Almost 1,000 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tb/s were recorded in the first half of 2026.
This is according to Cloudflare’s latest DDoS Threat Report, which noted geopolitical tensions as driving attacks, along with a shift toward the abuse of exposed internet infrastructure to help multiply and reflect malicious traffic.
Cloudflare reported a 519% quarter-over-quarter (QoQ) increase in the first half of 2026, working out to a massive 5,300 DDoS attacks every hour.
The web giant divides attacks into two camps: domain name system (DNS) floods typically associated with botnets, and reflection and amplification attacks using connectionless lightweight directory access protocol (CDLAP). Attacks of the former rose from 25.7% to 40% of network-layer attacks QoQ, while the latter surged by 580% QoQ to become the third most vulnerable vector in the second quarter.
Reflection and amplification attackers send requests to legitimate third-party servers while spoofing the victim’s IP address. Those servers then send their replies to the victim. If the reply is much larger than the original request, the traffic is amplified in DDoS fashion.
Cloudflare explained that CLDAP uses the connectionless user datagram protocol (UDP) instead of transmission control protocol (TCP).
“[This] makes it faster but less reliable. Because it uses UDP, there’s no handshake requirement, which allows attackers to spoof the source IP address, thus allowing attackers to exploit it as a reflection vector,” Cloudflare noted.
Media under fire
This past April was described as a peak month for DDoS activity and volume, reaching a high of 6.46 trillion requests and 165 petabytes (PB) respectively. A drop-off ensued shortly after, which Cloudflare suggested was down to Operation PowerOFF, a 21-country task force that dismantled DDoS-for-hire networks by seizing 53 domains, executing 25 search warrants, arresting four suspects, and targeting more than 75,000 users to date.
February of this year saw almost 150 hacktivist DDoS claims against 110 distinct organizations across 16 countries in response to strikes from Israel and the U.S. against Iran. Almost half (47.8%) of all targeted organizations globally belonged to the government sector.
War in both Iran and Ukraine saw media, production, and publishing become the most targeted industry in both quarters, accounting for 14.2% of all mitigated HTTP DDoS requests. The World Cup was also blamed for the media’s digital victimization in 2026.
China ended the first half of 2026 as the most attacked location, absorbing 22.4% of all HTTP DDoS requests globally in the second quarter, while Brazil overtook the U.S. as the top DDoS source country in the same period with 14.9% of all attacks.
Cloudflare noted that despite the growth in hyper-volumetric attacks surpassing 1 Tb/s in capacity, 96.6% of network-layer attacks remained under 500 Mb/s, with 90.6% ending in under 10 minutes flat. The firm stressed that “most internet properties wouldn’t be able to withstand even those small attacks.”
“Whether an attack lasts half a minute or 10 minutes, there is no practical window for human intervention: by the time an alert reaches a security analyst, the attack has already completed. … The cascading effects of even a short burst can (take) hours or days to fully resolve – all while services remain down or impaired,” Cloudflare warned.
Comments