Cloudflare recorded a significant rise in distributed denial-of-service (DDoS) attacks from January to June 2026, as the company mitigated 935 network-layer attacks exceeding 1 terabit per second in intensity. The number of these attacks increased by 519% between the first and second quarters, according to the 25th edition of Cloudflare’s DDoS Threat Report, which combined data from both quarters into a single semiannual report.
The report was prepared by Cloudflare’s threat intelligence organization, Cloudforce One, based on the company’s network data. It highlights a change in the nature of attacks, with the focus shifting from botnet floods to reflection and amplification methods. DNS-related attacks led the activity, while CLDAP attacks also rose sharply.
Surge in Hyperscale Attacks
During the first half of the year, Cloudflare mitigated 23.2 million network-layer attacks and 29.64 trillion HTTP requests associated with DDoS attacks. This equates to approximately 5,343 network-layer attacks per hour, or nearly 128,000 attacks per day.
April 2026 marked the peak of activity by volume, recording 6.46 trillion requests and 165 petabytes of data. Requests and volumes then declined, which the report potentially linked to Operation PowerOFF, a campaign spanning 21 countries that targeted more than 75,000 users of DDoS-for-hire services. The campaign resulted in 53 domains being taken down, 25 search warrants being issued, and four people being arrested.
In the second quarter alone, Cloudflare mitigated 805 network-layer attacks exceeding 1 terabit per second, an increase of more than sixfold compared with the previous quarter. The report defines hyperscale attacks as attacks exceeding 1 terabit per second, 1 billion packets per second, or 1 million requests per second.
Short Attacks Leave No Room for Manual Intervention
Despite the growth in hyperscale attacks, most attacks mitigated by Cloudflare remained relatively small and brief: 96.62% of network-layer attacks stayed below 500 megabits per second, and 90.60% ended within less than ten minutes. Nevertheless, the report explains that describing an attack as “small” is relative. An attack at 100 megabits per second may be enough to overwhelm a server or website, while an attack at 100 gigabits per second can disrupt most unprotected data centers.
Cloudflare also recorded hyperscale attacks lasting only 35 seconds. The report states that this duration leaves practically insufficient time for human intervention or on-demand solutions, while the subsequent effects may persist for hours or days through routing disruptions, TCP packet retransmissions, application timeouts, and service degradation.
DNS and CLDAP Lead the Shift
DNS-based attacks, including DNS Flood and DNS Amplification, accounted for 34.3% of network-layer attacks during the first half of the year. The share of DNS Flood alone rose from 25.7% to 40.0% between the first and second quarters.
CLDAP Flood attacks also jumped 580% quarter over quarter to become the third-largest attack method in the second quarter. These attacks exploit exposed endpoints for the LDAP service over UDP. Attackers send small queries with a spoofed source address to publicly accessible domain controllers on port 389, causing the servers to respond with packets dozens or hundreds of times larger toward the victim.
Geopolitical Tensions Redistribute Targets
The media, production, and publishing sector remained the most targeted sector in both quarters, accounting for 14.2% of the HTTP requests mitigated by Cloudflare, amid interest in developments in Iran and Ukraine and the World Cup.
After Israel and the United States launched Operation Epic Fury against Iran’s leadership and infrastructure on February 28, 2026, security researchers recorded 149 claims of attacks by hacktivists targeting 110 organizations in 16 countries over 72 hours. The government sector accounted for approximately 47.8% of targeted organizations globally, rising from 29th place in the first quarter to ninth place in the second quarter.
By the locations of targeted sites, China topped the list in the second quarter with a 22.4% share of global HTTP requests, followed by the United States at 18.8%, while Türkiye rose to third place. As for the countries from which attacks originated, Brazil led with 14.9%, compared with 13.4% for the United States, while Indonesia retained third place.
Cloudflare says its network, distributed across more than 330 cities with a capacity of 500 terabits per second, provides free and unlimited DDoS protection for every service on the network. The company also provides hosting providers, cloud computing platforms, and internet service providers with a free botnet threat feed, which more than 800 networks worldwide have subscribed to.