Half-year DDoS report: terabit-scale floods are now routine
Cloudflare's H1 2026 DDoS Threat Report, the 25th edition and its first half-year analysis, covers January through June. The headline: attacks exceeding 1 Tbps were once noteworthy anomalies; they are now part of the regular threat cadence. Cloudflare mitigated 935 network-layer attacks above that threshold in the period, with a 519% quarter-over-quarter spike between Q1 and Q2 alone.
Scale and speed of attacks
The volume is staggering. Cloudflare mitigated 23.2 million network-layer and 29.64 trillion HTTP DDoS requests during the half-year, averaging roughly 5,343 network-layer attacks per hour — about 128,000 daily. April was the peak month at 6.46 trillion requests and 165 PB of traffic, followed by a notable decline that Cloudflare attributes in part to Operation PowerOFF, a 21-country law enforcement effort that targeted more than 75,000 DDoS-for-hire users, shuttered 53 domains, executed 25 search warrants, and netted four arrests.
Hyper-volumetric attacks — defined as exceeding 1 Tbps, 1 billion packets per second, or 1 million requests per second — grew dramatically. In Q2 alone, Cloudflare mitigated 805 network-layer attacks exceeding 1 Tbps, a more than six-fold increase over the prior quarter.
The "small" attack is still a big problem
Volume trends don't tell the whole story. The median attack remained short and modest by comparison: 96.62% of network-layer attacks stayed under 500 Mbps, and 90.60% concluded in under 10 minutes. These numbers are relative, however. A 100 Mbps flood can still overwhelm a typical server, a 100 Gbps attack can knock most unprotected data centers offline, and attacks above 1 Tbps stress even major Internet infrastructure.
Attackers also mix layers — pairing high packet rates with lower bandwidth or vice versa — to target different weaknesses in network gear versus capacity. The duration of attacks is similarly deceptive. Even the largest hyper-volumetric assaults can last only seconds; Cloudflare has seen record-breaking attacks finish in 35 seconds. That leaves no window for human intervention. The cascading effects — routing instability, TCP retransmissions, application timeouts — can persist for hours or days after the attack itself has ended.
Targets and sources shift with geopolitics
Global events drove significant reshuffling in attack targeting during H1. The February 28 Operation Epic Fury strikes by Israel and the United States against Iran's leadership triggered a rapid hacktivist response: researchers recorded 149 DDoS claims against 110 distinct organizations across 16 countries within 72 hours, with nearly 47.8% of targets in the government sector. That sector jumped from the #29 most-attacked industry in Q1 to #9 in Q2 — the largest single industry rank movement of 2026.
Media, Production & Publishing held the #1 spot in both quarters at 14.2% of all mitigated HTTP DDoS requests, nearly four times the runner-up, amid sustained coverage of Iran, Ukraine, and the World Cup.
On the geographic front, China absorbed 22.4% of HTTP DDoS requests globally in Q2 to finish as the most attacked location. The United States held at #2 with 18.8%. Turkey nearly doubled its share to rise to #3, a surge that coincided with the buildup to the 2026 Ankara NATO Summit and pre-summit security operations that included at least 209 arrests.
Brazil overtook the United States as the top source country for attacks, accounting for 14.9% versus 13.4% of mitigated DDoS request traffic. That shift was driven by a Q2 surge that put Brazil at 21.4% of global attack source traffic. Indonesia stayed locked at #3, extending its run among the top sources.
Attack vectors: DNS floods and the CLDAP surge
Attack vectors shifted decisively from botnet floods toward reflection and amplification techniques. DNS-based attacks — both DNS Floods and DNS Amplification — accounted for 34.3% of network-layer attacks in H1. The two are distinct: DNS Floods point raw botnet request volume at a victim's authoritative DNS servers to exhaust query capacity, while DNS Amplification sends small spoofed queries to open resolvers, which reply with much larger responses to the victim's spoofed IP.
DNS Floods alone climbed from 25.7% to 40.0% of network-layer attacks quarter-over-quarter. The most dramatic change came from CLDAP Floods, which surged 580% quarter-over-quarter to become the #3 vector in Q2. CLDAP (Connectionless Lightweight Directory Access Protocol) abuses exposed Active Directory LDAP-over-UDP endpoints. Because it runs over UDP, there's no handshake, allowing attackers to spoof source IPs. Small queries sent to publicly reachable domain controllers on UDP port 389 draw responses tens to hundreds of times larger, overwhelming the victim.
Defense at network scale
Cloudflare frames its own infrastructure as the counterweight to these trends. Every service on its network carries free, unmetered DDoS protection running across 330+ cities with 500 Tbps of capacity. Mitigation operates without human intervention, which the report argues is essential given attacks above 1 Tbps now arrive at a pace measured in hundreds per quarter.
The company also points to its free DDoS Botnet Threat Feed for Service Providers, which lets hosting providers, cloud platforms, and ISPs identify and take down abusive IP addresses and accounts. Over 800 networks have signed up for the feed, and Cloudflare reports community collaboration on botnet node takedowns.



