DDoS threat landscape in 2024 Q2
Cloudflare's 18th quarterly DDoS threat report analyzes attack activity observed across its network, which spans over 320 cities and serves roughly 19% of all websites. The key findings for the second quarter of 2024 show a sustained rise in attack volumes, shifts in attacker behavior, and a notable increase in reported ransom attacks.
Attack volumes rise 20% year over year
Cloudflare mitigated 4 million DDoS attacks in Q2 2024—an 11% decrease from Q1 but a 20% increase compared to the same period in 2023. In the first half of 2024, the total reached 8.5 million attacks, already 60% of the 14 million attacks mitigated during the entire year of 2023.

During Q2, Cloudflare blocked 10.2 trillion HTTP requests and 57 petabytes of network-layer attack traffic before it reached customer origin servers.

The composition of these 4 million attacks was split between 2.2 million network-layer attacks and 1.8 million HTTP attacks. However, the HTTP figure has been normalized to account for an explosion in sophisticated, randomized attack patterns. Cloudflare's automated mitigation systems generate real-time fingerprints for each attack, and the randomized nature of these assaults meant that a single attack could generate many fingerprints. In practice, the system produced closer to 19 million fingerprints—over ten times the normalized figure—stemming from a handful of detection rules that successfully stopped the attacks but inflated the raw counts.

This ten-fold discrepancy highlights a dramatic shift in the threat landscape. Capabilities once associated with state-sponsored actors are now accessible to common cyber criminals, coinciding with the rise of generative AI and autopilot systems that enable faster and more sophisticated code development.
Ransom DDoS reports hit 12-month high
The percentage of attacked customers reporting threats or actual ransom DDoS attacks reached 16% in May 2024, the highest level in the past 12 months. The quarter began at 7% in April, spiked to 16% in May, and dipped slightly to 14% in June.

Looking at the broader trend, ransom DDoS attacks have increased quarter over quarter over the past year. In Q2 2024, 12.3% of attacked customers reported being threatened or extorted, up from 10.2% in the previous quarter and roughly on par with the 12.0% recorded a year earlier.

Who is behind the attacks
Most victims are in the dark about their attackers. Among Cloudflare customers targeted by HTTP DDoS attacks, 75% reported not knowing who attacked them or why.
Of those who believed they knew the source, 59% identified a competitor, 21% a disgruntled customer or user, and 17% state-level or state-sponsored threat actors. The remaining 3% classified the attack as self-inflicted.

Geographic and industry targets
China ranked as the most attacked country in Q2 2024, considering both HTTP and network-layer attacks, total volume, and attack traffic as a share of overall traffic. Turkey placed second, followed by Singapore, Hong Kong, Russia, Brazil, and Thailand, with the remaining top-15 positions shown in the chart below.

Among industries, Information Technology & Services was the most targeted for DDoS activity overall. Telecommunications, Services Providers and Carrier followed in second, with Consumer Goods in third.

When isolating HTTP DDoS attacks, the ranking shifts. Gaming and Gambling saw the highest HTTP attack request volume, with regional breakdowns provided below.

Attack sources and characteristics
Argentina was the largest source of DDoS attacks in Q2 2024, followed by Indonesia and the Netherlands. Collectively, TCP-based attacks—including SYN floods and RST floods—accounted for 38% of all network-layer attacks.

Network-layer vectors
DNS-based attacks remained the most common vector, comprising a combined 37% share for DNS floods and DNS amplification, despite a 49% quarter-over-quarter decrease. SYN floods followed at 23%, with RST floods representing just over 10%.

HTTP attack vectors
Half of all HTTP DDoS attacks in Q2 were mitigated using proprietary heuristics that targeted botnets known to Cloudflare. An additional 29% involved fake user agents, browser impersonation, or headless browsers. Another 13% had suspicious HTTP attributes that triggered automated systems, and 7% were classified as generic floods. These categories are not mutually exclusive—known botnets often combine multiple techniques—but they represent a first attempt at classifying HTTP attack vectors.

HTTP/2 dominated attack traffic, comprising 76% of HTTP DDoS requests, while HTTP/1.1 accounted for nearly 22%. By comparison, HTTP/3 was used in only 0.86% of attacks, despite representing roughly one-fifth of all legitimate web traffic.

Attack duration and size
Most attacks are brief. Over 57% of HTTP DDoS attacks and 88% of network-layer attacks end within 10 minutes, underscoring the need for automated inline mitigation. At the other end of the spectrum, approximately a quarter of HTTP attacks lasted over an hour and nearly a fifth persisted for more than a day, while only 1% of network-layer attacks exceeded three hours.


The vast majority of attacks are also relatively small. Over 95% of network-layer attacks remain below 500 Mbps, and 86% stay under 50,000 packets per second. Similarly, 81% of HTTP DDoS attacks remain below 50,000 requests per second—rates that can still overwhelm unprotected websites despite being modest at Cloudflare's scale.


Large volumetric attacks are nonetheless becoming more frequent. One in 100 network-layer attacks now exceeds 1 million packets per second, and two in 100 exceed 500 Gbps. On the HTTP layer, four in 1,000 attacks exceed 1 million requests per second.
Small attacks carry serious risk
The bulk of DDoS traffic consists of short, low-volume attacks. Their ubiquity makes them easy to dismiss, but they pose a real threat to services that lack well-configured DDoS defenses. Even a brief spike in malicious traffic can take down an application if the infrastructure is not tuned to absorb or filter it. Organizations that treat these small events as background noise often find that a single modest burst is enough to disrupt operations.
Attack code is getting smarter
There is a visible trend toward more sophisticated threat actor techniques. The increased availability of generative AI and developer copilot tools appears to be a contributing factor: they lower the barrier to producing attack code that is adaptive, faster, and harder to mitigates. These enhanced attacks do not just rely on volume; they employ more intelligent methods to evade detection and prolong the impact on targeted systems.
Defense is a resource problem
Even before this recent rise in attack sophistication, many organizations lacked the internal resources or expertise to defend against DDoS threats on their own. Running a 24/7 monitoring and mitigation operation is expensive and requires specialist knowledge. Cloudflare positions its automated mitigation systems as a way to close that resource gap, offering defense in depth that evolves alongside the threat landscape without requiring customers to maintain the underlying infrastructure themselves.



