All incidents

Surge in >1 Tbps DDoS attacks observed in H1 2026

campaignopenAug 11, 2026 — Aug 12, 2026
Cloudflare sees 519% rise in >1 Tbps DDoS attacks in H1 2026

CLOUDFLARE reported a 519 per cent increase in DDoS attacks that exceeded one terabit per second during the first half of 2026, a surge that hit organisations across the globe and left the media and publishing sector as the most frequent target. Cloudflare’s latest threat report details the shift.

The company mitigated 935 individual attacks above the 1 Tbps threshold, marking a sharp rise from the previous period. Attackers moved away from traditional botnet floods and favoured reflection and amplification methods, with DNS-based exploits accounting for 34.3 per cent of all network‑layer traffic observed. Databreaches.net summarises the figures.

On the HTTP layer, Cloudflare saw more than 29 trillion malicious requests, averaging over five thousand three hundred attacks each hour. Network‑layer defences handled in excess of 23 million mitigation events, highlighting the sheer volume of traffic that security teams had to absorb.

Geopolitical tensions played a clear role, with attackers focusing on Turkish entities and government institutions more often than in previous years. Law‑enforcement actions linked to the campaigns resulted in several arrests, although Cloudflare’s analysis did not attribute the activity to any named threat‑actor group.

Defenders should consider scaling anycast capacity to absorb large volumetric hits, enable automatic scrubbing services that can drop malicious traffic before it reaches origin servers, and enforce strict rate limits on open DNS resolvers to curb amplification attempts. Monitoring for sudden spikes in DNS query volume can also provide early warning of an emerging attack.

Additionally, keeping all public‑facing software patched, deploying bot‑management challenges to filter junk HTTP traffic, and regularly testing incident‑response playbooks for rapid mitigation will help reduce the chance of a successful volumetric flood. These steps combined can lower the likelihood of service disruption when attackers attempt to overwhelm bandwidth.

Intelligence briefing updated Aug 12, 2026

Root sourceblog.cloudflare.com
Timeline Coverage

Swipe to explore timeline