Ransom DDoS and ransomware front and center
The second quarter of 2021 saw a string of high-profile ransomware and ransom DDoS campaigns targeting critical infrastructure, from major pipeline operators to meat processors. Earlier in the quarter, more than 200 Belgian organizations, including government and parliament websites, were hit by DDoS attacks. And on July 4, hundreds of US companies — schools, small public bodies, travel firms, and credit unions — were struck by a ransomware attack demanding $70 million in Bitcoin. The attackers, linked to the REvil group, exploited multiple previously unknown vulnerabilities in IT management software.
These incidents moved ransomware and DDoS from background noise to front-page concerns, even landing on the US President's national security agenda. The attack trends observed across Cloudflare's network in Q2 paint a picture consistent with this wider threat landscape.
- Over 11% of surveyed customers targeted by a DDoS attack reported receiving a threat or ransom letter in the first six months of the year. Emergency onboarding of customers under active attack rose 41.8% in H1 2021 compared to H2 2020.
- HTTP DDoS attacks against government and public-sector websites grew 491%, making it the second most targeted industry after Consumer Services, which saw a 684% QoQ increase.
- China remained the top source of DDoS activity — 7 out of every 1,000 HTTP requests originating there were part of an HTTP DDoS attack, and over 3 out of every 100 bytes ingested in Chinese data centers were part of a network-layer attack.
- Amplification attacks abusing the Quote of the Day (QOTD) protocol rose 123% QoQ, and attacks over QUIC surged 109% QoQ as adoption of that protocol grows.
- Network-layer attacks in the 10–100 Gbps range increased 21.4% QoQ. One target, gaming company Hypixel, stayed online with no downtime or performance hits even under an attack campaign exceeding 620 Gbps.
HTTP DDoS attack insights
Application-layer DDoS attacks — specifically HTTP DDoS attacks — aim to overwhelm an HTTP server so it can no longer handle legitimate user requests. Bombarded with more requests than it can process, the server drops legitimate traffic or crashes, causing performance penalties or a denial of service for real users.

Most attacked industries
To normalize the data and avoid bias toward naturally larger data centers, we calculate the "DDoS activity" rate: the percentage of attack traffic out of total traffic (attack plus clean). In Q2 2021, Consumer Services was the most targeted industry, followed by Government Administration and Marketing & Advertising.

Where attacks originate
For HTTP attacks, we examine the source IP address of the client generating the malicious requests — unlike network-layer attacks, source IPs cannot be spoofed here. A high DDoS activity rate in a country indicates large botnets operating from within. China and the US held the top two spots: in China, more than 7 out of every 1,000 HTTP requests were part of an attack, while in the US the figure was nearly 5 in 1,000.

Where targets are located
By cross-referencing attack data with our customers' billing countries — noting that Cloudflare does not charge for attack traffic and has provided unmetered, unlimited DDoS protection since 2017 — we can identify which countries were hit hardest. In Q2 2021, organizations in the US and China were the most targeted by HTTP DDoS attacks. One out of every 200 HTTP requests destined for US-based organizations was part of an attack.

Network-layer attack trends in Q2 2021
Network-layer DDoS attacks target the infrastructure between the user and the service—routers, servers, and the internet link itself—rather than the application running the service. These attacks are typically measured in two ways: bit rate (Gbps) to saturate the link, or packet rate (pps) to overwhelm in-line hardware and session tables.

Attack size distribution
The majority of network-layer attacks in Q2 2021 were small in volume. Over half of all attacks were below 500 Mbps, while nearly 94% of attacks came in at under 50K pps. Although these figures might not make headlines, they are often sufficient to disrupt unprotected internet properties. Many organizations rely on uplinks with capacities below 1 Gbps, so even modest traffic floods can take a public-facing service offline when legitimate traffic shares the same link.
At the higher end, all attacks exceeding 300 Gbps occurred in June. While low-volume attacks dominated, the share of attacks in the 1–10M pps range—just 1% of the total—grew 27.5% quarter-over-quarter, suggesting that larger attacks are becoming more common rather than fading.



The prevalence of small attacks underscores a few strategic realities. Sub-500 Mbps floods may succeed as a smoke test for defense posture or as a warning shot. Attackers using widely available load-testing and automated DDoS tools can fire brief SYN floods and other vectors at a target, observe how the defenses react, and follow up with larger, costlier attacks. In other cases, a small attack precedes an extortion email demanding payment in exchange for not launching a more crippling assault.
Attack duration and vectors
More than 97% of network-layer attacks in Q2 lasted less than one hour. These short bursts are inherently difficult to catch with mitigation services that depend on manual analysis and rerouting—they are often over before an analyst even identifies the suspicious traffic. That makes an always-on, automated defense the only practical protection.

SYN floods and UDP-based attacks remained the dominant vectors. SYN flood attacks abuse the mechanics of the TCP three-way handshake. By sending a stream of initial SYN packets, an attacker forces a router or server to allocate memory for each half-open connection and wait for a final ACK that never arrives. Once the connection table is full, the device can no longer accept legitimate handshakes, causing a denial of service.

Emerging and resurgent threats
Several older attack vectors saw significant quarter-over-quarter growth. Amplification attacks abusing the Quote of the Day (QOTD) service, originally defined in RFC-865 in 1983 and designed for debugging with a 512-character ASCII limit, rose 123%. UDP-based Portmap and Echo amplification attacks increased 107% in the same period. This resurgence suggests attackers are dusting off legacy techniques to probe for protection bypasses.
Attacks involving QUIC also continued their upward trend, increasing 109% quarter-over-quarter. These incidents are typically floods or amplification attacks aimed at non-QUIC traffic where QUIC would normally be expected, hinting that attackers are attempting to exploit QUIC-designated ports and gateways in search of security holes.

Where attacks are observed
Cloudflare's data center in Haiti handled the largest percentage of network-layer attack traffic in Q2, followed by Brunei, where roughly 3 out of every 100 packets were part of an attack, and China.
Attack location data is bucketed by the Cloudflare edge data center that ingested the traffic, not by the source IP address. Because attackers routinely spoof source addresses, inferring origin country from the source IP would be unreliable. Cloudflare's presence in over 200 cities allows for geographically accurate observation of where attack traffic reaches the network.

An interactive map of attack activity by data center country is available on the Radar DDoS Report dashboard.
Ransomware and ransom DDoS: a growing threat
Q2 2021 ended with a notable resurgence of ransom-driven attacks, both ransomware and ransom DDoS (RDDoS). These are distinct threats: ransomware encrypts an organization's systems and demands payment for decryption, typically delivered via phishing emails. RDDoS instead aims to knock services offline until a ransom is paid—without ever requiring access to the internal network. A properly deployed DDoS protection service can effectively neutralize an RDDoS threat.
Groups operating under names such as ‘Fancy Lazarus’, ‘Fancy Bear’, and ‘REvil’ are actively targeting organizations across finance, transportation, energy, consumer goods, education, and healthcare. Before the actual ransom demand, attackers commonly send a short demonstration attack—often a UDP flood lasting 30 to 120 minutes—to show they mean business.
The ransom note is usually sent to publicly available company email aliases like support@ or legal@ and frequently lands in spam folders. In some reported cases, employees dismissed the note as spam, which delayed the response and worsened the impact on the organization's online services.
For organizations that receive such a threat, the recommended response is to avoid panic, avoid paying the ransom since it funds further criminal activity, and contact local law enforcement with a copy of the letter and any relevant logs. Most importantly, activating a cloud-based DDoS protection service with automated mitigation can be done rapidly when a threat is active, reducing risk and easing operational pressure.
Hypixel rides out a sustained multi-vector campaign
Cloudflare's Q2 also saw heavy use of its Magic Transit service, as both new and existing customers looked for help after receiving ransom letters or while under active attack. One high-profile case was Hypixel Inc., the studio behind the largest Minecraft minigame server. With over 24 million unique logins and a world record of more than 216,000 concurrent PC players, the company's business depends directly on uptime and low latency; any noticeable lag risks driving players elsewhere.
When Hypixel came under a massive DDoS attack campaign, it extended its existing Cloudflare setup with Magic Transit, the company's BGP-based protection for network infrastructure. Onboarding was completed overnight. Cloudflare's systems automatically detected and mitigated the attacks, several of which exceeded 620 Gbps. The traffic was mostly TCP floods and UDP amplification attacks; the graph below shows the multiple detection and mitigation systems that cooperated to handle the multi-vector traffic.

Even as the attack patterns shifted in real time, Magic Transit kept Hypixel's network shielded. Because clean traffic continued to route over Cloudflare's low-latency network, gamers saw no change in experience during the active volumetric attacks.
Across the entire campaign, Cloudflare automatically detected and mitigated more than 5,000 DDoS attacks. The breakdown: 53% ACK floods, 39% UDP-based attacks, and 8% SYN floods.

"We had several attacks of well over 620 Gbps with no impact at all on our players. Their gaming experience remained uninterrupted and fast, thanks to Cloudflare Magic Transit." — Simon Collins-Laflamme, CEO, Hypixel Inc.
Hypixel's relationship with Cloudflare started with Spectrum for gaming infrastructure protection. As the user base grew, the studio adopted more products to harden its critical systems. It now runs on CDN, Rate Limiting, Spectrum, Argo Smart Routing, and Load Balancing, combining performance and security for its real-time player base.
Beyond DDoS: integrated protection
DDoS is one piece of a larger threat landscape. As organizations move toward Zero Trust architectures, network and security buyers face growing risks around network access, plus a continued rise in bot-related and ransomware attacks.
Cloudflare's product design centers on integration. Cloudflare One applies a Zero Trust security model to protect devices, data, and applications, and it is built on the same platform as the company's DDoS and security products. The company's integrated stack has also received industry recognition:
- DDoS: Leader in Forrester Wave™ for DDoS Mitigation Solutions, Q1 2021
- WAF: Challenger in the 2020 Gartner Magic Quadrant for Web Application Firewall, with the highest placement in "Ability to Execute"
- Zero Trust: Leader in the Omdia Market Radar: Zero-Trust Access Report, 2020
- Web protection: Innovation leader in the Global Holistic Web Protection Market for 2020 by Frost & Sullivan
Cloudflare's global network is positioned to deliver DDoS protection alongside security, performance, and reliability services at scale, with low latency and automated mitigation.



