Distributed denial-of-service (DDoS) attacks reached unprecedented scales in the first half of 2026, with campaigns generating traffic in excess of one terabit per second (Tbps) becoming increasingly common. Cloudflare's H1 2026 DDoS Threat Report indicates a rise in both the volume and sophistication of these attacks, characterized by larger traffic floods, shorter durations, and greater automation.
April 2026 marked a peak month for DDoS activity, with Cloudflare reporting a high of 6.46 trillion requests and 165 petabytes of data mitigated. Despite this hyper-volumetric growth, the median DDoS attack remained relatively small and brief, with 96.62% of network-layer attacks registering under 500 Mbps and 90.60% concluding in less than ten minutes. This suggests a trend toward short, intense bursts of activity.
Attackers frequently employed multi-vector techniques, combining network-layer attacks with application-layer HTTP floods. This strategy allows threat actors to shift attack methods during an incident, complicating mitigation efforts and increasing the likelihood of service disruption. The availability of DDoS-for-hire platforms, compromised Internet of Things (IoT) devices, and automated attack tools has lowered the barrier for launching large-scale attacks, enabling threat actors to generate significant traffic without extensive infrastructure.
Government organizations experienced a notable surge in HTTP DDoS attacks during the second quarter of 2026. This increase followed "Operation Epic Fury," a period during which security researchers documented 149 hacktivist DDoS claims targeting 110 organizations across 16 countries within 72 hours, with 47.8% of these targets belonging to the government sector.
The media, production, and publishing sector was the most targeted industry throughout the first half of 2026, accounting for 14.2% of all mitigated HTTP DDoS requests, nearly four times the share of the second-ranked industry. These attacks were often short-duration and high-intensity, with many lasting less than one minute, underscoring the importance of continuous monitoring and automated defenses.
Geographically, China was the most targeted location for HTTP DDoS requests in the second quarter, accounting for 22.4% of mitigated traffic, followed by the United States at 18.8%. Turkey climbed to third place, more than doubling its share of global attack traffic. This increase in Turkey coincided with preparations for the 2026 Ankara NATO Summit, during which Turkish authorities conducted extensive pre-summit security operations.
Brazil emerged as the leading source country for DDoS attacks during the reporting period, surpassing the United States. Brazil accounted for 14.9% of mitigated DDoS request traffic, driven by a sharp increase in the second quarter where it generated 21.4% of all mitigated traffic. Indonesia maintained its position as the third-largest source country.
DNS-based attacks remained the most prevalent network-layer attack vector, with DNS Flood and DNS Amplification attacks constituting 34.3% of all such attacks. CLDAP Flood attacks saw a significant quarter-over-quarter increase of 580%, becoming the third most common network-layer attack vector in the second quarter of 2026. CLDAP attacks exploit exposed LDAP-over-UDP services to amplify traffic and overwhelm targeted systems.






