Cloudflare DDoS report: 1 Tbps attacks jumped in H1 2026

Cloud-edge DDoS defense shield absorbing DNS traffic waves labeled 1 Tbps.

DDoS pressure shifted toward reflection at scale​

Cloudflare's H1 2026 DDoS report describes a larger high-end attack class, not a simple rise in ordinary traffic noise. The company says it mitigated 935 network-layer attacks above 1 Tbps in the first six months of 2026, with most of that count arriving in Q2. DNS and CLDAP reflection also became more prominent, pointing defenders toward exposure management as well as raw capacity.

The 1 Tbps category expanded quickly​

Cloudflare says the number of network-layer DDoS attacks above 1 Tbps rose sharply between Q1 and Q2 2026. Across the first half, it mitigated 935 such attacks, including 805 in the second quarter, which the report describes as a more than six-fold increase over the previous quarter and a 519% quarter-over-quarter surge.

The broader volume was also large. Cloudflare says it mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion HTTP DDoS requests from January through June 2026. That equates to about 5,343 network-layer attacks per hour, or roughly 128,000 per day, on its network.

April was the peak month in the report, reaching 6.46 trillion requests and 165 PB of attack volume. Cloudflare says traffic declined afterward and describes this as a possible reflection of Operation PowerOFF, a 21-country action that targeted DDoS-for-hire users, domains and infrastructure.


DNS and CLDAP moved to the center​

The report says the attack-vector mix shifted from botnet floods toward reflection and amplification. DNS-based attacks accounted for 34.3% of all network-layer DDoS activity in H1 2026, while DNS Floods rose from 25.7% to 40.0% of network-layer attacks quarter-over-quarter.

The operational meaning is straightforward for defenders: critical naming infrastructure remains a practical pressure point. If authoritative DNS capacity is exhausted, services that depend on that domain can become unreachable even when the application servers themselves are still online.

CLDAP Floods also grew fast, with Cloudflare reporting a 580% quarter-over-quarter increase and ranking the vector at number three in Q2. The report frames CLDAP as a reflection and amplification issue tied to exposed directory-service infrastructure, which means basic exposure reduction can matter alongside dedicated DDoS mitigation capacity.


Short attacks still create long disruption​

Cloudflare's data shows that most attacks remained short and relatively small by hyperscale standards. In H1 2026, 96.62% of network-layer attacks were under 500 Mbps, and 90.60% ended in under 10 minutes.

That does not make them harmless. Cloudflare notes that a 100 Mbps attack can overwhelm a server or website, while 100 Gbps can take many unprotected data centers offline. The report also says some record-level assaults can last only seconds, including attacks observed at 35 seconds from start to finish.

The implication is that manual response is too slow for much of this threat model. By the time an alert reaches an analyst, a short burst may already have caused routing instability, retransmissions, application timeouts or downstream service degradation that takes longer to clear than the attack itself.


Media and government targets reflected global events​

Media, Production & Publishing was the most attacked industry in both quarters, according to Cloudflare. The sector accounted for 14.2% of all mitigated HTTP DDoS requests, which the report says was nearly four times the runner-up.

Cloudflare links that pressure to sustained attention around Iran, Ukraine and the World Cup. This is an attribution of timing and target interest, not proof that one actor or motive explains all media-sector activity.

The government sector moved sharply in Q2. Cloudflare says it rose from number 29 to number 9 by share of mitigated HTTP DDoS requests during Operation Epic Fury, after security researchers recorded 149 hacktivist DDoS claims against 110 organizations across 16 countries within 72 hours. Nearly 47.8% of those targeted organizations were government entities, according to the report.


Country patterns shifted on both target and source sides​

Cloudflare says China ended H1 as the most attacked location after absorbing 22.4% of global HTTP DDoS requests in Q2. The United States remained second at 18.8%, indicating that large internet economies stayed attractive targets across the period.

Turkey moved into the number three most-attacked position by Q2 after more than doubling its share of global attack traffic. Cloudflare says the surge coincided with the buildup to the 2026 Ankara NATO Summit in June and early July, including pre-summit raids by Turkish security forces.

The reported source-country ranking also changed. Brazil overtook the United States as the top DDoS source country in H1 2026, at 14.9% versus 13.4%, after a Q2 surge in which Brazil accounted for 21.4% of mitigated DDoS request traffic. Indonesia remained in third place in both quarters.


Conclusion​

Cloudflare's H1 2026 report points to a DDoS environment where scale and speed are converging. The largest attacks are more frequent, but the shorter attacks are also operationally relevant because they can hit before a human-led response can begin.

The clearest defensive takeaway is that capacity alone is not enough. Organizations also need to understand dependency points such as DNS, reduce exposure that can be abused for reflection, and assume that politically visible events can concentrate traffic pressure on media, government and public-facing services.


Sources​


Editorial Team - CoinBotLab
  • Reading time 5 min read
  • Reading time 6 min read
  • Views2
  • Reading time 5 min read
  • Views2
  • Reading time 6 min read
  • Views5
  • Reading time 5 min read
  • Views1
  • Reading time 5 min read
  • Views3

Comments

There are no comments to display

Information

Author
CoinBotLab AI Editor
Published
Reading time
4 min read
Views
3

More by CoinBotLab AI Editor

Top