Cloudflare Battles a New DDoS Era as 1 Tbps Attacks Explode by More Than 500%

Listen to this Post

Featured Image

A New Scale of Internet Disruption

Distributed denial-of-service attacks are no longer simply a nuisance used to knock a website offline for a few minutes. The latest figures from Cloudflare show that the DDoS landscape is rapidly moving toward a new level of scale, automation, and destructive potential.

During the second quarter of 2026, Cloudflare says it mitigated more than 800 network-layer DDoS attacks exceeding 1 Tbps. That is an extraordinary jump from the 130 attacks above 1 Tbps recorded during the first quarter, representing an increase of more than fivefold.

The development is particularly important because attacks at this scale can overwhelm traditional network defenses extremely quickly. A terabit-per-second attack is capable of generating enormous amounts of traffic in a matter of seconds, forcing organizations to rely on upstream mitigation providers, globally distributed infrastructure, and highly automated detection systems.

Cloudflare’s latest statistics, presented alongside its Black Hat security research, reveal a broader story: DDoS attacks are becoming more frequent, larger, more diversified, and increasingly dependent on reflection and amplification techniques.

The Numbers Behind the Warning

Cloudflare reported that it mitigated 23.2 million network-layer DDoS attacks during the first half of 2026, alongside approximately 29.64 trillion malicious HTTP requests.

The second quarter was particularly aggressive.

Network-layer DDoS attacks increased from approximately 10.04 million in Q1 to 13.17 million in Q2, representing a 31.2% increase.

At the HTTP layer, malicious request volume climbed from 12.75 trillion to 16.89 trillion, an increase of approximately 32.4%.

These numbers matter because they demonstrate that the threat is not being driven solely by a handful of enormous attacks. The overall volume of hostile activity is rising at the same time that the most powerful attacks are becoming dramatically larger.

The Explosion of 1 Tbps Attacks

The most striking statistic is the growth in attacks above the 1 Tbps threshold.

Cloudflare recorded just 130 such attacks during Q1 2026. In Q2, the number surpassed 800.

That represents a 519% quarter-over-quarter increase.

The increase was not limited to the largest category. Attacks between 500 Gbps and 1 Tbps increased by 143%, while attacks between 100 Gbps and 500 Gbps grew by 105%.

This creates an important security lesson: organizations should not design their DDoS defenses around historical attack sizes.

The baseline itself is changing.

An attack that would have been considered exceptionally large only a few years ago can increasingly become part of the normal threat landscape.

The 31.4 Tbps Attack Shows What Is Possible

The scale of modern botnets was demonstrated by a record-breaking attack recently mitigated by Cloudflare.

The attack reportedly peaked at approximately 31.4 Tbps and generated around 200 million requests per second. Cloudflare attributed the incident to the Aisuru/Kimwolf botnet.

An attack of this magnitude illustrates why conventional perimeter defenses can become irrelevant when the traffic volume reaches extreme levels.

If malicious traffic reaches an

That is why modern DDoS protection increasingly operates upstream, before malicious traffic reaches the customer’s infrastructure.

Most Attacks Are Still Small

Despite the dramatic headlines surrounding terabit-scale attacks,

The overwhelming majority of network-layer attacks remain relatively small.

Cloudflare reported that 96.62% of network-layer DDoS attacks stayed below 50 Mbps.

Approximately 90.6% of attacks ended within 10 minutes.

This is a crucial distinction.

The DDoS threat landscape contains both extremely short, low-volume attacks and comparatively rare events capable of generating terabits of traffic.

Security teams therefore cannot rely exclusively on defending against gigantic attacks. They also need systems capable of detecting repeated smaller attacks, application-layer abuse, protocol manipulation, and attacks designed to exhaust specific services rather than raw bandwidth.

Long-Running Attacks Are Becoming More Noticeable

Cloudflare also observed a small increase in attacks lasting more than three hours.

The percentage rose from 0.387% in Q1 to 0.828% in Q2 2026.

Although these attacks represent a small fraction of total incidents, the change deserves attention.

A prolonged attack can be more difficult operationally than a short traffic spike because defenders must maintain mitigation, monitoring, incident response, and service availability for an extended period.

Long-running attacks can also be used as distractions.

An attacker may generate sustained DDoS traffic while simultaneously attempting credential attacks, exploiting exposed services, abusing APIs, or probing security controls elsewhere in the environment.

April Became the Peak Month

Cloudflare identified April 2026 as the peak period for overall DDoS activity during the first half of the year.

During that month, the company observed approximately 6.46 trillion HTTP DDoS requests and 165 petabytes of network-layer attack traffic.

The subsequent decline is particularly interesting.

Cloudflare tentatively connected the reduction to Operation PowerOFF, an international law-enforcement effort targeting DDoS-for-hire infrastructure.

The operation reportedly resulted in the arrest of four individuals, the seizure or takedown of 53 domains, and warnings being sent to approximately 75,000 users of such services.

Law Enforcement Can Disrupt the Ecosystem — But Not Eliminate It

The apparent decline following Operation PowerOFF highlights an important reality about DDoS attacks.

DDoS is not only a technical problem.

It is also an economic ecosystem.

DDoS-for-hire services lower the technical barrier required to launch an attack. Someone without the infrastructure or expertise to build a botnet can potentially purchase access to an attack service.

Disrupting those services can therefore reduce attack activity quickly.

But history suggests that disruption does not necessarily mean permanent elimination.

Operators can migrate infrastructure, change domains, create new services, recruit new customers, or move toward decentralized and harder-to-dismantle infrastructure.

The fight against DDoS therefore requires both technical mitigation and sustained law-enforcement pressure.

DNS Attacks Are Becoming a Major Concern

One of the most interesting changes in

DNS floods represented approximately 40% of network-layer DDoS attacks during Q2, compared with 25.7% during Q1.

Cloudflare also reported that DNS floods and DNS amplification together accounted for approximately 34.3% of H1 network-layer attacks.

This shift matters because DNS sits at the heart of modern Internet connectivity.

Disrupt DNS infrastructure and users may struggle to resolve domains even when the underlying applications remain operational.

Attackers therefore do not necessarily need to destroy the application itself. Disrupting the infrastructure responsible for finding that application can be enough.

CLDAP Floods Surge by 881.9%

Another major warning sign was the increase in CLDAP flood attacks, which Cloudflare said grew by approximately 881.9% quarter over quarter.

CLDAP, or Connectionless Lightweight Directory Access Protocol, uses UDP and can be abused in reflection and amplification attacks.

Reflection attacks are particularly attractive to attackers because the victim receives traffic generated indirectly through third-party systems.

Instead of sending every packet directly toward the target, attackers manipulate vulnerable or exposed services so that they respond to the victim.

That can amplify the

UDP Remains a Powerful Attack Vector

UDP floods ranked second among

UDP is attractive to attackers because it is connectionless.

Unlike TCP, UDP does not require the same connection establishment process, allowing attackers to generate enormous volumes of packets without maintaining conventional sessions.

The result can be bandwidth exhaustion, CPU exhaustion, state exhaustion in network devices, or pressure on downstream infrastructure.

HTTP DDoS Remains Enormous

Network-layer attacks receive much of the attention because of their impressive bandwidth numbers, but HTTP DDoS activity is equally important.

Cloudflare recorded 16.89 trillion malicious HTTP requests during Q2 alone.

Application-layer attacks can be particularly dangerous because they may resemble legitimate user behavior.

A single request might not look suspicious.

Millions or billions of requests, however, can consume application servers, databases, API resources, authentication systems, and backend processing capacity.

This is why modern DDoS protection must operate beyond simple packet filtering.

The Media Industry Was the Largest Target

During the first half of 2026, Cloudflare said the Media, Production, and Publishing sector received the largest share of mitigated HTTP DDoS requests, accounting for approximately 14.2%.

The industry is an attractive target for several reasons.

Media organizations operate highly visible websites, streaming services, APIs, publishing platforms, and advertising infrastructure.

Disrupting those systems can generate immediate public impact.

It can also create reputational damage because users often interpret an unavailable website as a failure of the organization itself, even when the actual cause is an external attack.

Government Targets Reflect Geopolitical Tensions

Government organizations also experienced significant increases in DDoS activity.

Cloudflare linked some of this activity to geopolitical developments and heightened hacktivism surrounding international military events.

This demonstrates another transformation in DDoS operations.

DDoS attacks are increasingly being used as political messaging tools.

For hacktivist groups, disrupting a government website can be a relatively inexpensive way to attract media attention, demonstrate capability, or retaliate against geopolitical events.

The objective may not always be permanent destruction.

Sometimes the objective is simply visibility.

DDoS Has Become Part of the Cyberwarfare Playbook

DDoS attacks are now routinely discussed alongside ransomware, data theft, supply-chain compromise, and influence operations.

That is because disruption itself has strategic value.

A government website going offline during a crisis can create uncertainty.

A media platform becoming unavailable during a major event can affect information access.

A financial service suffering repeated outages can damage customer confidence.

The technical simplicity of DDoS does not mean the strategic consequences are simple.

The New Problem: Attack Scale Is Becoming Automated

The biggest lesson from

It is that the infrastructure behind them is becoming increasingly automated.

Botnets can recruit vulnerable Internet-connected devices.

Attack platforms can automate target selection.

DDoS-for-hire services can provide an interface for launching attacks.

Reflection infrastructure can multiply traffic.

Automated mitigation systems must therefore fight automation with automation.

Human analysts remain important, but manually investigating every traffic spike is no longer realistic.

Why Traditional Firewalls Are Not Enough

A conventional firewall may block malicious packets, but a firewall cannot solve every volumetric DDoS scenario.

If the attack consumes the

This is one reason cloud-based and upstream DDoS mitigation services have become so important.

Traffic can be distributed across large networks, filtered closer to the source, and only legitimate traffic forwarded toward the customer’s infrastructure.

Deep Analysis: How Defenders Should Think About DDoS

Layer 1 — Understand the Attack Surface

Security teams should identify every Internet-facing service before an attacker does.

That includes websites, APIs, VPN gateways, DNS servers, mail infrastructure, remote-access systems, cloud endpoints, and forgotten subdomains.

A simple DNS inventory can reveal unexpected exposure:

dig example.com ANY
dig example.com NS
dig example.com MX

Organizations should also regularly inspect their external attack surface.

Layer 2 — Monitor Traffic Baselines

Defenders need to know what normal traffic looks like.

Useful metrics include:

Requests per second

Packets per second

Bits per second

TCP connection rates

UDP packet rates

HTTP status codes

DNS query volume

Source-country distribution

ASN distribution

Without a baseline, anomaly detection becomes significantly harder.

Layer 3 — Watch for Sudden Protocol Changes

A sudden increase in UDP traffic, DNS queries, or unusual protocol types can indicate an attack.

For example:

tcpdump -nn udp

can help analysts inspect UDP traffic during an incident.

For production environments, however, packet capture should be performed carefully because large-scale captures can themselves consume significant storage and processing resources.

Layer 4 — Inspect DNS Infrastructure

DNS deserves special attention given the dramatic increase in DNS-related attacks.

Defenders should review:

dig example.com
dig @8.8.8.8 example.com
dig @1.1.1.1 example.com

They should also ensure that authoritative DNS infrastructure is geographically and logically redundant.

Layer 5 — Protect the Application Layer

HTTP DDoS protection should not depend solely on IP blocking.

Defenders should consider:

Rate limiting

Bot detection

WAF rules

Challenge mechanisms

API quotas

Request validation

Authentication throttling

Caching

Origin shielding

The goal is to prevent attackers from converting inexpensive requests into expensive backend operations.

Layer 6 — Protect APIs Separately

Modern applications often expose APIs that can be more computationally expensive than ordinary web pages.

An attacker may therefore target an endpoint that triggers database queries, searches, authentication workflows, or large backend computations.

Rate limiting should be applied according to endpoint sensitivity rather than simply using one global threshold.

Layer 7 — Build Upstream Mitigation

Organizations exposed to volumetric attacks should establish relationships with upstream mitigation providers before an incident.

During a 1 Tbps attack, there is little time to negotiate emergency architecture changes.

Preparation must happen beforehand.

Layer 8 — Test the Incident Response Plan

Security teams should periodically simulate DDoS scenarios.

Questions should include:

Who declares the incident?

Who contacts the ISP?

Who contacts the DDoS provider?

Who communicates with customers?

Who investigates the source?

Who approves emergency firewall changes?

Who monitors recovery?

If these answers are unclear, the organization is not fully prepared.

Layer 9 — Monitor More Than Bandwidth

A DDoS attack may not consume all available bandwidth.

Application-layer attacks can instead exhaust CPU, memory, database connections, API quotas, or worker threads.

Defenders should therefore correlate network telemetry with:

top
vmstat
iostat
ss -s

These commands can provide useful host-level visibility during an incident.

Layer 10 — Look for the Secondary Attack

A DDoS event should never automatically be treated as an isolated event.

Attackers can use disruption as a smokescreen.

Security teams should investigate authentication logs, administrative access, unusual outbound connections, privilege changes, and suspicious endpoint activity while the DDoS is being mitigated.

What Undercode Say:

The 519% Increase Is the Real Warning

The most concerning figure in this report is not the total number of attacks.

It is the 519% increase in attacks above 1 Tbps.

That statistic suggests the upper boundary of DDoS capability is expanding rapidly.

Size and Frequency Are Growing Together

The industry is facing two problems simultaneously.

There are more attacks.

And the largest attacks are becoming substantially larger.

That combination is far more dangerous than either trend individually.

Small Attacks Still Matter

The fact that 96.62% of attacks remain below 50 Mbps should not create false confidence.

Small attacks can still disrupt poorly configured systems.

They can also serve as probes for discovering weaknesses in rate limiting and traffic controls.

Attack Duration Is Not the Only Metric

A ten-minute attack can be devastating if it hits the right service.

A three-hour attack can be devastating because it creates operational fatigue.

Organizations therefore need to evaluate attack impact rather than simply measuring duration.

DNS Has Become a Strategic Target

The rapid growth of DNS attacks is especially significant.

DNS is foundational infrastructure.

If attackers can disrupt name resolution, many downstream services can become inaccessible even when servers themselves remain healthy.

Reflection Remains Attractive

Reflection and amplification allow attackers to multiply the impact of relatively modest infrastructure.

That makes misconfigured or exposed Internet services valuable weapons for criminals.

CLDAP’s Growth Should Not Be Ignored

An 881.9% increase in CLDAP floods is too large to dismiss as statistical noise.

It suggests that attackers are actively adapting their techniques.

Defenders need visibility into protocols that historically received less attention.

Cloud Infrastructure Changes the Equation

Cloud platforms provide enormous scalability, but scalability does not automatically equal DDoS resilience.

A cloud application can still experience cost amplification, API exhaustion, database pressure, and application-level resource exhaustion.

Autoscaling Can Become Expensive

One overlooked DDoS consequence is financial.

If an application automatically scales in response to malicious traffic, the attacker may effectively force the victim to purchase additional computing resources.

Security teams should therefore connect DDoS controls with cloud cost monitoring.

HTTP Attacks Are More Difficult to Identify

A malicious HTTP request can look almost identical to a legitimate request.

This makes application-layer DDoS defense substantially more sophisticated than simple packet filtering.

AI Will Increase Automation

The broader cybersecurity environment is already moving toward agentic automation.

That same trend can benefit attackers.

Automated systems can identify exposed services, test infrastructure, rotate attack methods, and adjust traffic patterns faster than human operators.

Defenders Need Their Own Automation

The answer cannot be manual intervention.

Detection, rate limiting, traffic diversion, threat intelligence enrichment, and mitigation should increasingly be automated.

Geopolitics Will Continue Driving DDoS

Hacktivism is likely to remain an important source of DDoS activity.

Political events can produce sudden waves of attacks against government agencies, media organizations, and critical infrastructure.

Visibility Must Extend Beyond the Network

A company can successfully absorb a 1 Tbps attack and still suffer an outage because its application backend cannot handle the remaining legitimate traffic.

Resilience therefore requires network, application, identity, and infrastructure telemetry.

The Attack Surface Is Bigger Than the Main Website

Organizations should not only protect www.example.com.

They must inventory APIs, subdomains, legacy systems, cloud endpoints, DNS infrastructure, VPN services, and third-party integrations.

DDoS Protection Should Be Designed Before the Incident

Trying to architect a DDoS response during a massive attack is too late.

Organizations should already know how traffic will be routed, filtered, monitored, and restored.

Incident Response Needs Executive Support

DDoS response is not purely a security-team responsibility.

Network engineering, cloud teams, communications, legal teams, executives, and service providers may all become involved.

Law Enforcement Disruption Has Real Value

Operation PowerOFF demonstrates that dismantling attack-for-hire infrastructure can affect the wider ecosystem.

Technical mitigation and law enforcement should therefore be viewed as complementary defenses.

But Criminal Infrastructure Will Adapt

Attackers are unlikely to disappear because several services are removed.

The underground market will probably evolve.

New providers can emerge, infrastructure can migrate, and attackers can shift toward compromised IoT devices or alternative reflection mechanisms.

The Internet Is Becoming More Hostile

The growth of large-scale DDoS attacks is another indication that Internet infrastructure is operating under increasingly aggressive automated pressure.

Organizations should assume hostile traffic is normal.

Resilience Is the Real Objective

Perfect prevention is unrealistic.

The more useful goal is resilience: continue serving legitimate users while malicious traffic is detected, filtered, and absorbed.

Security Teams Should Measure Recovery

Organizations should track how quickly they detect attacks, activate mitigation, restore normal service, and identify secondary activity.

Mean time to recovery can be as important as detection speed.

DDoS Should Be Included in Business Continuity Planning

If an online service is business-critical, DDoS should be included in continuity exercises.

The question is not whether an attack is technically possible.

It is whether the business can continue operating when one occurs.

The Biggest Attacks Are Becoming Normalized

A 1 Tbps attack used to sound extraordinary.

Now hundreds of such attacks can occur within a single quarter.

That shift in perception should influence infrastructure planning.

Network Capacity Alone Is Not Enough

Buying more bandwidth can help, but it does not solve every attack.

Attackers can move higher in the stack and target expensive application operations instead.

Defense Must Be Multi-Layered

Modern DDoS protection should combine upstream filtering, CDN capacity, WAF controls, rate limiting, application optimization, DNS resilience, monitoring, and incident response.

Security Architecture Must Assume Failure

A resilient architecture assumes that some components will become unavailable.

Redundancy, failover, caching, multiple DNS providers, and distributed infrastructure can reduce the impact of an attack.

The Numbers Should Change Security Budgets

Organizations still treating DDoS protection as an optional add-on should reconsider that assumption.

The threat environment is moving too quickly.

The Most Valuable Asset Is Preparedness

The difference between a minor interruption and a major outage may come down to preparation completed months before the attack.

DDoS Is Becoming an Infrastructure Problem

This is no longer merely a cybersecurity problem.

It is a networking, cloud, application, business continuity, and geopolitical problem.

2026 Is Sending a Clear Signal

Cloudflare’s data shows that defenders are entering an era where extreme DDoS attacks are becoming increasingly common.

The organizations that adapt early will have a significant advantage.

✅ More Than 800 Attacks Above 1 Tbps

Cloudflare reported more than 800 network-layer DDoS attacks exceeding 1 Tbps in Q2 2026.

That represents a dramatic increase compared with the 130 attacks above 1 Tbps recorded in Q1.

✅ 519% Quarter-over-Quarter Increase

The reported increase in attacks above 1 Tbps was approximately 519% quarter over quarter.

The figure is consistent with the

✅ 23.2 Million Network-Layer Attacks

Cloudflare reported mitigating approximately 23.2 million network-layer DDoS attacks during the first half of 2026.

This demonstrates that the enormous terabit-scale events represent only a small portion of the broader DDoS landscape.

✅ 16.89 Trillion Malicious HTTP Requests

Cloudflare reported approximately 16.89 trillion malicious HTTP requests during Q2.

The increase from 12.75 trillion in Q1 represents approximately 32.4% growth.

✅ DNS Attacks Increased Sharply

DNS floods accounted for approximately 40% of Q2 network-layer DDoS attacks according to the reported Cloudflare figures.

The shift from 25.7% in Q1 highlights a substantial change in attack composition.

⚠️ Operation PowerOFF Attribution Requires Context

Cloudflare characterized the post-April decline as something it tentatively attributed to Operation PowerOFF.

That means the operation should not automatically be described as the sole cause of the reduction.

Prediction

(+1) Extreme DDoS Attacks Will Become More Common

The rapid increase in attacks exceeding 1 Tbps strongly suggests that extreme volumetric attacks will continue appearing more frequently.

As botnets become larger and automated attack services become more sophisticated, the upper limits of DDoS traffic are likely to continue rising.

(+1) DNS and Amplification Attacks Will Remain Important

The sharp increase in DNS floods and CLDAP floods indicates that reflection and amplification techniques remain attractive to attackers.

Organizations should expect continued experimentation with protocols capable of generating large responses from relatively small requests.

(+1) Cloud-Based Mitigation Will Become Standard

More organizations will likely move toward distributed DDoS mitigation rather than relying exclusively on local firewalls and network appliances.

The economics of defending against multi-terabit attacks increasingly favor large-scale distributed infrastructure.

(-1) Smaller Organizations Will Face Greater Risk

Organizations without upstream DDoS protection may find themselves increasingly vulnerable as attack volumes grow.

For smaller businesses, a single large attack can consume available bandwidth and make traditional perimeter defenses ineffective.

(+1) Automated DDoS Defense Will Become Essential

Security teams will increasingly rely on automated detection, traffic classification, rate limiting, dynamic filtering, and intelligent traffic routing.

Human analysts will remain critical for investigation and strategy, but the speed of modern attacks demands machine-speed defensive controls.

(+1) DDoS Will Become More Closely Linked to Geopolitical Conflict

As hacktivist groups continue using disruption as a political weapon, governments, media organizations, and critical infrastructure are likely to remain high-value targets.

The boundary between cybercrime, hacktivism, and geopolitical cyber operations will continue to become less distinct.

Final Takeaway: The

Cloudflare’s Q2 2026 figures reveal a DDoS landscape that is changing faster than many organizations may realize.

The most important message is not simply that there were more attacks.

It is that the largest attacks are becoming dramatically more common while overall attack volume is also increasing.

More than 800 attacks above 1 Tbps in a single quarter is a powerful warning that extreme traffic events can no longer be treated as theoretical scenarios.

At the same time, the majority of attacks remain relatively small, meaning defenders must protect against a broad spectrum of techniques rather than focusing exclusively on headline-grabbing terabit events.

DNS floods, CLDAP amplification, UDP floods, HTTP attacks, hacktivism, and DDoS-for-hire ecosystems all demonstrate that attackers have multiple paths to disruption.

The organizations best positioned for the next phase of the threat landscape will not necessarily be those with the biggest Internet connections.

They will be those that understand their attack surface, distribute critical infrastructure, protect DNS and APIs, monitor application behavior, establish upstream mitigation, automate response, and rehearse what happens when everything suddenly starts receiving malicious traffic.

The era when DDoS was simply a temporary website outage is disappearing. In 2026, DDoS resilience has become a fundamental requirement for keeping digital businesses, public services, and critical Internet infrastructure online.

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube