Listen to this Post

A New Scale of Internet Disruption
Distributed denial-of-service attacks are no longer simply a nuisance used to knock a website offline for a few minutes. The latest figures from Cloudflare show that the DDoS landscape is rapidly moving toward a new level of scale, automation, and destructive potential.
During the second quarter of 2026, Cloudflare says it mitigated more than 800 network-layer DDoS attacks exceeding 1 Tbps. That is an extraordinary jump from the 130 attacks above 1 Tbps recorded during the first quarter, representing an increase of more than fivefold.
The development is particularly important because attacks at this scale can overwhelm traditional network defenses extremely quickly. A terabit-per-second attack is capable of generating enormous amounts of traffic in a matter of seconds, forcing organizations to rely on upstream mitigation providers, globally distributed infrastructure, and highly automated detection systems.
Cloudflare’s latest statistics, presented alongside its Black Hat security research, reveal a broader story: DDoS attacks are becoming more frequent, larger, more diversified, and increasingly dependent on reflection and amplification techniques.
The Numbers Behind the Warning
Cloudflare reported that it mitigated 23.2 million network-layer DDoS attacks during the first half of 2026, alongside approximately 29.64 trillion malicious HTTP requests.
The second quarter was particularly aggressive.
Network-layer DDoS attacks increased from approximately 10.04 million in Q1 to 13.17 million in Q2, representing a 31.2% increase.
At the HTTP layer, malicious request volume climbed from 12.75 trillion to 16.89 trillion, an increase of approximately 32.4%.
These numbers matter because they demonstrate that the threat is not being driven solely by a handful of enormous attacks. The overall volume of hostile activity is rising at the same time that the most powerful attacks are becoming dramatically larger.
The Explosion of 1 Tbps Attacks
The most striking statistic is the growth in attacks above the 1 Tbps threshold.
Cloudflare recorded just 130 such attacks during Q1 2026. In Q2, the number surpassed 800.
That represents a 519% quarter-over-quarter increase.
The increase was not limited to the largest category. Attacks between 500 Gbps and 1 Tbps increased by 143%, while attacks between 100 Gbps and 500 Gbps grew by 105%.
This creates an important security lesson: organizations should not design their DDoS defenses around historical attack sizes.
The baseline itself is changing.
An attack that would have been considered exceptionally large only a few years ago can increasingly become part of the normal threat landscape.
The 31.4 Tbps Attack Shows What Is Possible
The scale of modern botnets was demonstrated by a record-breaking attack recently mitigated by Cloudflare.
The attack reportedly peaked at approximately 31.4 Tbps and generated around 200 million requests per second. Cloudflare attributed the incident to the Aisuru/Kimwolf botnet.
An attack of this magnitude illustrates why conventional perimeter defenses can become irrelevant when the traffic volume reaches extreme levels.
If malicious traffic reaches an
That is why modern DDoS protection increasingly operates upstream, before malicious traffic reaches the customer’s infrastructure.
Most Attacks Are Still Small
Despite the dramatic headlines surrounding terabit-scale attacks,
The overwhelming majority of network-layer attacks remain relatively small.
Cloudflare reported that 96.62% of network-layer DDoS attacks stayed below 50 Mbps.
Approximately 90.6% of attacks ended within 10 minutes.
This is a crucial distinction.
The DDoS threat landscape contains both extremely short, low-volume attacks and comparatively rare events capable of generating terabits of traffic.
Security teams therefore cannot rely exclusively on defending against gigantic attacks. They also need systems capable of detecting repeated smaller attacks, application-layer abuse, protocol manipulation, and attacks designed to exhaust specific services rather than raw bandwidth.
Long-Running Attacks Are Becoming More Noticeable
Cloudflare also observed a small increase in attacks lasting more than three hours.
The percentage rose from 0.387% in Q1 to 0.828% in Q2 2026.
Although these attacks represent a small fraction of total incidents, the change deserves attention.
A prolonged attack can be more difficult operationally than a short traffic spike because defenders must maintain mitigation, monitoring, incident response, and service availability for an extended period.
Long-running attacks can also be used as distractions.
An attacker may generate sustained DDoS traffic while simultaneously attempting credential attacks, exploiting exposed services, abusing APIs, or probing security controls elsewhere in the environment.
April Became the Peak Month
Cloudflare identified April 2026 as the peak period for overall DDoS activity during the first half of the year.
During that month, the company observed approximately 6.46 trillion HTTP DDoS requests and 165 petabytes of network-layer attack traffic.
The subsequent decline is particularly interesting.
Cloudflare tentatively connected the reduction to Operation PowerOFF, an international law-enforcement effort targeting DDoS-for-hire infrastructure.
The operation reportedly resulted in the arrest of four individuals, the seizure or takedown of 53 domains, and warnings being sent to approximately 75,000 users of such services.
Law Enforcement Can Disrupt the Ecosystem — But Not Eliminate It
The apparent decline following Operation PowerOFF highlights an important reality about DDoS attacks.
DDoS is not only a technical problem.
It is also an economic ecosystem.
DDoS-for-hire services lower the technical barrier required to launch an attack. Someone without the infrastructure or expertise to build a botnet can potentially purchase access to an attack service.
Disrupting those services can therefore reduce attack activity quickly.
But history suggests that disruption does not necessarily mean permanent elimination.
Operators can migrate infrastructure, change domains, create new services, recruit new customers, or move toward decentralized and harder-to-dismantle infrastructure.
The fight against DDoS therefore requires both technical mitigation and sustained law-enforcement pressure.
DNS Attacks Are Becoming a Major Concern
One of the most interesting changes in
DNS floods represented approximately 40% of network-layer DDoS attacks during Q2, compared with 25.7% during Q1.
Cloudflare also reported that DNS floods and DNS amplification together accounted for approximately 34.3% of H1 network-layer attacks.
This shift matters because DNS sits at the heart of modern Internet connectivity.
Disrupt DNS infrastructure and users may struggle to resolve domains even when the underlying applications remain operational.
Attackers therefore do not necessarily need to destroy the application itself. Disrupting the infrastructure responsible for finding that application can be enough.
CLDAP Floods Surge by 881.9%
Another major warning sign was the increase in CLDAP flood attacks, which Cloudflare said grew by approximately 881.9% quarter over quarter.
CLDAP, or Connectionless Lightweight Directory Access Protocol, uses UDP and can be abused in reflection and amplification attacks.
Reflection attacks are particularly attractive to attackers because the victim receives traffic generated indirectly through third-party systems.
Instead of sending every packet directly toward the target, attackers manipulate vulnerable or exposed services so that they respond to the victim.
That can amplify the
UDP Remains a Powerful Attack Vector
UDP floods ranked second among
UDP is attractive to attackers because it is connectionless.
Unlike TCP, UDP does not require the same connection establishment process, allowing attackers to generate enormous volumes of packets without maintaining conventional sessions.
The result can be bandwidth exhaustion, CPU exhaustion, state exhaustion in network devices, or pressure on downstream infrastructure.
HTTP DDoS Remains Enormous
Network-layer attacks receive much of the attention because of their impressive bandwidth numbers, but HTTP DDoS activity is equally important.
Cloudflare recorded 16.89 trillion malicious HTTP requests during Q2 alone.
Application-layer attacks can be particularly dangerous because they may resemble legitimate user behavior.
A single request might not look suspicious.
Millions or billions of requests, however, can consume application servers, databases, API resources, authentication systems, and backend processing capacity.
This is why modern DDoS protection must operate beyond simple packet filtering.
The Media Industry Was the Largest Target
During the first half of 2026, Cloudflare said the Media, Production, and Publishing sector received the largest share of mitigated HTTP DDoS requests, accounting for approximately 14.2%.
The industry is an attractive target for several reasons.
Media organizations operate highly visible websites, streaming services, APIs, publishing platforms, and advertising infrastructure.
Disrupting those systems can generate immediate public impact.
It can also create reputational damage because users often interpret an unavailable website as a failure of the organization itself, even when the actual cause is an external attack.
Government Targets Reflect Geopolitical Tensions
Government organizations also experienced significant increases in DDoS activity.
Cloudflare linked some of this activity to geopolitical developments and heightened hacktivism surrounding international military events.
This demonstrates another transformation in DDoS operations.
DDoS attacks are increasingly being used as political messaging tools.
For hacktivist groups, disrupting a government website can be a relatively inexpensive way to attract media attention, demonstrate capability, or retaliate against geopolitical events.
The objective may not always be permanent destruction.
Sometimes the objective is simply visibility.
DDoS Has Become Part of the Cyberwarfare Playbook
DDoS attacks are now routinely discussed alongside ransomware, data theft, supply-chain compromise, and influence operations.
That is because disruption itself has strategic value.
A government website going offline during a crisis can create uncertainty.
A media platform becoming unavailable during a major event can affect information access.
A financial service suffering repeated outages can damage customer confidence.
The technical simplicity of DDoS does not mean the strategic consequences are simple.
The New Problem: Attack Scale Is Becoming Automated
The biggest lesson from
It is that the infrastructure behind them is becoming increasingly automated.
Botnets can recruit vulnerable Internet-connected devices.
Attack platforms can automate target selection.
DDoS-for-hire services can provide an interface for launching attacks.
Reflection infrastructure can multiply traffic.
Automated mitigation systems must therefore fight automation with automation.
Human analysts remain important, but manually investigating every traffic spike is no longer realistic.
Why Traditional Firewalls Are Not Enough
A conventional firewall may block malicious packets, but a firewall cannot solve every volumetric DDoS scenario.
If the attack consumes the
This is one reason cloud-based and upstream DDoS mitigation services have become so important.
Traffic can be distributed across large networks, filtered closer to the source, and only legitimate traffic forwarded toward the customer’s infrastructure.
Deep Analysis: How Defenders Should Think About DDoS
Layer 1 — Understand the Attack Surface
Security teams should identify every Internet-facing service before an attacker does.
That includes websites, APIs, VPN gateways, DNS servers, mail infrastructure, remote-access systems, cloud endpoints, and forgotten subdomains.
A simple DNS inventory can reveal unexpected exposure:
dig example.com ANY dig example.com NS dig example.com MX
Organizations should also regularly inspect their external attack surface.
Layer 2 — Monitor Traffic Baselines
Defenders need to know what normal traffic looks like.
Useful metrics include:
Requests per second
Packets per second
Bits per second
TCP connection rates
UDP packet rates
HTTP status codes
DNS query volume
Source-country distribution
ASN distribution
Without a baseline, anomaly detection becomes significantly harder.
Layer 3 — Watch for Sudden Protocol Changes
A sudden increase in UDP traffic, DNS queries, or unusual protocol types can indicate an attack.
For example:
tcpdump -nn udp
can help analysts inspect UDP traffic during an incident.
For production environments, however, packet capture should be performed carefully because large-scale captures can themselves consume significant storage and processing resources.
Layer 4 — Inspect DNS Infrastructure
DNS deserves special attention given the dramatic increase in DNS-related attacks.
Defenders should review:
dig example.com dig @8.8.8.8 example.com dig @1.1.1.1 example.com
They should also ensure that authoritative DNS infrastructure is geographically and logically redundant.
Layer 5 — Protect the Application Layer
HTTP DDoS protection should not depend solely on IP blocking.
Defenders should consider:
Rate limiting
Bot detection
WAF rules
Challenge mechanisms
API quotas
Request validation
Authentication throttling
Caching
Origin shielding
The goal is to prevent attackers from converting inexpensive requests into expensive backend operations.
Layer 6 — Protect APIs Separately
Modern applications often expose APIs that can be more computationally expensive than ordinary web pages.
An attacker may therefore target an endpoint that triggers database queries, searches, authentication workflows, or large backend computations.
Rate limiting should be applied according to endpoint sensitivity rather than simply using one global threshold.
Layer 7 — Build Upstream Mitigation
Organizations exposed to volumetric attacks should establish relationships with upstream mitigation providers before an incident.
During a 1 Tbps attack, there is little time to negotiate emergency architecture changes.
Preparation must happen beforehand.
Layer 8 — Test the Incident Response Plan
Security teams should periodically simulate DDoS scenarios.
Questions should include:
Who declares the incident?
Who contacts the ISP?
Who contacts the DDoS provider?
Who communicates with customers?
Who investigates the source?
Who approves emergency firewall changes?
Who monitors recovery?
If these answers are unclear, the organization is not fully prepared.
Layer 9 — Monitor More Than Bandwidth
A DDoS attack may not consume all available bandwidth.
Application-layer attacks can instead exhaust CPU, memory, database connections, API quotas, or worker threads.
Defenders should therefore correlate network telemetry with:
top vmstat iostat ss -s
These commands can provide useful host-level visibility during an incident.
Layer 10 — Look for the Secondary Attack
A DDoS event should never automatically be treated as an isolated event.
Attackers can use disruption as a smokescreen.
Security teams should investigate authentication logs, administrative access, unusual outbound connections, privilege changes, and suspicious endpoint activity while the DDoS is being mitigated.
What Undercode Say:
The 519% Increase Is the Real Warning
The most concerning figure in this report is not the total number of attacks.
It is the 519% increase in attacks above 1 Tbps.
That statistic suggests the upper boundary of DDoS capability is expanding rapidly.
Size and Frequency Are Growing Together
The industry is facing two problems simultaneously.
There are more attacks.
And the largest attacks are becoming substantially larger.
That combination is far more dangerous than either trend individually.
Small Attacks Still Matter
The fact that 96.62% of attacks remain below 50 Mbps should not create false confidence.
Small attacks can still disrupt poorly configured systems.
They can also serve as probes for discovering weaknesses in rate limiting and traffic controls.
Attack Duration Is Not the Only Metric
A ten-minute attack can be devastating if it hits the right service.
A three-hour attack can be devastating because it creates operational fatigue.
Organizations therefore need to evaluate attack impact rather than simply measuring duration.
DNS Has Become a Strategic Target
The rapid growth of DNS attacks is especially significant.
DNS is foundational infrastructure.
If attackers can disrupt name resolution, many downstream services can become inaccessible even when servers themselves remain healthy.
Reflection Remains Attractive
Reflection and amplification allow attackers to multiply the impact of relatively modest infrastructure.
That makes misconfigured or exposed Internet services valuable weapons for criminals.
CLDAP’s Growth Should Not Be Ignored
An 881.9% increase in CLDAP floods is too large to dismiss as statistical noise.
It suggests that attackers are actively adapting their techniques.
Defenders need visibility into protocols that historically received less attention.
Cloud Infrastructure Changes the Equation
Cloud platforms provide enormous scalability, but scalability does not automatically equal DDoS resilience.
A cloud application can still experience cost amplification, API exhaustion, database pressure, and application-level resource exhaustion.
Autoscaling Can Become Expensive
One overlooked DDoS consequence is financial.
If an application automatically scales in response to malicious traffic, the attacker may effectively force the victim to purchase additional computing resources.
Security teams should therefore connect DDoS controls with cloud cost monitoring.
HTTP Attacks Are More Difficult to Identify
A malicious HTTP request can look almost identical to a legitimate request.
This makes application-layer DDoS defense substantially more sophisticated than simple packet filtering.
AI Will Increase Automation
The broader cybersecurity environment is already moving toward agentic automation.
That same trend can benefit attackers.
Automated systems can identify exposed services, test infrastructure, rotate attack methods, and adjust traffic patterns faster than human operators.
Defenders Need Their Own Automation
The answer cannot be manual intervention.
Detection, rate limiting, traffic diversion, threat intelligence enrichment, and mitigation should increasingly be automated.
Geopolitics Will Continue Driving DDoS
Hacktivism is likely to remain an important source of DDoS activity.
Political events can produce sudden waves of attacks against government agencies, media organizations, and critical infrastructure.
Visibility Must Extend Beyond the Network
A company can successfully absorb a 1 Tbps attack and still suffer an outage because its application backend cannot handle the remaining legitimate traffic.
Resilience therefore requires network, application, identity, and infrastructure telemetry.
The Attack Surface Is Bigger Than the Main Website
Organizations should not only protect www.example.com.
They must inventory APIs, subdomains, legacy systems, cloud endpoints, DNS infrastructure, VPN services, and third-party integrations.
DDoS Protection Should Be Designed Before the Incident
Trying to architect a DDoS response during a massive attack is too late.
Organizations should already know how traffic will be routed, filtered, monitored, and restored.
Incident Response Needs Executive Support
DDoS response is not purely a security-team responsibility.
Network engineering, cloud teams, communications, legal teams, executives, and service providers may all become involved.
Law Enforcement Disruption Has Real Value
Operation PowerOFF demonstrates that dismantling attack-for-hire infrastructure can affect the wider ecosystem.
Technical mitigation and law enforcement should therefore be viewed as complementary defenses.
But Criminal Infrastructure Will Adapt
Attackers are unlikely to disappear because several services are removed.
The underground market will probably evolve.
New providers can emerge, infrastructure can migrate, and attackers can shift toward compromised IoT devices or alternative reflection mechanisms.
The Internet Is Becoming More Hostile
The growth of large-scale DDoS attacks is another indication that Internet infrastructure is operating under increasingly aggressive automated pressure.
Organizations should assume hostile traffic is normal.
Resilience Is the Real Objective
Perfect prevention is unrealistic.
The more useful goal is resilience: continue serving legitimate users while malicious traffic is detected, filtered, and absorbed.
Security Teams Should Measure Recovery
Organizations should track how quickly they detect attacks, activate mitigation, restore normal service, and identify secondary activity.
Mean time to recovery can be as important as detection speed.
DDoS Should Be Included in Business Continuity Planning
If an online service is business-critical, DDoS should be included in continuity exercises.
The question is not whether an attack is technically possible.
It is whether the business can continue operating when one occurs.
The Biggest Attacks Are Becoming Normalized
A 1 Tbps attack used to sound extraordinary.
Now hundreds of such attacks can occur within a single quarter.
That shift in perception should influence infrastructure planning.
Network Capacity Alone Is Not Enough
Buying more bandwidth can help, but it does not solve every attack.
Attackers can move higher in the stack and target expensive application operations instead.
Defense Must Be Multi-Layered
Modern DDoS protection should combine upstream filtering, CDN capacity, WAF controls, rate limiting, application optimization, DNS resilience, monitoring, and incident response.
Security Architecture Must Assume Failure
A resilient architecture assumes that some components will become unavailable.
Redundancy, failover, caching, multiple DNS providers, and distributed infrastructure can reduce the impact of an attack.
The Numbers Should Change Security Budgets
Organizations still treating DDoS protection as an optional add-on should reconsider that assumption.
The threat environment is moving too quickly.
The Most Valuable Asset Is Preparedness
The difference between a minor interruption and a major outage may come down to preparation completed months before the attack.
DDoS Is Becoming an Infrastructure Problem
This is no longer merely a cybersecurity problem.
It is a networking, cloud, application, business continuity, and geopolitical problem.
2026 Is Sending a Clear Signal
Cloudflare’s data shows that defenders are entering an era where extreme DDoS attacks are becoming increasingly common.
The organizations that adapt early will have a significant advantage.
✅ More Than 800 Attacks Above 1 Tbps
Cloudflare reported more than 800 network-layer DDoS attacks exceeding 1 Tbps in Q2 2026.
That represents a dramatic increase compared with the 130 attacks above 1 Tbps recorded in Q1.
✅ 519% Quarter-over-Quarter Increase
The reported increase in attacks above 1 Tbps was approximately 519% quarter over quarter.
The figure is consistent with the
✅ 23.2 Million Network-Layer Attacks
Cloudflare reported mitigating approximately 23.2 million network-layer DDoS attacks during the first half of 2026.
This demonstrates that the enormous terabit-scale events represent only a small portion of the broader DDoS landscape.
✅ 16.89 Trillion Malicious HTTP Requests
Cloudflare reported approximately 16.89 trillion malicious HTTP requests during Q2.
The increase from 12.75 trillion in Q1 represents approximately 32.4% growth.
✅ DNS Attacks Increased Sharply
DNS floods accounted for approximately 40% of Q2 network-layer DDoS attacks according to the reported Cloudflare figures.
The shift from 25.7% in Q1 highlights a substantial change in attack composition.
⚠️ Operation PowerOFF Attribution Requires Context
Cloudflare characterized the post-April decline as something it tentatively attributed to Operation PowerOFF.
That means the operation should not automatically be described as the sole cause of the reduction.
Prediction
(+1) Extreme DDoS Attacks Will Become More Common
The rapid increase in attacks exceeding 1 Tbps strongly suggests that extreme volumetric attacks will continue appearing more frequently.
As botnets become larger and automated attack services become more sophisticated, the upper limits of DDoS traffic are likely to continue rising.
(+1) DNS and Amplification Attacks Will Remain Important
The sharp increase in DNS floods and CLDAP floods indicates that reflection and amplification techniques remain attractive to attackers.
Organizations should expect continued experimentation with protocols capable of generating large responses from relatively small requests.
(+1) Cloud-Based Mitigation Will Become Standard
More organizations will likely move toward distributed DDoS mitigation rather than relying exclusively on local firewalls and network appliances.
The economics of defending against multi-terabit attacks increasingly favor large-scale distributed infrastructure.
(-1) Smaller Organizations Will Face Greater Risk
Organizations without upstream DDoS protection may find themselves increasingly vulnerable as attack volumes grow.
For smaller businesses, a single large attack can consume available bandwidth and make traditional perimeter defenses ineffective.
(+1) Automated DDoS Defense Will Become Essential
Security teams will increasingly rely on automated detection, traffic classification, rate limiting, dynamic filtering, and intelligent traffic routing.
Human analysts will remain critical for investigation and strategy, but the speed of modern attacks demands machine-speed defensive controls.
(+1) DDoS Will Become More Closely Linked to Geopolitical Conflict
As hacktivist groups continue using disruption as a political weapon, governments, media organizations, and critical infrastructure are likely to remain high-value targets.
The boundary between cybercrime, hacktivism, and geopolitical cyber operations will continue to become less distinct.
Final Takeaway: The
Cloudflare’s Q2 2026 figures reveal a DDoS landscape that is changing faster than many organizations may realize.
The most important message is not simply that there were more attacks.
It is that the largest attacks are becoming dramatically more common while overall attack volume is also increasing.
More than 800 attacks above 1 Tbps in a single quarter is a powerful warning that extreme traffic events can no longer be treated as theoretical scenarios.
At the same time, the majority of attacks remain relatively small, meaning defenders must protect against a broad spectrum of techniques rather than focusing exclusively on headline-grabbing terabit events.
DNS floods, CLDAP amplification, UDP floods, HTTP attacks, hacktivism, and DDoS-for-hire ecosystems all demonstrate that attackers have multiple paths to disruption.
The organizations best positioned for the next phase of the threat landscape will not necessarily be those with the biggest Internet connections.
They will be those that understand their attack surface, distribute critical infrastructure, protect DNS and APIs, monitor application behavior, establish upstream mitigation, automate response, and rehearse what happens when everything suddenly starts receiving malicious traffic.
The era when DDoS was simply a temporary website outage is disappearing. In 2026, DDoS resilience has become a fundamental requirement for keeping digital businesses, public services, and critical Internet infrastructure online.
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




