On Cloudflare's network, the number of mitigated DDoS attacks exceeding 1Tbps surged sharply. In its "DDoS Threat Report H1 2026," covering observations from January through June 2026, the company reported that it mitigated 935 network-layer attacks exceeding 1Tbps during the first half of the year, with 805 of these concentrated in Q2. That's up from 130 in Q1—a 519% increase, or more than a sixfold rise in count.
High-volume attacks themselves aren't new. Cloudflare had already recorded a 31.4Tbps attack in its Q4 2025 report. What's changed this time isn't a single record-breaking peak, but rather how often attacks exceeding the 1Tbps threshold repeated within a quarter. The single largest attack and the repeated occurrence of attacks exceeding 1Tbps need to be read as separate phenomena.
However, this isn't a comprehensive count of all DDoS activity across the internet. It's an aggregation of activity detected and mitigated on Cloudflare's own network, and the attack count refers to unique fingerprints that led to real-time mitigation. Since a single attack or campaign can generate multiple fingerprints, the figure of 935 shouldn't be read as the number of affected organizations or attackers.
805 Attacks Exceeding 1Tbps in Q2 Alone
Cloudflare states that during H1 2026, it mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion HTTP DDoS requests. On average, that works out to roughly 5,343 network-layer attacks per hour, or about 128,000 per day. Within this overall volume, 935 attacks exceeded the 1Tbps bandwidth threshold.
Cloudflare's category of "hyper-volumetric" attacks includes not just those exceeding 1Tbps, but also those exceeding 1Bpps and 1Mrps. However, the figure of 805 isn't the sum of this broader category—it refers specifically to network-layer attacks that exceeded 1Tbps. Mixing in packet rate or HTTP request rate conditions would change what the surge is actually measuring.
The jump from 130 in Q1 to 805 in Q2 isn't about a single high-volume attack being observed once. What Cloudflare's half-year report shows is that the number of mitigation targets exceeding this same bandwidth threshold surged sharply across the quarter. Notably, this is the first time Cloudflare has published a combined H1 report merging Q1 and Q2, rather than its usual quarterly format.
Most Attacks Are Small and Short—But Too Short for Manual Response
Of the network-layer attacks Cloudflare mitigated during H1, 96.62% were under 500Mbps. While the rise in attacks exceeding 1Tbps stands out, the vast majority of attacks by count remain relatively low in bandwidth. Looking only at large-scale attacks, one cannot conclude that the volume of everyday attack processing has also grown massively.
The same holds true for duration. 90.60% of network-layer attacks ended within 10 minutes. When most attacks conclude this quickly, operations that rely on staff reviewing individual alerts before initiating defenses struggle to keep pace. Separate from attack scale, the extent to which detection and mitigation are automated is what determines operational effectiveness.
This doesn't mean all short-duration attacks are harmless. The two figures—under 500Mbps and within 10 minutes—represent distributions of bandwidth and duration, respectively. This aggregate data alone doesn't reveal the damage caused by individual attacks, the resilience of targeted services, or whether attacks occurred simultaneously.
Cloudflare's methodology also has its scope. Under the quarterly report's methodology, counts are based on unique fingerprints that led to mitigation, excluding Advanced TCP/DNS Protection and customer-created rules. Therefore, the figures cited here don't represent every traffic event Cloudflare protected against, nor do they represent the total number of attacks worldwide.
Massive Traffic Concentrated on DNS and CLDAP
Among network-layer attack vectors, DNS-based attacks accounted for 34.3% of the total across H1. DNS Flood, which stood at 25.7% in Q1, rose to 40.0% in Q2, while CLDAP Flood surged 580% quarter-over-quarter to become the third-ranked vector in Q2. Alongside the rise in high-bandwidth attacks, the proportion of attacks leveraging name resolution and UDP-based public services is also shifting.
DNS Flood is a method that sends a massive volume of requests directly to authoritative DNS servers. DNS Amplification, by contrast, sends spoofed-source queries to open resolvers, causing them to return larger responses toward the target. Both use DNS, but attacks that directly generate traffic volume and attacks that amplify third-party responses need to be considered separately.
CLDAP Flood abuses externally reachable LDAP over UDP endpoints. It typically targets UDP port 389, where small spoofed-source queries can trigger responses tens to hundreds of times larger. How organizations restrict their public-facing DNS and UDP services, and where carriers block anomalous traffic sources, isn't something that can be resolved by the targeted organization alone.
The fact that DNS-related attacks accounted for 34.3% doesn't mean non-DNS attacks have disappeared. Still, given that upstream public-facing surfaces like authoritative DNS, open resolvers, and UDP port 389 can serve as amplification points for attacks, preparations to block traffic before it reaches applications remain necessary.
Decline After April's Peak—Effectiveness of Crackdowns Still Unconfirmed
The monthly peak for H1 was April. Cloudflare recorded 6.46 trillion HTTP DDoS requests and 165PB of network-layer attack traffic that month, with both figures declining afterward. While it's confirmed that traffic volume and HTTP request peaks occurred in the same month, the numbers alone don't determine why the decline occurred.
On April 13, an international law enforcement operation targeting DDoS-for-hire services—"Operation PowerOFF"—was carried out. According to Europol, 21 countries participated, sending over 75,000 warning messages to identified users, taking down 53 domains, issuing 25 search warrants, and making 4 arrests. The U.S. Department of Justice named Cloudflare as one of the supporting organizations.
Cloudflare noted the possibility that the decline after April reflects this operation. However, the report doesn't claim that the crackdown caused the decline. This half-year report alone lacks sufficient material to distinguish between attack infrastructure being taken down, attackers relocating, or changes in observation scope. Directly linking law enforcement outcomes to traffic trends would require examining subsequent distribution patterns as well.
Reading the Numbers Shifts the Focus of Countermeasures Upstream
The source and target countries referenced in Cloudflare's report don't directly indicate the location of attackers or victims. Since source IP addresses at the network layer can be spoofed, Cloudflare instead uses the location where its data centers ingested the traffic. On the target side, the country reflects the customer's billing address, which may not match the actual location of the facility under attack.
Given this constraint, the focus of countermeasures should be on the routes attack traffic travels through, rather than country-by-country rankings. As of Q4 2025, Cloudflare reported that over 800 networks had joined its free DDoS Botnet Threat Feed. This feed is a mechanism that passes along IP addresses within a network observed participating in HTTP DDoS attacks to that network's service provider.
Now that attacks exceeding 1Tbps have risen to 805 in Q2 and the ratios of DNS and CLDAP attacks have also shifted, the question becomes whether processing at the mitigation-service level is enough, or whether connectivity providers can correct the sources of attacks originating within their own networks. In Q3, attention will turn to whether the post-April decline continues, and whether the frequency of massive attacks and the rise in DNS-based vectors move in the same direction.
