News

Cloudflare H1 2026 DDoS Report: 1 Tbps Attacks Surge as DNS Floods Take Over

Cloudflare's H1 2026 DDoS report reveals a 519% QoQ surge in 1 Tbps attacks, DNS floods now 40% of network-layer attacks, and geopolitical events driving targeted campaigns. Automated mitigation is no longer optional.

August 11, 2026· 3 min read· Source: Cloudflare Blog
Cloudflare H1 2026 DDoS Report: 1 Tbps Attacks Surge as DNS Floods Take Over

Cloudflare's 25th DDoS Threat Report, covering H1 2026, shows a threat landscape that has shifted dramatically. The headline: 1 Tbps attacks are no longer rare. Cloudflare mitigated 935 network-layer attacks exceeding 1 Tbps in the first half of 2026, with a 519% quarter-over-quarter surge between Q1 and Q2. Hyper-volumetric attacks—defined as exceeding 1 Tbps, 1 Bpps, or 1 Mrps—saw a more than six-fold increase in Q2 alone.

Attack vectors: DNS floods and reflection dominate

The center of gravity has moved from botnet floods to reflection and amplification. DNS-based attacks accounted for 34.3% of all network-layer activity in H1 2026. DNS Floods alone climbed from 25.7% to 40.0% of network-layer attacks quarter-over-quarter. CLDAP Floods surged 580% QoQ to become the #3 vector in Q2.

This shift matters because reflection attacks are harder to attribute and often require less botnet infrastructure. Attackers are exploiting misconfigured DNS servers and CLDAP services to amplify their traffic, making even small botnets capable of launching massive floods.

Geopolitics drives targeting

Geopolitical events are shaping attack patterns. Media, Production & Publishing remained the most-attacked industry at 14.2% of all mitigated HTTP DDoS requests, driven by coverage of Iran, Ukraine, and the World Cup. Turkey rose to the #3 most-attacked country ahead of the July NATO Summit in Ankara. The Government sector jumped from #29 to #9—the largest single sector movement of 2026—during Operation Epic Fury.

The numbers: 5,300 attacks per hour

Cloudflare mitigated 23.2 million network-layer and 29.64 trillion HTTP DDoS requests in H1 2026—about 5,343 network-layer attacks per hour, or 128,000 per day. April was the peak month, hitting 6.46 trillion requests and 165 PB of traffic. The subsequent decline may reflect Operation PowerOFF, a 21-country law enforcement action that targeted over 75,000 DDoS-for-hire users and resulted in four arrests.

Low and slow: the median attack is still small

Despite the hyper-volumetric growth, 96.62% of network-layer attacks stayed under 500 Mbps, and 90.60% ended in under 10 minutes. But 'small' is relative: a 100 Mbps attack can overwhelm a server, and 100 Gbps can knock most unprotected data centers offline.

Attackers often mix layers—high packet rates with low bandwidth, or vice versa—to exploit different weaknesses. Most attacks are short-lived; some record-breaking assaults last only 35 seconds. There is no window for human intervention. By the time an alert reaches an analyst, the attack is over. The cascading effects—routing instability, TCP retransmissions, application timeouts—can take hours or days to resolve.

Automated, always-on protection is no longer a convenience; it's a necessity.

By the time an alert reaches a security analyst, the attack has already completed. Manual mitigation and on-demand solutions are simply too slow for this reality.
Manul X Editorial
H1 2026 DDoS Attack Vectors: Q1 vs Q2
At a glance
VectorQ1 ShareQ2 ShareChange
DNS Floods25.7%40.0%+14.3 pts
CLDAP FloodsLow#3 vector+580% QoQ
Other network-layerDeclined