<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cloudflare-h1-2026-ddos-report-1-tbps-attacks-up-519-dns-floods-dominate-j4uzsbghw" -->

---
title: Cloudflare H1 2026 DDoS report: 1 Tbps attacks up 519%,...
description: Cloudflare&#x27;s H1 2026 DDoS Threat Report reveals a dramatic escalation in attack scale and frequency. Network-layer attacks exceeding 1 Tbps surged 519%...
canonical: https://daily.dev/posts/cloudflare-h1-2026-ddos-report-1-tbps-attacks-up-519-dns-floods-dominate-j4uzsbghw
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Cloudflare H1 2026 DDoS report: 1 Tbps attacks up 519%, DNS floods dominate | daily.dev
og:description: Cloudflare&#x27;s H1 2026 DDoS Threat Report reveals a dramatic escalation in attack scale and frequency. Network-layer attacks exceeding 1 Tbps surged 519%...
og:url: https://daily.dev/posts/cloudflare-h1-2026-ddos-report-1-tbps-attacks-up-519-dns-floods-dominate-j4uzsbghw
og:image: https://api.daily.dev/og/posts/j4uzsbGHW.png
og:image:alt: Cloudflare H1 2026 DDoS report: 1 Tbps attacks up 519%, DNS floods dominate
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Cloudflare H1 2026 DDoS report: 1 Tbps attacks up 519%, DNS floods dominate

**[Collections](https://daily.dev/sources/collections)** · 3 min read · 7 upvotes · 1 comments

## Summary

Cloudflare's H1 2026 DDoS Threat Report reveals a dramatic escalation in attack scale and frequency. Network-layer attacks exceeding 1 Tbps surged 519% quarter-over-quarter to 935 incidents, with the largest single attack peaking at 31.4 Tbps from the Aisuru/Kimwolf botnet. DNS floods dominated at 34.3% of all network-layer attacks, while CLDAP reflection attacks surged 580% QoQ. Geopolitical factors shaped targeting: government sector attacks jumped from #29 to #9, Turkey became the #3 most-attacked country around the NATO Summit, and Brazil overtook the US as the top DDoS traffic source. Despite headline-grabbing terabit attacks, 96.62% of attacks stayed under 500 Mbps and 90.6% ended within 10 minutes — underscoring why automated mitigation is essential. A law enforcement action (Operation PowerOFF) may have contributed to a post-April decline in attack volume.

## Content

Cloudflare's 25th DDoS Threat Report covers the first half of 2026, and the headline number is hard to ignore: 935 network-layer attacks exceeded 1 Tbps, with the bulk of that surge happening in Q2 (around 800 attacks, up 519% from Q1's 130). For context, the company absorbed 23.2 million network-layer attacks and 29.64 trillion malicious HTTP requests across the full half-year — averaging roughly 5,343 attacks per hour.

## The biggest attack on record

The Aisuru/Kimwolf botnet launched a 31.4 Tbps attack, which Cloudflare mitigated. That's the largest they've recorded. It's the kind of number that sounds abstract until you consider what it would do to infrastructure without always-on automated mitigation.

## How attacks are being launched

DNS-based floods accounted for 34.3% of all network-layer attack traffic in H1, and jumped from 25.7% to 40% of Q2 attacks specifically. CLDAP reflection — a technique that abuses the Connectionless Lightweight Directory Access Protocol to amplify traffic — surged 580% quarter-over-quarter to become the third most common attack vector. In Q2 alone, CLDAP floods were up 881.9%.

Despite the hyper-volumetric headlines, the distribution of attacks tells a different story about who needs to worry: 96.62% of network-layer attacks stayed under 500 Mbps, and 90.6% ended within 10 minutes. The massive attacks get the attention, but the bulk of DDoS activity is still fast, small, and automated.

## Geopolitics is shaping the target list

This is where the report gets genuinely interesting. Real-world events are clearly influencing which sectors and countries get hit.

**Media and publishing** remained the most-attacked industry, accounting for 14.2% of all mitigated HTTP DDoS requests. Two ongoing conflicts — Ukraine and Iran — plus major sporting events including the World Cup appear to be driving sustained campaigns against news organizations and publishers. When people want to suppress or disrupt information, media outlets are the obvious target.

**Government** jumped from the 29th most-attacked sector to 9th, driven by what Cloudflare calls Operation Epic Fury. The specifics aren't fully detailed, but the scale of the shift — 20 places in a single reporting period — suggests a coordinated campaign rather than opportunistic attacks.

**Turkey** moved to the 3rd most-attacked country, ahead of the NATO Summit. The timing is unlikely to be coincidental.

**Brazil** overtook the United States as the top source country for DDoS traffic, which is a notable shift worth watching in future reports.

## Activity peaked in April, then dropped

Attack volume peaked in April before declining through Q2. Cloudflare tentatively links this to Operation PowerOFF, a law enforcement action that arrested four individuals and took down 53 DDoS-for-hire domains. Whether that's the actual cause or just correlation is hard to say, but the timing lines up.

## What this means practically

The 519% surge in terabit-scale attacks sounds alarming, but the more important operational reality is that most attacks are still short and relatively small. The threat isn't just the record-breakers — it's the constant background noise of automated attacks that never stop. That's why Cloudflare keeps emphasizing always-on automated protection rather than incident response: by the time a human notices and responds, 90% of attacks are already over.

## Questions this post answers

### What was the largest DDoS attack Cloudflare has ever mitigated?

The largest DDoS attack Cloudflare has mitigated reached 31.4 Tbps, launched by the Aisuru/Kimwolf botnet during the first half of 2026. This set a new record and was mitigated through Cloudflare's automated defenses. It occurred amid a broader surge in terabit-scale attacks, with 935 network-layer attacks exceeding 1 Tbps in that period, most of them concentrated in Q2.

_Teams sizing DDoS defenses against record attack scales can track infrastructure threat trends on daily.dev._

### What percentage of DDoS attacks are actually large-scale according to Cloudflare's data?

Only a small fraction are large: 96.62% of network-layer attacks stayed under 500 Mbps, and 90.6% ended within 10 minutes, according to Cloudflare's H1 2026 DDoS report. This means most real-world DDoS activity is fast, small, and automated rather than the terabit-scale headline attacks, which supports relying on always-on automated mitigation instead of manual incident response.

_Engineers weighing automated versus manual DDoS response can follow infrastructure security data on daily.dev._

### Why did CLDAP reflection attacks increase so much in 2026?

CLDAP reflection attacks surged 580% quarter-over-quarter, becoming the third most common DDoS vector, with Q2 alone seeing an 881.9% increase, per Cloudflare's H1 2026 report. CLDAP abuses the Connectionless Lightweight Directory Access Protocol to amplify attack traffic. This rise came alongside DNS-based floods growing from 25.7% to 40% of Q2 network-layer attacks.

_Security teams tracking emerging amplification vectors like CLDAP can follow DDoS trend reporting on daily.dev._

## Community discussion

Top comments from developers on daily.dev.

**@trevorsuna** · 0 upvotes

> The sub-10-minute figure is more operationally useful than the record-breaking peak. It makes manual response too slow for most events, so always-on mitigation, tested origin protection, and alerts tied to mitigation behavior matter more than a heroic incident runbook.

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#cloudflare](https://daily.dev/tags/cloudflare), [#dns](https://daily.dev/tags/dns)

[View this post on daily.dev](https://daily.dev/posts/cloudflare-h1-2026-ddos-report-1-tbps-attacks-up-519-dns-floods-dominate-j4uzsbghw)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Cloudflare H1 2026 DDoS report: 1 Tbps attacks up 519%, DNS floods dominate","url":"https://daily.dev/posts/cloudflare-h1-2026-ddos-report-1-tbps-attacks-up-519-dns-floods-dominate-j4uzsbghw","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cloudflare-h1-2026-ddos-report-1-tbps-attacks-up-519-dns-floods-dominate-j4uzsbghw"},"datePublished":"2026-08-11T13:17:34.221Z","dateModified":"2026-09-13T20:00:49.677Z","description":"Cloudflare's H1 2026 DDoS Threat Report reveals a dramatic escalation in attack scale and frequency. Network-layer attacks exceeding 1 Tbps surged 519%...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0ffd858f4ef0fc80f9497c6eafdec9c4?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0ffd858f4ef0fc80f9497c6eafdec9c4?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/cloudflare-h1-2026-ddos-report-1-tbps-attacks-up-519-dns-floods-dominate-j4uzsbghw","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":7},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"security,cyber,cloudflare,dns","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Cloudflare H1 2026 DDoS report: 1 Tbps attacks up 519%, DNS floods dominate"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/cloudflare-h1-2026-ddos-report-1-tbps-attacks-up-519-dns-floods-dominate-j4uzsbghw","comment":[{"@type":"Comment","text":"The sub-10-minute figure is more operationally useful than the record-breaking peak. It makes manual response too slow for most events, so always-on mitigation, tested origin protection, and alerts tied to mitigation behavior matter more than a heroic incident runbook.","datePublished":"2026-08-12T02:42:34.769Z","url":"https://daily.dev/posts/j4uzsbGHW#c-H3E3k0QTQ","author":{"@type":"Person","name":"Trevor Suna","url":"https://daily.dev/trevorsuna","image":"https://media.daily.dev/image/upload/s--dZ7gXxpp--/f_auto/v1784081551/avatars/avatar_EMoP47rpuw8DNjhp6R1b6?_a=BAMAMicg0"}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/cloudflare-h1-2026-ddos-report-1-tbps-attacks-up-519-dns-floods-dominate-j4uzsbghw#faq","mainEntity":[{"@type":"Question","name":"What was the largest DDoS attack Cloudflare has ever mitigated?","acceptedAnswer":{"@type":"Answer","text":"The largest DDoS attack Cloudflare has mitigated reached 31.4 Tbps, launched by the Aisuru/Kimwolf botnet during the first half of 2026. This set a new record and was mitigated through Cloudflare's automated defenses. It occurred amid a broader surge in terabit-scale attacks, with 935 network-layer attacks exceeding 1 Tbps in that period, most of them concentrated in Q2. Teams sizing DDoS defenses against record attack scales can track infrastructure threat trends on daily.dev."}},{"@type":"Question","name":"What percentage of DDoS attacks are actually large-scale according to Cloudflare's data?","acceptedAnswer":{"@type":"Answer","text":"Only a small fraction are large: 96.62% of network-layer attacks stayed under 500 Mbps, and 90.6% ended within 10 minutes, according to Cloudflare's H1 2026 DDoS report. This means most real-world DDoS activity is fast, small, and automated rather than the terabit-scale headline attacks, which supports relying on always-on automated mitigation instead of manual incident response. Engineers weighing automated versus manual DDoS response can follow infrastructure security data on daily.dev."}},{"@type":"Question","name":"Why did CLDAP reflection attacks increase so much in 2026?","acceptedAnswer":{"@type":"Answer","text":"CLDAP reflection attacks surged 580% quarter-over-quarter, becoming the third most common DDoS vector, with Q2 alone seeing an 881.9% increase, per Cloudflare's H1 2026 report. CLDAP abuses the Connectionless Lightweight Directory Access Protocol to amplify attack traffic. This rise came alongside DNS-based floods growing from 25.7% to 40% of Q2 network-layer attacks. Security teams tracking emerging amplification vectors like CLDAP can follow DDoS trend reporting on daily.dev."}}]}
```

