DDoS Attacks Reach Record-Breaking Scales as 1 Tbps+ Campaigns Grow Common in 2023
DDoS attacks reached unprecedented levels during the first half of 2026, with hyper-volumetric campaigns exceeding 1 Tbps becoming increasingly prevalent.
Key Findings from Cloudflare’s H1 2026 DDoS Threat Report
Cloudflare’s H1 2026 DDoS Threat Report highlights a shift in attack strategies, characterized by larger traffic volumes, shorter durations, and heightened automation. The report underscores the growing reliance on multi-vector approaches, combining network-layer and application-layer techniques to disrupt critical online services across industries.
Network-Layer Attacks Dominate
Hyper-Volumetric Campaigns
Network-layer attacks remained dominant, with hyper-volumetric campaigns generating terabits-per-second traffic surges. Cloudflare documented a marked rise in attacks surpassing 1 Tbps, reflecting the expanding scale of coordinated disruptions.
April 2026 Peak Activity
The company noted that April 2026 recorded a peak in activity, with 6.46 trillion requests and 165 petabytes of traffic processed. Despite the surge in volume, the median attack size mitigated by Cloudflare stayed relatively low, with 96.62% of network-layer attacks under 500 Mbps and 90.60% lasting less than 10 minutes.
Application-Layer Attacks Pose Persistent Risks
Application-layer attacks continued to pose significant risks, leveraging HTTP flood methods to overwhelm websites and APIs. Attackers increasingly integrated HTTP floods with network-layer techniques, enabling dynamic shifts in attack vectors to evade detection and complicate mitigation. This multi-layered approach intensified pressure on defensive systems, increasing the likelihood of service outages.
Geographic and Sectoral Trends
Government Entities Under Attack
Government entities faced a sharp rise in HTTP DDoS attacks during Q2 2026, coinciding with Operation Epic Fury. During this period, security researchers documented 149 hacktivist DDoS claims targeting 110 organizations across 16 countries within 72 hours. Nearly half of the affected entities belonged to the public sector.
Media and Production Industries Targeted
The media and production publishing industries were the most targeted, accounting for 14.2% of all mitigated HTTP DDoS requests—nearly four times the share of the second-highest sector.
Geographic Distribution
China emerged as the primary target, accounting for 22.4% of mitigated HTTP DDoS requests in Q2. The United States followed with 18.8%, while Turkey saw its attack traffic more than double, aligning with preparations for the 2026 Ankara NATO summit. Brazil surpassed the United States as the leading source of DDoS attacks, contributing 14.9% of mitigated traffic compared to 13.4% for the U.S.
Emerging Attack Vectors
DNS-Based Attacks
DNS-based attacks remained the most common network-layer vector, with DNS Flood and DNS Amplification accounting for 34.3% of all network-layer incidents. CLDAP Flood attacks experienced a 580% quarterly increase, becoming the third most frequent network-layer technique. These attacks exploit exposed LDAP-over-UDP services to amplify traffic and overwhelm targets.
Threat Landscape Evolution
The report underscores the evolving threat landscape, where automation and resource-sharing among threat actors are reshaping DDoS attack dynamics. Continuous monitoring and adaptive defense mechanisms are critical to mitigating the growing complexity of these campaigns.
According to Cloudflare’s H1 2026 DDoS Threat Report, the proliferation of DDoS-for-hire platforms, compromised IoT devices, and automated tools further lowered the barriers for launching large-scale attacks, allowing threat actors to exploit existing infrastructure without building their own.
