dns-amplification

1 posts

cloudflare

Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave (opens in new tab)

Cloudflare’s H1 2026 DDoS report shows a sharp rise in extreme attacks alongside a shift toward reflection and amplification techniques. Although most attacks remained brief and relatively small, 935 network-layer attacks exceeded 1 Tbps, making automated, always-on protection essential. Geopolitical events also strongly influenced which industries and countries were targeted. ## DDoS Activity Reached Record Levels - Cloudflare mitigated: - 23.2 million network-layer DDoS attacks - 29.64 trillion HTTP DDoS requests - This equals roughly 5,343 network-layer attacks per hour, or 128,000 per day. - April was the peak month, with 6.46 trillion requests and 165 petabytes of traffic. - Activity declined afterward, possibly following Operation PowerOFF, which targeted: - More than 75,000 DDoS-for-hire users - 53 domains - 25 search warrants - Four arrests across 21 countries ## Hyper-Volumetric Attacks Surge - Cloudflare mitigated 935 network-layer attacks exceeding 1 Tbps during H1. - Q2 alone accounted for 805 such attacks, more than six times Q1’s total. - Hyper-volumetric attacks are defined as exceeding: - 1 Tbps - 1 billion packets per second - 1 million requests per second ## Most Attacks Remained Short and Small - Despite record-breaking incidents: - 96.62% of network-layer attacks stayed below 500 Mbps. - 90.60% lasted less than 10 minutes. - Even “small” attacks can be damaging: - 100 Mbps can overwhelm an individual server or website. - 100 Gbps can disable most unprotected data centers. - Attacks above 1 Tbps can stress major infrastructure. - Attackers may combine high packet rates with lower bandwidth, or the reverse, to target different network weaknesses. - Some extreme attacks lasted only 35 seconds, leaving no realistic opportunity for manual intervention. - Short attacks can still cause prolonged routing instability, retransmissions, timeouts, and downstream outages. ## Media and Government Organizations Were Major Targets - Media, Production & Publishing was the most targeted industry in both quarters. - It represented 14.2% of mitigated HTTP DDoS requests. - Coverage of conflicts in Iran and Ukraine, along with the World Cup, contributed to sustained targeting. - Following Operation Epic Fury against Iran, government organizations experienced a major spike: - Researchers recorded 149 hacktivist DDoS claims against 110 organizations in 16 countries. - Nearly 47.8% of targeted organizations were in the government sector. - Government moved from 29th place in Q1 to 9th in Q2. ## China and Turkey Rose Among Targeted Locations - China was the most attacked location in Q2, receiving 22.4% of global HTTP DDoS requests. - The United States ranked second with 18.8%. - Turkey more than doubled its share of attack traffic and reached third place. - The increase coincided with security activity surrounding the 2026 Ankara NATO Summit. ## Brazil Became the Leading Attack Source - Brazil overtook the United States as the leading source country: - Brazil: 14.9% during H1, rising to 21.4% in Q2 - United States: 13.4% - Indonesia remained the third-largest source country. ## DNS and CLDAP Attacks Gained Ground - DNS-based attacks accounted for 34.3% of network-layer activity. - DNS Floods rose from 25.7% to 40.0% of network-layer attacks between Q1 and Q2. - DNS Floods directly overwhelm authoritative DNS servers with query volume. - DNS Amplification abuses open resolvers and spoofed source addresses to send larger responses to victims. - CLDAP Floods increased 580% quarter-over-quarter and became the third-most common vector in Q2. - These attacks exploit exposed LDAP-over-UDP endpoints, particularly those associated with Active Directory. - Overall, the attack landscape shifted from conventional botnet floods toward reflection and amplification methods. Cloudflare’s findings reinforce that DDoS defenses must be automated, distributed, and continuously active. Short attack durations and rapidly increasing traffic volumes make manual or on-demand mitigation too slow to protect services reliably.