Cloudflare mitigated 935 DDoS attacks exceeding 1 Tbps in the first half of 2026. The number of extremely severe attacks rose rapidly, particularly in the second quarter. At the same time, attackers are shifting toward DNS and amplification techniques.
In the second quarter, Cloudflare recorded 805 network-level DDoS attacks that exceeded the 1 Tbps threshold. That is more than six times as many as in the first three months of the year. Quarterly growth amounted to 519 percent.
The growth is not limited to the most severe attacks. According to BleepingComputer, the number of attacks between 500 Gbps and 1 Tbps increased by 143 percent. In the 100–500 Gbps range, the increase was 105 percent.
Over the entire first half of the year, Cloudflare blocked 23.2 million network-level DDoS attacks. The number rose from 10.04 million in the first quarter to 13.17 million in the second, a 31.2 percent increase. At the same time, the number of malicious HTTP requests increased by 32.4 percent, from 12.75 trillion to 16.89 trillion.
A recent record-breaking attack that Cloudflare thwarted demonstrated that the upper limit is also rising rapidly. This attack, originating from the Aisuru/Kimwolf botnet, peaked at 31.4 Tbps and 200 million requests per second.
DNS increasingly used as a weapon
Not only the scale but also the nature of the attacks is changing. DNS-related attacks accounted for 34.3 percent of all network-level attacks in the first half of the year. The share of DNS floods rose from 25.7 to 40 percent between the first and second quarters.
CLDAP floods were also on the rise. In these attacks, publicly accessible systems are exploited to convert relatively small requests into much larger volumes of traffic directed at the victim. Cloudflare saw this attack method grow by 580 percent in a single quarter, making CLDAP the third-most-used attack vector in the second quarter.
Despite the rise of attacks exceeding 1 Tbps, most DDoS attacks are much smaller. Of the network-level attacks, 96.62 percent remained below 500 Mbps. Over 90 percent lasted less than ten minutes. According to Cloudflare, it is precisely this short duration that makes manual intervention largely ineffective, an attack may be over before an administrator can respond.
Geopolitics reflected in targets
International conflicts are also reflected in the figures. Media, manufacturing, and publishing companies were the most targeted sector in both quarters. They accounted for 14.2 percent of all HTTP DDoS requests blocked by Cloudflare.
The most significant shift occurred among government entities. The sector climbed from 29th place in the first quarter to ninth place in the second quarter. Cloudflare links this to Operation Epic Fury, the U.S.-Israeli attacks on Iran. According to security researchers cited in the report, in the first 72 hours following the attacks, hacktivists claimed responsibility for 149 DDoS attacks against 110 organizations in 16 countries.
China was the most targeted country in the second quarter, accounting for 22.4 percent of global HTTP DDoS traffic, followed by the United States with 18.8 percent. Turkey rose to third place. On the other side of the attacks, Brazil emerged as the primary source: over the first half of the year, 14.9 percent of the DDoS request traffic blocked by Cloudflare originated from that country.