Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps during the second quarter of 2026, marking a dramatic increase in extremely large attacks compared with the previous quarter.

The company recorded just 130 attacks above 1 Tbps in the first quarter, meaning the latest figure represents an increase of more than five times, or 519% quarter over quarter.

Cloudflare is a major internet infrastructure and security provider offering services including content delivery, DNS, reverse proxy, and DDoS protection. Its network sits between attackers and their targets, allowing the company to detect and absorb large-scale attacks before they reach customer systems.

The increase comes after Cloudflare recently reported mitigating a record-breaking DDoS attack that peaked at 31.4 Tbps and generated 200 million requests per second. The attack was attributed to the Aisuru, also known as Kimwolf, botnet.

According to Cloudflare’s latest report, the company mitigated 23.2 million network-layer DDoS attacks during the first half of 2026, along with 29.64 trillion malicious HTTP requests.

The growth was not limited to attacks exceeding 1 Tbps. Attacks between 500 Gbps and 1 Tbps increased by 143% during the second quarter, while attacks ranging from 100 to 500 Gbps grew by 105%.

Despite the sharp increase in massive attacks, Cloudflare said most DDoS incidents remained relatively small and short-lived. About 96.62% of network-layer attacks stayed below 50 Mbps, while 90.6% ended within 10 minutes.

Longer attacks also became slightly more common. The percentage of attacks lasting more than three hours increased from 0.387% in the first quarter to 0.828% in the second quarter.

READ
Google Confirms Blogger Bug Behind Mass Malware False Positives, Restoration Underway

Overall network-layer DDoS activity increased from 10.04 million attacks in Q1 to 13.17 million in Q2, representing a 31.2% increase. Malicious HTTP request activity also rose from 12.75 trillion to 16.89 trillion, an increase of 32.4%.

Cloudflare said DDoS activity reached its highest point in April, when it recorded 6.46 trillion HTTP DDoS requests and 165 petabytes of network-layer attack traffic.

Activity declined noticeably after April, which Cloudflare tentatively linked to the international Operation PowerOFF crackdown targeting DDoS-for-hire services. The operation resulted in four arrests, the seizure of 53 domains, and warnings being sent to approximately 75,000 users of the services.

Cloudflare also observed changes in the techniques being used by attackers during the second quarter, with more attacks relying on DNS-based and reflection or amplification methods.

DNS floods accounted for 40% of network-layer DDoS attacks in Q2, up from 25.7% in Q1. DNS floods and DNS amplification attacks together represented 34.3% of network-layer attacks during the first half of the year.

CLDAP flood attacks saw an especially sharp increase, rising 881.9% quarter over quarter, while UDP floods ranked as the second most common attack type in Q2, accounting for 14.06% of attacks.

The media, production, and publishing sector received the largest share of Cloudflare’s mitigated HTTP DDoS requests during the first half of 2026, accounting for 14.2% of the total.


Buy ExpressVPN with PayPal or Credit Card

Government organizations also experienced a notable increase in DDoS activity. Cloudflare linked the rise partly to geopolitical developments and increased hacktivist activity surrounding the U.S.-Israeli military operation against Iran.

READ
FBI Warns Cybercriminals Are Stealing Intimate Photos From Online Accounts

Advertisement