Cloudflare published its H1 2026 DDoS Threat Report on August 11, revealing a dramatic escalation in hyper-volumetric attacks (>1 Tbps). The company mitigated 935 network-layer attacks exceeding 1 terabit per second in the first six months of 2026, with a 519% surge between Q1 and Q2 2026. In Q2 alone, Cloudflare mitigated over 805 attacks exceeding 1 Tbps—a more than sixfold increase over Q1. These 'terabit-scale' attacks, previously rare, are now delivered 'at a cadence measured in hundreds per quarter.'
The shift is vector-driven: DNS reflection and CLDAP amplification attacks dominated, accounting for 34.3% of all network-layer activity. Despite the surge in mega-attacks, the median attack remained small and brief: 96.62% of network-layer attacks stayed below 500 Mbps and 90.6% ended in under 10 minutes. April 2026 was the peak month, with 6.46 trillion malicious HTTP requests and 165 petabytes of network-layer traffic. Volumes declined afterward, possibly following Operation PowerOFF, a 21-country law enforcement action that took down 53 booter/stresser domains and led to four arrests.
Geopolitical tensions amplified the threat landscape. Following the February 28 U.S.-Israeli Operation Epic Fury strikes against Iran, DDoS activity spiked within 72 hours. The government sector climbed 20 places in DDoS target rankings (Q1 29th to Q2 9th position by HTTP request share), the largest single-sector movement of 2026. Media, Production, and Publishing held the top target spot at 14% of mitigated traffic.
For operators, this signals that automated, always-on DDoS defense is no longer optional—median attack duration (under 10 minutes) gives no window for manual mitigation. The industrialization of DDoS-for-hire services, AI-assisted attack development, and million-device botnets mean Tbps-scale threats will become the new baseline within 24 months.