Microsoft mitigated a 3.47 Tbps DDoS attack on an Azure customer in Asia in November; DDoS attacks in India rose from 2% of all attacks in H1 2021 to 23% in H2
Context & Ripple Effects
Microsoft had already reported mitigating a 2.4 Tbps Azure attack, a figure that surpassed AWS's previously reported 2.3 Tbps event. The newer disclosure raises the scale benchmark again while highlighting a sharp late-2021 increase in India's share of reported attacks.
Later Azure incidents show that DDoS resilience is not only a capacity metric: attacks temporarily affected Azure and Microsoft 365 services in 2023, and a 2024 attack was tied to a wider service outage.
First-order effects
- The targeted Azure customer avoided the immediate impact of a 3.47 Tbps attack through Microsoft's mitigation infrastructure, making Azure's DDoS protection a concrete part of the service delivered to enterprise customers.
- Microsoft's security teams must account for a changed attack distribution as India rose from 2% to 23% of reported attacks between the first and second halves of 2021.
Second-order effects
- AWS and other cloud providers face renewed pressure to demonstrate mitigation capacity as Microsoft extends the attack-size benchmark beyond the earlier Azure event that had surpassed AWS's reported record.
- Azure customers will place greater weight on provider-level DDoS defenses and service-availability assurances, especially after a DDoS-triggered outage disrupted Microsoft services in later coverage.
Third-order effects
- Cloud DDoS competition is shifting from isolated record claims toward resilience as a core cloud-service differentiator: large mitigations matter only insofar as customers' applications remain available.
- If attack volumes continue to rise, the dividing line between cloud platforms will increasingly be their ability to absorb attacks without cascading disruption across shared services.
The trend: DDoS attacks are becoming a cloud-platform resilience test, with escalating attack scale and changing regional concentration increasing the value of built-in mitigation.