Cloudflare DDoS Threat Report H1 2026: 1 Tbps Attacks Soar as DNS Floods Dominate
Cloudflare DDoS Threat Report H1 2026: 1 Tbps Attacks Soar
Cloudflare has published its 25th DDoS Threat Report, covering the first half of 2026. The report, produced by Cloudforce One (Cloudflare's Threat Intelligence organization), reveals a shifting DDoS landscape dominated by reflection and amplification attacks, geopolitical targeting, and a dramatic surge in hyper-volumetric assaults.
The 1 Tbps Club Grew Dramatically
Cloudflare mitigated 935 network-layer DDoS attacks exceeding 1 Tbps in the first half of 2026, with a +519% quarter-over-quarter surge between Q1 and Q2. The total volume of mitigated traffic reached 23.2 million network-layer and 29.64 trillion HTTP DDoS requests, averaging approximately 5,343 network-layer attacks per hour — about 128,000 per day.
April 2026 was the peak month, hitting 6.46 trillion requests and 165 petabytes of traffic. To put that in perspective, that volume is equivalent to streaming 4K video continuously for years.
Attack Vectors Shift to Reflection and Amplification
The center of gravity in DDoS attack vectors shifted from botnet floods to reflection and amplification techniques:
- DNS-based attacks accounted for 34.3% of all network-layer activity in H1 2026
- DNS Floods climbed from 25.7% to 40.0% of network-layer attacks quarter-over-quarter
- CLDAP Floods surged +580% QoQ to become the #3 attack vector in Q2
This shift matters because reflection and amplification attacks require fewer botnet resources per attack — they abuse open or misconfigured public services to multiply traffic volume, making them harder to block at the source and more demanding of upstream mitigation capacity.
Geopolitics Drive Targeting
The report highlights how global events shape attack patterns:
- Media, Production & Publishing held the #1 most-attacked industry position in both quarters at 14.2% of all mitigated HTTP DDoS requests, driven by coverage of Iran, Ukraine, and the World Cup.
- Turkey rose to the #3 most-attacked country amid the July NATO Summit in Ankara.
- Government sector jumped from #29 to #9 — the largest single sector movement of 2026 — during Operation Epic Fury.
Law Enforcement Impact
After the April peak, attack volumes declined — a trend Cloudflare partially attributes to Operation PowerOFF, a 21-country law enforcement action that:
- Targeted over 75,000 DDoS-for-hire users
- Took down 53 domains associated with booter and stresser services
- Issued 25 search warrants
- Resulted in four arrests
While this takedown disrupted the DDoS-for-hire ecosystem temporarily, history shows these services tend to re-emerge. Organizations should not rely on law enforcement actions as a substitute for robust DDoS protection.
What Should You Do?
- Layer your defenses. A WAF alone cannot stop large volumetric DDoS attacks. Combine a CDN-based DDoS protection layer (Cloudflare, AWS Shield, Akamai) with your WAF for defense-in-depth.
- Monitor DNS infrastructure. With DNS floods now the #1 attack vector, ensure your DNS provider supports high-capacity anycast resolution and enable DNSSEC where possible.
- Prepare for reflection attacks. Audit your public-facing services (CLDAP, NTP, Memcached, SNMP) for amplification vulnerability. Close unnecessary UDP services and restrict access where possible.
- Review your DDoS response plan. The report shows attacks are getting larger and more frequent. Test your failover procedures, confirm your mitigation provider's capacity, and ensure on-call runbooks are up to date.
- Watch geopolitical events. If your organization operates in or covers regions experiencing political tension (Turkey, Iran, Ukraine), expect elevated attack volume during major events.