Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave
Cloudflare’s H1 2026 DDoS Threat Report documents a surge in attacks, including 805 exceeding 1 Tbps, amid geopolitical tensions and DNS-based assaults, while automated mitigation remains essential.
Cloudflare’s mid-year DDoS Threat Report, covering January to June 2026, reports 23.2 million network-layer and 29.64 trillion HTTP DDoS requests mitigated, averaging 5,343 network-layer attacks hourly. April 2026 saw peak activity with 6.46 trillion requests and 165 petabytes of traffic, though volumes declined following a 21-country crackdown on DDoS-for-hire services that dismantled 53 domains and led to four arrests.
Hyper-volumetric attacks over 1 Tbps rose six-fold in Q2 2026, yet 96.62% of network-layer attacks remained under 500 Mbps and 90.60% lasted under 10 minutes. Attackers often combine high packet rates with low bandwidth to exploit network gear weaknesses, while even brief assaults can trigger prolonged service degradation, underscoring the need for automated, always-on protection.
Geopolitical events amplified DDoS activity, including Operation Epic Fury in February 2026, which prompted 149 hacktivist claims against 110 organizations across 16 countries, with 47.8% targeting government sectors. The Media, Production & Publishing industry bore the brunt, accounting for 14.2% of mitigated HTTP DDoS requests, nearly four times the runner-up.
DNS-based attacks, including DNS Flood and DNS Amplification, comprised 34.3% of network-layer assaults, while CLDAP Flood attacks grew 580% quarter-over-quarter. Cloudflare’s global network, with 500 Tbps capacity and free unmetered DDoS protection, mitigates attacks without human intervention, supported by a free DDoS Botnet Threat Feed used by over 800 networks to identify and disrupt abusive sources.