The 1 Tbps Surge: Cloudflare Report Reveals New Frontier in Global DDoS Threats

The 1 Tbps Surge: Cloudflare Report Reveals New Frontier in Global DDoS Threats

Key points

  • Cloudflare neutralized over 900 network-layer DDoS attacks exceeding 1 Tbps during the first half of 2026, representing a 519% surge between the first and second quarters 2.
  • DNS-based attacks became a dominant force, with DNS floods alone climbing to 40% of all network-layer attacks in Q2 and CLDAP floods surging by 580% 2.
  • Geopolitical conflicts and major events shaped the threat landscape, keeping the media and publishing sector at the top of the target list and pushing Turkey into the top three most-attacked countries 2.
  • Despite the rise in massive hyper-volumetric assaults, over 90% of mitigated attacks ended in under 10 minutes, proving that speed and automation are critical for defense 2.

An Explosion of Hyper-Volumetric Attacks

The scale of distributed denial-of-service attacks reached unprecedented heights during the first half of 2026, propelled by a dramatic escalation in hyper-volumetric assaults. According to threat intelligence data from Cloudflare, the company mitigated a combined 935 network-layer attacks exceeding 1 terabit per second across the first six months of the year 2. This category of extreme threats saw a massive 519% quarter-over-quarter surge, with the second quarter alone accounting for 805 of these massive attacks – representing a greater than six-fold increase over the preceding period 2.

Overall, Cloudflare handled staggering volumes midway through the year, blocking 23.2 million network-layer attacks and nearly 30 trillion HTTP DDoS requests 2. This relentless barrage averages out to roughly 5,343 network-layer attacks every single hour 2. April emerged as the peak month for sheer volume, absorbing 6.46 trillion requests and 165 petabytes of traffic – an astronomical data load comparable to streaming 4K video continuously for years or processing an entire day’s traffic for major global video platforms 2.

Vectors Shift to DNS and Amplification

Beyond sheer brute-force botnets, the structural mechanics behind these assaults underwent a fundamental evolution. Attackers increasingly moved away from traditional botnet floods, pivoting instead toward reflection and amplification techniques to maximize disruption with minimal infrastructure 2.

DNS-based threats stood out as a primary instrument of choice, accounting for 34.3% of all network-layer activity in the first half of the year 2. Standalone DNS floods surged from 25.7% to capture 40% of network-layer attacks quarter-over-quarter, weaponizing queries to overwhelm authoritative domain servers 2. Meanwhile, Connectionless Lightweight Directory Access Protocol (CLDAP) floods experienced a massive 580% quarterly increase, skyrocketing to become the third most common vector by the second quarter 2. These reflection techniques allow malicious actors to turn open network endpoints into force multipliers, throwing staggering amounts of junk data at unsuspecting targets.

Geopolitics Dictate the Target Board

Global conflicts, high-stakes diplomacy, and international events heavily influenced where threat actors focused their attention. The Media, Production and Publishing sector retained its dubious crown as the most-attacked industry in both quarters, soaking up 14.2% of all mitigated HTTP DDoS requests as coverage surrounding conflicts in Ukraine and Iran, alongside the World Cup, drew sustained hostile interest 2.

Government targets also experienced radical shifts amid shifting geopolitical flashpoints. Following strikes associated with Operation Epic Fury, hacktivist activity spiked globally, propelling the government sector from 29th place in the first quarter up to 9th place in the second quarter by share of mitigated HTTP requests 2. Geographically, China and the United States absorbed the highest shares of global attack traffic, while Turkey climbed to the third most-attacked location against the backdrop of the Ankara NATO Summit 2. Meanwhile, source countries shifted as well, with Brazil overtaking the United States as the leading origin of DDoS request traffic 2.

The Speed and Necessity of Automation

Despite the frightening headlines generated by terabit-scale attacks, the median DDoS assault remained surprisingly short and small in physical duration 2. Statistics show that 90.6% of network-layer attacks concluded in under 10 minutes, and 96.6% stayed under 500 Mbps 2. However, security experts emphasize that ‘small’ is entirely relative; a 100 Mbps assault can easily crash an unprotected website, while a 100 Gbps flood can knock standard data centers completely offline 2.

Furthermore, even the largest hyper-volumetric assaults often last mere seconds – with some record-breaking spikes completing their cycle in just 35 seconds 2. This temporal reality leaves zero window for manual human intervention, as an attack is frequently over by the time an alert reaches a security analyst 2. While the active bombardment may be brief, its downstream aftershocks – such as routing instability, application timeouts, and service degradation – can linger for hours 2. Consequently, security leaders note that automated, always-on mitigation is no longer a luxury, but an absolute baseline requirement for modern digital infrastructure 2.

Primary sources

  1. DDoS attacks over 1 Tbps surged fivefold in the second quarter (bleepingcomputer.com) – Cloudflare reported that it successfully mitigated more than 800 network-layer DDoS attacks exceeding 1 Tbps during the second quarter.
  2. Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave (blog.cloudflare.com) – Cloudflare's H1 2026 Threat Report details a six-fold surge in 1 Tbps attacks, the dominance of DNS and CLDAP amplification vectors, and the heavy influence of geopolitics on targeted industries and regions.

News RankerPowered by News Ranker

Sam Salhi
https://www.linkedin.com/in/samsalhi

Sr. Program Manager @ Nokia | Engineer, Futurist, CX Advocate, and Technologist | MSc, MBA, PMP | Science & Technology Communicator, Consultant, Innovator, and Entrepreneur