Q4 WAF Attacks Came From 12.5 Million Unique IP Addresses
If your Q4 report shows 12.5 million unique IP addresses behind WAF traffic, that number is more than a scary headline. It changes how you should read every “blocked requests” chart that follows. Unique IP WAF attacks at this scale signal industrialized probing, rotating infrastructure, and automation designed to defeat simple assumptions like “repeat offenders are easy to spot.”
For threat intelligence reporting, the first risk is interpretation. A huge unique-IP count can make your program look “busy” while hiding what actually matters: which paths and parameters are being tested, how close attacks are getting to app logic, and whether your rules are stopping the right things or just generating noise. If your WAF is blocking broadly but your logs lack the detail to distinguish exploit attempts from commodity scanning, you end up with volume and no story. That is a bad place to be when leadership asks, “Are we safer, or just louder?”
The second risk is operational cost. Unique IP WAF attacks drive up alert fatigue, SIEM ingestion, and analyst time. They also pressure caching layers and edge configurations in ways that appear to be performance problems rather than security problems. When this activity is bot-driven, it bleeds into availability and conversion: rate limits trip legitimate traffic, challenges get misapplied, and customers feel friction you did not intend.
The way forward is to treat the edge as part of your security program, not a default setting. Tighten what you log, normalize what you report, and tune rules around the attacks you actually see. Then add bot mitigation where automation is the real “attacker,” because blocking IPs alone will not keep up with rotation.
That many unique sources are a reminder that “set it and forget it” at the edge is a gamble. If you want your WAF numbers to translate into fewer incidents, not just bigger charts, tighten your edge rules.
Source: Wordfence Q4 2025 Threat Intelligence Report