BLOG

DDoS attacks in 2026: what does the latest Cloudflare report show?

nullnull
14/08/2026
null

TL;DR: Cloudflare's report for the first half of 2026 shows that DDoS is becoming a widespread threat that is increasingly fast and difficult to predict. Over the six-month period, Cloudflare mitigated 23.2 million network-layer attacks, while the number of attacks exceeding 1 Tbps increased by 519% quarter over quarter in Q2. At the same time, attacks targeting DNS and using reflection and amplification techniques are playing an increasingly important role. The data also shows a strong link between DDoS activity and geopolitical events – an organization's risk profile can change practically overnight. The takeaway? Effective DDoS protection should operate continuously and automatically, covering not only applications but also the network and DNS layers.

Cloudflare has just published the 25th edition of its DDoS Threat Reportthe first under its new semi-annual format, covering data from January through June 2026.

The report, prepared by the Cloudforce One team based on telemetry from Cloudflare's network (which protects more than 20% of Internet traffic), paints a picture of a threat landscape that is evolving faster than many of us would have predicted just a year ago. As a company that deploys and manages Cloudflare solutions for its customers, we decided to take a closer look at the report.

DDoS at massive scale: more than 5,000 attacks per hour

Right from the start, the report presents figures that demonstrate just how dramatically the scale of DDoS threats has changed. In the first half of 2026, Cloudflare mitigated 23.2 million L3/L4 attacks and 29.64 trillion HTTP requests associated with DDoS attacks. In practice, this translates into an average of more than 5,300 network-layer attacks per hour and around 128,000 every day.

The highest level of activity was recorded in April. In a single month, Cloudflare blocked 6.46 trillion DDoS-related requests and 165 petabytes of malicious traffic. Attack volumes began to decline in the following months. One factor that may have contributed to this trend was Operation PowerOFF – an international law enforcement operation targeting DDoS-for-hire services operating across 21 countries.

null

The key takeaway from these figures is the sheer frequency of attacks. DDoS is no longer an occasional incident that mobilizes an entire security team once in a while. With tens of thousands of attacks occurring every day, it has become a threat that Internet infrastructure must be able to handle continuously.

Attacks exceeding 1 Tbps are becoming increasingly common

One of the most concerning trends described in the report is the rapid growth of hyper-volumetric attacks, i.e. DDoS attacks exceeding 1 Tbps, 1 billion packets per second, or 1 million HTTP requests per second. These attacks generate such enormous volumes of traffic in a very short period of time that they can exhaust available infrastructure resources and make services unavailable.

Cloudflare's data shows that such events are no longer rare. In the first half of 2026, the company mitigated 935 network-layer attacks exceeding 1 Tbps. As many as 805 of them occurred in the second quarter. This represents a 519% quarter-over-quarter increase – more than six times the number recorded in Q1.

null

What matters here is not only the scale of individual attacks, but also how frequently they occur. Attacks that could until recently be considered extreme cases are now occurring hundreds of times per quarter. This is also changing the risk profile: organizations must be prepared not only for higher traffic volumes, but also for attacks that can reach enormous scale almost instantly.

With hyper-volumetric attacks, response time is critical. If protection depends on manual incident detection, analysis, and mitigation, infrastructure may become overwhelmed before the security team has time to respond. This is why continuous and automated protection is becoming increasingly important – it must be capable of detecting and filtering malicious traffic without waiting for human intervention.

DNS is increasingly becoming a target

The report also reveals a clear shift in how DDoS attacks are carried out. Attacks targeting DNS and using reflection and amplification mechanisms are playing an increasingly significant role.

null

Why does this matter? DNS is one of the fundamental components of Internet services. If DNS infrastructure stops responding, the application itself may still be functioning correctly, but users will be unable to connect to it.

A DNS Flood exploits this dependency by directing an enormous number of queries at the victim's DNS servers in an attempt to exhaust their capacity to handle traffic. DNS Amplification works somewhat differently. The attacker sends small queries to poorly secured, publicly accessible DNS resolvers while spoofing the victim's IP address. The servers then send much larger responses to that address. As a result, third-party infrastructure is used to multiply the volume of traffic directed at the target.

DNS, however, is not the only service exploited in this way. Cloudflare highlights a sharp increase in CLDAP Flood attacks, which use reflection/amplification mechanisms based on Internet-exposed CLDAP services. In Q2, the number of these attacks increased by 580% compared with Q1, making CLDAP the third most commonly observed network-layer attack vector.

This is an important signal for infrastructure and security teams. DDoS protection does not end with the website or application. Lower-layer services and protocols – including DNS and unnecessarily exposed UDP ports – are equally important. Misconfigurations can cause them to become either targets themselves or part of the infrastructure used to launch an attack.

The impact of geopolitics on DDoS risk

DDoS is increasingly becoming a digital reaction to real-world events. A conflict, political decision, or major international event can translate into a surge in attacks almost immediately.

Across both quarters, media, content production, and publishing were the most frequently targeted sectors, accounting for 14.2% of all mitigated HTTP DDoS requests. This was almost four times the share of the next industry in the ranking. Cloudflare links this increased activity, among other factors, to coverage of the conflict with Iran, the war in Ukraine, and major sporting events. Media organizations are attractive targets not necessarily because of the data they hold, but because of their role in providing information – a successful DDoS attack can restrict access to information precisely when public demand for it is at its highest.

This relationship is even more apparent in the public sector. Following the launch of Operation Epic Fury, associated with Israeli and US strikes on Iranian infrastructure, 149 DDoS campaigns targeting 110 organizations across 16 countries were recorded within just 72 hours. Public-sector organizations accounted for nearly 47.8% of the targets. As a result, the sector climbed 20 places in the ranking of the most frequently attacked industries – from 29th place in Q1 to 9th in Q2.

Cloudflare observed a similar pattern in Turkey, which ranked third among the most frequently attacked countries. The increase in DDoS activity coincided with the NATO Summit in Ankara and preceding operations by Turkish security services.

This shows that an organization's DDoS risk profile can change practically overnight. An organization does not need to modify its infrastructure, launch a new service, or make a security mistake to suddenly become a more attractive target. Sometimes, operating in a particular industry or country, having ties to a specific institution, or simply finding yourself at the center of current events is enough.

This is particularly important for media organizations, public administration, critical infrastructure operators, and organizers of major events.

How can you prepare your infrastructure for today's DDoS attacks?

The Cloudflare report shows that DDoS protection must keep pace not only with the growing scale of attacks, but also with changes in how they are carried out. DNS protection is becoming increasingly important. Attacks can develop within seconds, while risk is no longer determined solely by the size of an organization or the industry in which it operates. It can also be influenced by what is happening in the world at any given moment.

From our perspective, there are three key takeaways from the report.

  • First – DDoS protection must operate continuously and automatically. With more than 90% of attacks lasting less than 10 minutes and some ending after just a few dozen seconds, it is unrealistic to assume that a security team will have enough time to manually detect the threat, analyze it, and initiate mitigation. Protection mechanisms should respond automatically, before an attack can affect service availability.

  • SecondDNS now requires just as much attention as the application layer. The growing prevalence of DNS Flood attacks and attacks using reflection and amplification mechanisms shows that securing the application itself or deploying a WAF is only part of the equation. Organizations should also review their DNS configuration, UDP port exposure, and whether their infrastructure is prepared to withstand attempts to overwhelm these components.

  • Third – the DDoS risk profile can change very quickly. Conflicts and political, sporting, or media events can increase attackers' interest in a particular industry, country, or organization within days. This is why DDoS risk should not be assessed only once every few years. Organizations should regularly verify whether their current level of protection still matches their exposure and the evolving threat landscape.

For IT and security teams, this means a fundamental shift in approach: from reacting to DDoS attacks to building infrastructure that is prepared for an attack before it even begins.

If you want to assess how resilient your infrastructure currently is against DDoS attacks – across the DNS, network, and application layers – we can analyze your current configuration and identify areas where Cloudflare solutions can strengthen your protection.

Source: Cloudflare DDoS Threat Report for 2026 H1, Cloudforce One.


Text autors:
null
Tomasz Szóstek , Security Engineer , 4Prime IT Security
Tomasz has specialized in networking and cybersecurity for many years. His main areas of interest include Next Generation Firewall (NGFW) and Web Application Firewall (WAF) technologies. He has experience working with leading IT security vendors such as Fortinet, Palo Alto, F5, Juniper, Cloudflare, Cisco, and Check Point.
null
Natalia Prochowska-Zawisza , Content Manager , 4Prime IT Security
Natalia is a Content Manager at 4Prime IT Security with over 5 years of experience in the IT industry. She specializes in creating expert cybersecurity content, translating complex technological topics into clear and accessible materials for businesses and IT professionals.

Read more

The attack on your company could have started a month ago.

Check how you can secure your organization today.