Akamai: web application attacks on the gaming industry increased 167% YoY from May 2021-April 2022, and 37% of all DDoS attacks were against the gaming sector
Leigh Mc Gowran / Silicon Republic :
Context & Ripple Effects
Gaming was already Akamai's poster child for account abuse: its 55B credential stuffing attacks between Nov. 2017 and March 2019 established the sector as a magnet for automated attacks on login flows. The new numbers extend that pattern from credentials to the application layer itself — a 167% YoY jump in web application attacks and 37% of all DDoS volume landing on gaming.
The timing matters because it follows ransom DDoS rising 29% YoY and 175% QoQ in Q4 2021, meaning gaming absorbed the largest share of an attack category that had just become explicitly extortion-driven. Akamai's position as both the measurement source and a mitigation vendor frames the report as market intelligence for its own core business.
First-order effects
- Game publishers and platform operators face a doubled web-application attack load plus over a third of global DDoS traffic, making uptime during launches and live-service events directly contingent on edge mitigation capacity.
- Akamai converts the finding into sales leverage: the same telemetry documenting the surge positions its security portfolio as the default answer for gaming customers weighing dedicated protection spend.
Second-order effects
- Competing CDN and DDoS-mitigation providers are pushed to match Akamai's gaming-specific threat reporting with their own vertical data, since sector-level telemetry is becoming a marketing asset in enterprise security procurement.
- The concentration of DDoS on gaming alongside FS-ISAC's finding of rising DDoS against banks shows attackers rotating across high-availability consumer sectors, forcing security budgets in adjacent industries to be benchmarked against gaming's exposure rather than treated as isolated.
Third-order effects
- If ransom-driven DDoS keeps growing while one sector absorbs the plurality of volume, DDoS hardens into a recurring extortion economy rather than episodic vandalism — echoing the scale escalation from the record 620Gbps attack on Brian Krebs' site toward sustained, monetized campaigns.
- Sector-targeting data from vendors like Akamai is likely to shape how regulators and insurers price cyber risk by industry, with gaming's attack share feeding into premiums and compliance expectations for live-service operators.
The trend: DDoS and application-layer attacks are consolidating around consumer-facing online sectors, with gaming emerging as the highest-volume target in an extortion-driven attack economy.