack was "suspected to be linked" to Aisuru, which is the right amount of caution. Much of the social-media retelling since then has dropped it.

Section summary: The outages were real, Aisuru's record capacity was real, and nobody has publicly proven that one caused the other.

Aisuru's record since then​

The botnet did not slow down after October:

  • Cloudflare's Q3 2025 report described a 29.7 Tbps UDP "carpet-bombing" attack that hit about 15,000 destination ports per second, plus a separate 14.1 billion-packets-per-second attack. Cloudflare said it had mitigated 2,867 Aisuru attacks since the start of 2025. It also noted that 89% of network-layer attacks and 71% of HTTP DDoS attacks were over in under 10 minutes, which is faster than people or on-demand services can react.
  • A new record: According to FastNetMon, in late January 2026, Cloudflare disclosed details of what is now the largest publicly reported DDoS attack to date, an incident that occurred in December 2025 and peaked at 31.4 Tbps. The attack was attributed to the Aisuru botnet.
  • The takedown: In March, SecurityWeek reported on an international operation against Aisuru, Kimwolf, JackSkid and Mossad. Authorities said the botnets have compromised more than 3 million devices as of March 2026, including DVRs, cameras, Wi-Fi routers, and other IoT devices. Per the U.S. Department of Justice, cybercriminals used the Aisuru botnet to issue over 200,000 DDoS attack commands.
  • After the takedown: Bitsight's telemetry recorded that on the 19th of March 2026 the US DOJ, with Germany, and Canada, seized the C2 infrastructure behind Aisuru and three sibling botnets. Bitsight says the takedown cut daily attack volume by about 66% and pushed the operators onto a smaller and more consolidated infrastructure. That's a big cut, but the botnet is still running.
  • Backbone data: Arelion's July 2026 report found that Aisuru now drives approximately 33 percent of global DDoS attack traffic on Arelion's network, and that it primarily targeted major gaming and cloud providers.

One more detail matters for gaming. Krebs reported that on October 8, 2025, two days after the platform outages, TCPShield took an Aisuru flood of more than 15 Tbps. TCPShield provides DDoS protection to more than 50,000 Minecraft servers. This was a separate incident, but it shows who Aisuru tended to target.

Section summary: Law enforcement has damaged Aisuru but not killed it, and independent data keeps placing gaming near the top of its target list.

Why "we bought protection" isn't the same as "we're protected"​

Andriani's core argument doesn't depend on who caused October's outages. He asks why big, well-funded platforms still go down when they've already paid for DDoS protection.

His answer is configuration drift: the growing mismatch between the DDoS controls you deployed and the environment as it looks today. Game studios change constantly. They ship patches, add live-service features, open regional endpoints and move workloads between hosts. His example is a new matchmaking service whose traffic is routed differently from the original service. The mitigation policy that protected the old path doesn't automatically follow the new one. The protection hasn't changed, but the thing it's supposed to protect has.

This is his illustration, not a documented account of any named company's architecture. The failure mode will still sound familiar to anyone who runs change management. Typical drift includes:

  1. A new public endpoint or API goes live outside the scrubbing path.
  2. A DNS or routing change sends traffic around a mitigation provider.
  3. A cloud migration moves a service without carrying over its protection policy.
  4. Thresholds tuned for last year's traffic no longer fit a service that has grown or shrunk.

None of these requires an attacker to be clever. The attacker only has to find the gap before you do.

Point-in-time tests measure a system that no longer exists​

Andriani's second point is about timing. If you run a DDoS test in January and change the environment significantly in February, what does January's result tell you in August? A studio might push meaningful production changes every week while formal testing happens quarterly or twice a year. Every change in between could open a gap.

He credits scheduled testing where it's due. It does show how well people and procedures hold up on test day. That matters, because escalation paths, communications and runbooks go stale too.

The independent data backs up the timing concern:

SourceFinding on attack duration
Cloudflare, Q3 202589% of network-layer and 71% of HTTP DDoS attacks ended within 10 minutes
Gcore, Q3–Q4 202575% of network-layer attacks lasted less than a minute; only 2% ran past 10 minutes

When most floods are over in less than a minute, protection has to already be in place and correctly scoped before the attack starts. Nobody has time to notice the gap mid-attack and fix it.

The numbers also need to be kept straight. Andriani cites Gcore's H2 2025 data: gaming accounted for 19% of observed attacks, making it the third most-targeted sector, and overall activity rose 150% year over year. Gcore's March 24, 2026 release for Q3–Q4 2025 puts technology at 34% and financial services at 20%. It counts 1.3 million attacks in Q4 2025, up from 512,000 in Q4 2024. These figures describe what Gcore saw on its own network, not a count of every attack worldwide. Gcore also sells DDoS protection.

Section summary: Attacks are short, frequent and aimed at services where downtime costs money immediately. Test results age quickly in environments that change weekly.

The counterweight: what continuous validation doesn't prove​

Andriani recommends ongoing DDoS validation instead of relying only on scheduled tests. Three caveats apply:

  • It's a vendor position. It's reasonable, but it's also MazeBolt's business model. Some MazeBolt marketing goes further and suggests misconfiguration is behind successful DDoS attacks in general. No independent evidence here supports that broader claim.
  • Sometimes volume just wins. Krebs quoted Robert Coelho, a long-time operator of gaming-focused mitigation services, estimating that it now takes at least a million dollars a month in network capacity just to absorb attacks of this size. A perfectly configured defense can still be overwhelmed if the pipe is too small.
  • Collateral damage is a real risk. Netscout's Roland Dobbins told Krebs that outbound attack traffic from infected customers on ISPs can cause as much disruption as inbound floods. If congestion hits upstream, your configuration may not be the problem at all.

Continuous validation keeps your evidence about coverage current. It doesn't guarantee uptime, and anyone selling it as a guarantee is overselling.

A practical checklist for studios and online-service operators​

This procedure builds on Andriani's recommendation and follows ordinary change-management practice. It doesn't depend on any particular product:

  1. Inventory everything public-facing. For each internet-facing service, record the owner, endpoints, how traffic reaches it and which mitigation control covers each path.
  2. Make DDoS review part of every change. When a service, endpoint, route, host or protection policy changes, ask Andriani's three questions: did this change what is exposed, how traffic reaches it, or how existing DDoS controls respond?
  3. Validate safely. Confirm that the intended controls still apply, using authorized testing that suits production. Uncontrolled live attack simulation against production is its own outage waiting to happen.
  4. Look for the pattern behind a gap. Andriani advises investigating how a gap appeared rather than patching it in isolation. If one change exposed one service, the same pattern may exist elsewhere.
  5. Keep the human side current. Keep upstream provider contacts, escalation paths and incident runbooks up to date. U.S. guidance from CISA also recommends monitoring against a traffic baseline so you can spot an attack, and reporting incidents to CISA or the FBI.
  6. Watch for short bursts. Given the duration data above, alerting that only fires on sustained floods will miss most attacks.

The home-network angle: where the firepower comes from​

There's a part of this story for ordinary PC and console owners too. Krebs reported that Aisuru is built mostly from consumer routers, security cameras, DVRs and similar devices running outdated firmware or factory-default settings. It has recently drawn heavily on devices hosted by major U.S. ISPs. Bitsight also notes that the botnet has pivoted to targeting exposed Android Debug Bridge (ADB) instances, enabling local network scanning and the deployment of proxyware on vulnerable devices.

In other words, some of the traffic that knocks games offline may be coming from gamers' own homes. Some basic housekeeping helps:

  • Update router firmware, and replace routers that no longer get updates.
  • Change default admin passwords on routers, cameras and DVRs.
  • Be suspicious of cheap, no-name Android TV boxes. Make sure debugging features like ADB aren't exposed.
  • If your connection slows down for no obvious reason, check what's connected to your network.

The bottom line​

As Andriani puts it, players don't care whether a game passed its last test or whether an outage came from bad code or an outside attack. The game either works or it doesn't. For Xbox and everyone else running always-on services, the lesson from October 2025 doesn't depend on who caused the outages. Owning DDoS protection is one thing. Knowing it still covers your services today is another. Botnets have reached 31.4 Tbps, and most attacks are over in under a minute, so there's no time left to find that out during the attack.

 

References

  1. Gaming moves fast. Can its defenses keep up? TechRadar 2026-09-30T10:29:21+00:00
  2. Arelion’s 2026 DDoS report shows Aisuru botnet responsible for nearly one third of DDoS attacks | Arelion arelion.com
  3. DDoS Botnet Aisuru Blankets US ISPs in Record DDoS – Krebs on Security krebsonsecurity.com