You specifically asked about "how many users" I assume customers. Customers are rarely the ones performing a DDoS unless servers are improperly configured causing a company to DDoS itself from it's own customers. This is never intentional and is usually short lived usually because the company launched an event they did not properly plan and scale for or an engineer flubbed an update. Once the event is over or the planned change was reverted the DDoS will likely cease and some people will be fired and/or they will better plan next time maybe.
If you mean all the customers one day decided to revolt and they all agreed to commit felonies then it is unlikely they could achieve a full sustained outage for long as their identity and IP addresses are already well known. Customers do have the advantage of being able to attack authenticated and thus going deeper into the stack increasing load. If anonymous attackers can do much the company may need to rewrite everything. It would make for some good bodycam videos and I will enjoy all of them with snacks. Bonus if they manage to get reviewed by Donut Operator.
For actual DDoS attacks, official detailed numbers will never be public as this would tell attackers how much more they need to spend to achieve 100%. It will vary by company, ddos cdn's and scrubbing sites used, website infrastructure, how well applications are coded and a number of other factors.