1 Tbps DDoS Attacks Become the New Normal as Cloudflare Reports Record H1 Activity

August 13, 2026

Cloudflare has reported a sharp rise in large-scale distributed denial-of-service attacks during the first half of 2026, blocking 935 network-layer attacks exceeding 1 terabit per second.

The company said hyper-volumetric attacks grew 519% between the first and second quarters, showing that attackers are increasingly capable of delivering extreme traffic floods at a rapid pace.

The findings appear in Cloudflare’s 25th DDoS Threat Report, which combines data from January through June 2026. Unlike previous reports that covered each quarter separately, this edition provides a half-year view of attacks observed and mitigated across the Cloudflare network.

During the period, Cloudflare mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion HTTP DDoS requests. This amounts to roughly 5,343 network-layer attacks per hour, or about 128,000 per day.

Cloudflare Blocks 935 DDoS Attacks Over 1 Tbps

The figures show that DDoS activity remains a constant operational threat for organizations operating public-facing infrastructure. Hyper-volumetric DDoS attacks are defined as attacks exceeding 1 Tbps, 1 billion packets per second, or 1 million requests per second.

Hyper-volumetric attacks (Source : cloudflare )
Hyper-volumetric attacks (Source: Cloudflare)

Cloudflare mitigated 805 attacks above 1 Tbps during the second quarter alone. These attacks can overwhelm internet connections, network equipment, and data centers before security teams have time to investigate alerts or manually activate mitigation controls.

Despite the growth of record-scale attacks, most DDoS incidents were smaller and shorter. Cloudflare said 96.62% of network-layer attacks stayed below 500 Mbps, while 90.60% ended in less than 10 minutes.

April 2026 was a peak month for DDoS activity and volume (Source : cloudflare )
April 2026 was a peak month for DDoS activity and volume (Source: Cloudflare)

However, even a 100 Mbps flood can disrupt an unprotected website or server. A short attack can also cause longer service problems, including routing instability, TCP retransmissions, application timeouts, and degraded downstream services.

The main attack vectors also changed significantly. DNS-based attacks represented 34.3% of all network-layer DDoS activity during the first half of the year. DNS floods increased from 25.7% of attacks in the first quarter to 40.0% in the second quarter.

Attackers use DNS floods to exhaust the query capacity of authoritative DNS servers, potentially making domains and related online services inaccessible.

CLDAP floods also grew 580% quarter over quarter, becoming the third-most-common network-layer attack vector in the second quarter.

Top attack source countries (Source : cloudflare )
Top attack source countries (Source: Cloudflare)

This technique abuses exposed LDAP-over-UDP services, often on UDP port 389, to reflect amplified traffic at victims using spoofed source addresses.

Geopolitical events continued to influence targeting patterns. Media, Production and Publishing was the most attacked industry in both quarters, receiving 14.2% of all mitigated HTTP DDoS requests. Cloudflare linked sustained pressure on the sector to coverage of events involving Iran, Ukraine, and the World Cup.

Government organizations also saw a major shift. The sector moved from 29th place in the first quarter to ninth place in the second quarter during Operation Epic Fury.

Meanwhile, China ranked as the most attacked location in the second quarter, followed by the United States and Turkey. Cloudflare said automated, always-on protection is essential because modern DDoS attacks can begin, peak, and end within seconds.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Original article can be found here