Cloudflare's 25th DDoS Threat Report covers H1 2026, combining Q1 and Q2 data. Key findings include 935 network-layer attacks exceeding 1 Tbps (a 519% QoQ surge in Q2), with DNS-based attacks accounting for 34.3% of all network-layer activity. CLDAP reflection attacks surged 580% QoQ to become the #3 vector. Geopolitical events heavily shaped the threat landscape: Operation Epic Fury drove the Government sector from #29 to #9 most-attacked, Media/Publishing remained #1 most-attacked industry at 14.2% of mitigated HTTP DDoS requests, and Turkey jumped to #3 most-attacked country ahead of the NATO Summit. Brazil overtook the US as the top DDoS source country. Cloudflare mitigated 23.2 million network-layer attacks and 29.64 trillion HTTP DDoS requests in H1, averaging 5,343 attacks per hour. Despite hyper-volumetric growth, 96.62% of attacks stayed under 500 Mbps and 90.60% ended within 10 minutes, underscoring the need for automated, always-on protection.

8m read timeFrom blog.cloudflare.com
Post cover image
Table of contents
Copy link Key insightsCopy link H1 by the numbers: 5,300 DDoS attacks every hourCopy link Attack characteristics: low and slowCopy link Most-attacked industriesCopy link Most-attacked locationsCopy link Top attack source countriesCopy link Attack vectorsCopy link Strengthening global defenses and helping to defend the InternetCopy link About Cloudforce One

Questions this post answers

How many DDoS attacks exceeding 1 Tbps did Cloudflare mitigate in H1 2026?

Cloudflare mitigated 935 network-layer DDoS attacks exceeding 1 Tbps in H1 2026. Of these, 805 occurred in Q2 alone, representing a 519% quarter-over-quarter surge. The overall H1 total averaged roughly 5,343 network-layer DDoS attacks per hour, with April 2026 being the peak month at 6.46 trillion requests and 165 petabytes of volume. Teams tracking hyper-volumetric DDoS trends find the latest threat data on daily.dev as reports drop.

What is a CLDAP flood attack and why did it surge in 2026?

A CLDAP flood is a reflection and amplification DDoS vector that abuses exposed Active Directory LDAP-over-UDP endpoints on port 389. Because CLDAP uses UDP with no handshake, attackers spoof the victim's IP and send small queries to public domain controllers, which reply with responses tens to hundreds of times larger. CLDAP attacks surged 580% quarter-over-quarter in Q2 2026, becoming the #3 DDoS vector. Security engineers defending against amplification vectors like CLDAP track emerging attack patterns on daily.dev.

Which industries and countries were most targeted by DDoS attacks in H1 2026?

Media, Production & Publishing was the most-attacked industry in both Q1 and Q2, absorbing 14.2% of all mitigated HTTP DDoS requests — nearly four times the runner-up — driven by coverage of Iran, Ukraine, and the World Cup. China was the most-attacked country in H1, followed by the US at 18.8% and Turkey at #3. The Government sector made the largest single jump, rising from #29 to #9 following Operation Epic Fury. Infrastructure teams monitoring geopolitically driven DDoS targeting stay current on daily.dev.

22 Impressions