Cloudflare Reports Record DDoS Attacks Exceeding 1 Tbps in H1 2023
Key Takeaways Cloudflare observed a substantial increase in large-scale DDoS attacks during the first half of 2026, blocking 935 network-layer attacks exceeding 1 Tbps. Hyper-volumetric attacks...
Key Takeaways
- Cloudflare observed a substantial increase in large-scale DDoS attacks during the first half of 2026, blocking 935 network-layer attacks exceeding 1 Tbps.
- Hyper-volumetric attacks surged by 519% between Q1 and Q2 2026, demonstrating attackers’ enhanced capabilities in launching extreme traffic floods.
- The “Media, Production, and Publishing” sector was the most targeted industry, receiving 14.2% of all mitigated HTTP DDoS requests, influenced by ongoing geopolitical events.
- DNS-based and CLDAP floods emerged as prominent attack vectors, with CLDAP floods increasing by 580% quarter-over-quarter.
Cloudflare has documented a significant escalation in the scope and intensity of distributed denial-of-service (DDoS) attacks throughout the first six months of 2026. The cybersecurity firm successfully thwarted 935 network-layer attacks that surpassed the 1 terabit per second (Tbps) threshold, indicating a concerning trend in attacker sophistication.
Table Of Content
According to Cloudflare’s 25th DDoS Threat Report, which consolidates data from January to June 2026, hyper-volumetric attacks witnessed an alarming 519% increase from the first to the second quarter. This surge underscores a growing capacity among threat actors to unleash massive traffic floods with unprecedented speed.
This latest report marks a shift in Cloudflare’s reporting methodology, offering a comprehensive half-year overview of the attacks observed and mitigated across its extensive network, rather than separate quarterly analyses.
Escalation in DDoS Activity
During the reporting period, Cloudflare’s infrastructure mitigated a staggering 23.2 million network-layer DDoS attacks and processed 29.64 trillion HTTP DDoS requests. This translates to an average of approximately 5,343 network-layer attacks every hour, or roughly 128,000 per day.
These figures highlight that DDoS activity remains an persistent operational challenge for any organization maintaining public-facing internet infrastructure. Hyper-volumetric DDoS attacks are specifically defined as those exceeding 1 Tbps, 1 billion packets per second, or 1 million requests per second.
Notably, Cloudflare alone mitigated 805 attacks surpassing 1 Tbps during the second quarter. Such high-volume assaults possess the capability to overwhelm internet connections, network hardware, and data centers almost instantly, often before security teams can even begin investigating alerts or manually activating defensive measures.
Despite the rise in these record-breaking attacks, the majority of DDoS incidents remained smaller in scale and duration. Cloudflare reported that 96.62% of network-layer attacks registered below 500 Mbps, and 90.60% concluded within a mere 10 minutes.
However, even a relatively modest 100 Mbps flood can severely disrupt an unprotected website or server. Furthermore, brief attacks can precipitate lingering service issues, including routing instability, TCP retransmissions, application timeouts, and degraded performance across downstream services.
Evolving Attack Vectors and Geopolitical Influences
The primary attack vectors also underwent significant shifts during the first half of the year. DNS-based attacks accounted for 34.3% of all network-layer DDoS activity. The prevalence of DNS floods escalated from 25.7% of attacks in Q1 to 40.0% in Q2.
Attackers leverage DNS floods to exhaust the query processing capacity of authoritative DNS servers, potentially rendering domains and their associated online services inaccessible to legitimate users.
CLDAP floods also experienced a dramatic increase, surging by 580% quarter-over-quarter, positioning them as the third most common network-layer attack vector in the second quarter. This technique exploits exposed LDAP-over-UDP services, typically on UDP port 389, to reflect and amplify traffic towards targets using spoofed source IP addresses.
Geopolitical events continued to exert a notable influence on targeting patterns. The “Media, Production, and Publishing” sector emerged as the most frequently attacked industry across both quarters, absorbing 14.2% of all mitigated HTTP DDoS requests. Cloudflare linked sustained pressure on the sector to global events, including coverage related to Iran, Ukraine, and the World Cup.
Government organizations also experienced a significant targeting shift, moving from 29th place in Q1 to ninth place in Q2, coinciding with a period referred to as Operation Epic Fury.
Geographically, China was identified as the most targeted location in the second quarter, followed by the United States and Turkey. Cloudflare emphasizes the critical need for automated, always-on protection mechanisms, given that modern DDoS attacks can initiate, peak, and conclude within seconds.
What You Should Do
- Implement robust DDoS mitigation services that offer always-on, automated protection capable of detecting and neutralizing attacks at the network edge.
- Ensure your DNS infrastructure is resilient to DNS flood attacks by utilizing geographically distributed, high-capacity DNS services.
- Regularly audit your network for exposed services, particularly LDAP-over-UDP (port 389), and secure them to prevent their exploitation in reflection/amplification attacks.
- Maintain up-to-date threat intelligence to understand evolving attack vectors and targeting trends relevant to your industry and geopolitical landscape.
- Develop and regularly test an incident response plan specifically for DDoS attacks, ensuring your security teams can react effectively even to rapid-onset, high-volume assaults.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.