Why Is Traffic From Mexico and Brazil a Security Threat Right Now?

Writer: Jordan Sprogis

Jordan Sprogis, Contributing Expert

Jordan Sprogis is a creative writer and tech researcher who has been working on online content for the better part of a decade. She holds a bachelor's degree in professional writing from Western Connecticut State University and has devoted much of her career to crafting content for various web verticals, including CyberSpyder and The Echo. Since joining HostingAdvice, Jordan has combined her storytelling ability with her fascination for advancements in technology to pen over 500 articles geared toward industry pros and newcomers alike.

Editor: Lillian Castro

Lillian Castro, Senior Editor

Lillian Castro brings more than 30 years of editing and journalism experience to our team. She has written and edited for major news organizations, including The Atlanta Journal-Constitution and the New York Times, and she previously served as an adjunct instructor at the University of Florida. Today, she edits HostingAdvice content for clarity, accuracy, and reader engagement.

Reviewer: Cristian Lopez

Cristian Lopez, News Manager

Cristian Lopez uses his Business Marketing background from the University of Illinois at Chicago to create comfortable environments for customers, clients, and colleagues to share their thoughts and ideas openly. From interviewing tech leaders to conducting UX market research projects, Cristian knows the importance of storytelling — a key variable for innovation and inspiration. His goal at HostingAdvice is to wow readers on the ever-evolving nature of the tech industry and bring his audience the most reliable and exciting content on all things hosting.

Follow the HostingAdvice team for a daily dose of tech news, trending IT discussions, and interviews with the web's most innovative technologists.
Follow Us:
2.7k
1k

More than 50% of all network-layer DDoS attacks apparently now come from just two countries.

According to Gcore’s latest report, Mexico and Brazil are the leading sources of DDoS traffic, with Mexico making up 31%, Brazil 24%, followed by the U.S. at 20%.

The technology sector (34%), financial services (20%), and gaming (19%) are the among the most targeted.

Pie chart showing DDoS attack distribution by industry for Q3–Q4 2025, with technology at 34%, financial services at 20%, gaming at 19%, telecom at 11%, media and entertainment at 8%, retail at 6%, and other at 2%
It looks like DDoS attacks are targeting the very infrastructure hosts rely on.

One theory for the heavy saturation is the infamous AISURU botnet, which has been recently busy infecting millions of IoT devices across Mexico and Brazil.

For those looking for a word of advice, Andrey Slastenov — who’s the head of security at Gcore — told us that traditional “detect, reroute, then react” strategies are nowhere near good enough to do the job anymore.

Why Latin America?

While the report doesn’t name a single cause, it does bring up a pattern: Attack traffic is concentrated where there’s an abundance of insecure, always-on devices. In countries like Mexico and Brazil, that’s millions of connected devices — from routers to cameras — are being deployed without updates or oversight.

Mexico is expected to hit $4.95 billion (USD) by 2030 in the IoT market, a reminder of just how many always-on devices are coming online in a single region.
Brazil’s chart is a bit less than Mexico’s projection, but still climbing very fast, landing at about $4.1 billion (USD) by 2030.

That’s the kind of environment botnets like AISURU thrive in. And once those devices are infected, they’ll be coordinated into partaking in a much larger attack.

To be clear, this isn’t necessarily unique to Mexico or Brazil. Not that long ago, we were seeing similar traffic spikes tied to bot activity coming out of China and Singapore. Next month it’s going to be somewhere else — the test is whether providers are going to be prepared at each corner.

What Happens When You Can’t Stop the Attack?

The only way to stay ahead of DDoS is to catch the traffic early on, long before it builds up. But realistically, most hosting providers aren’t in a position to stop attacks near the source. That’s the job of upstream providers, like CDNs and hyperscalers.

Does that mean hosts should take filtering into their own hands? Sort of. But specifically watching traffic from Mexico or Brazil more closely? No. When more than half of attack traffic is originating from identifiable places, tightening filters too strictly can mean blocking actual users from those regions. The opposite, being too lenient, risks dangerous traffic.

It’s a careful balance… It’s also why rate limiting/filtering is your friend.

Many attacks (L3 & L4) are focused on overwhelming infrastructure, which is why hosts are left filtering massive traffic bursts.

Behavioral indicators are more informative than location, like sudden traffic spikes and request patterns. In fact, Gcore’s report notes that most network-layer attacks (L3 & L4) are short, high-volume bursts, often lasting less than a minute.

“Today’s volumetric traffic bursts can even overwhelm regional capacity of smaller providers before mitigation mechanisms are even triggered,” he said.

So no, hosts likely can’t stop DDoS attacks completely, but Slastenov encourages them to be prepared for what will inevitably seep through. That can mean slower performance during attacks as filtering and rate limiting kick in; maybe some temporary traffic controls.

There’s no perfect formula; just different types of damage control. But that’s kind of the point that Gcore’s report makes, right? DDoS attacks are happening within a second — much faster than systems can even react to. So all the downstream providers can do is prepare and brace.

About the Author

Contributing Expert

Jordan Sprogis is a creative writer and tech researcher who has been working on online content for the better part of a decade. She holds a bachelor's degree in professional writing from Western Connecticut State University and has devoted much of her career to crafting content for various web verticals, including CyberSpyder and The Echo. Since joining HostingAdvice, Jordan has combined her storytelling ability with her fascination for advancements in technology to pen over 500 articles geared toward industry pros and newcomers alike.

« BACK TO: BLOG

Meet the Experts

Our team of experts with a combined 50+ years of experience in web hosting serve insight and advice to more than 20 million users!

We Know Hosting

$

4

8

,

2

8

3

spent annually on web hosting!