DDoS giants: 1Tbps+ attacks spike 519%
Cloudflare mitigated over 800 network-layer DDoS attacks above 1 Tbps in Q2, a fivefold rise from Q1.
The second quarter of the year saw an unprecedented surge in the largest category of distributed denial-of-service attacks, with Cloudflare reporting it mitigated more than 800 network-layer DDoS attacks exceeding 1 Tbps—a more than fivefold increase from the 130 such attacks recorded in the first quarter. The figures, shared with BleepingComputer and presented at the Black Hat security conference, point to a dramatic escalation in the scale and frequency of the most disruptive DDoS events.
Attackers push past the terabit barrier
Cloudflare, a major web infrastructure and security firm providing CDN, DNS, reverse-proxy, and DDoS protection services to customers worldwide, sits directly between DDoS botnets and their intended targets. This position allows the company to observe and absorb attacks at enormous scale, protecting roughly 20% of the web. Its latest data shows that the most significant increase occurred in attacks exceeding 1 Tbps, which rose 519% quarter over quarter.
This growth in extreme attacks comes amid an overall rise in DDoS activity. Attacks between 500 Gbps and 1 Tbps increased by 143%, while those between 100 and 500 Gbps rose 105%.
Majority of attacks still small and short
Despite the surge in large-scale incidents, the vast majority of network-layer attacks remained comparatively small and brief. Cloudflare reported that 96.62% of network-layer attacks stayed below 50 Mbps, and 90.6% ended within 10 minutes. However, the proportion of attacks lasting more than three hours increased slightly, from 0.387% in Q1 to 0.828% in Q2 2026.
Record-breaking attack and overall volumes
Cloudflare recently mitigated a record-breaking attack that peaked at 31.4 Tbps and 200 million requests per second, launched by the Aisuru/Kimwolf botnet. This event underscores the capacity of modern botnets to generate truly massive traffic volumes.
In the first half of the year, Cloudflare mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion malicious HTTP requests. Network-layer attacks rose from 10.04 million to 13.17 million, a 31.2% increase, while malicious HTTP request volume grew from 12.75 trillion to 16.89 trillion, up by 32.4%.
April peak and the PowerOFF effect
Cloudflare observed overall DDoS activity peaking in April, with 6.46 trillion HTTP DDoS requests and 165 PB of network-layer attack traffic. This was followed by a notable decline after April, which the firm tentatively attributes to the international Operation PowerOFF crackdown on DDoS-for-hire services.
The operation resulted in the arrest of four individuals, the takedown of 53 domains, and the distribution of warnings to 75,000 users of such services. These enforcement actions may have disrupted the operations of DDoS-for-hire platforms, contributing to the observed drop in activity.
Shift toward DNS and reflection techniques
Among the trends emerging in the last quarter, Cloudflare saw attacks shifting toward DNS-related and reflection/amplification techniques. DNS floods accounted for 40% of network-layer attacks in Q2, up from 25.7% in Q1. Together, DNS floods and DNS amplification attacks represented 34.3% of H1 network-layer attacks. CLDAP floods increased 881.9% quarter-over-quarter, and UDP floods ranked second in Q2 at 14.06%.
These techniques exploit the amplification potential of DNS and other protocols to generate large traffic volumes with relatively small botnets, making them attractive to attackers.
Targets: Media and government hit hardest
Regarding targets, Cloudflare reports that the Media, Production, and Publishing sector received the largest share of mitigated HTTP DDoS requests during H1 2026, at 14.2%. The government sector also saw a notable increase, which Cloudflare linked to geopolitical events, including the US-Israeli military operation against Iran, prompting heightened hacktivism.
Key statistics from Cloudflare's Q2 DDoS report
- More than 800 network-layer DDoS attacks exceeding 1 Tbps in Q2, up from 130 in Q1 (519% increase)
- 31.4 Tbps and 200 million requests per second peak for the Aisuru/Kimwolf attack
- 23.2 million network-layer DDoS attacks and 29.64 trillion malicious HTTP requests mitigated in H1
- 96.62% of network-layer attacks below 50 Mbps; 90.6% ended within 10 minutes
- DNS floods rose to 40% of network-layer attacks in Q2, up from 25.7% in Q1
- Media, Production, and Publishing sector received 14.2% of mitigated HTTP DDoS requests in H1
Why this matters for defenders
The surge in terabit-scale attacks suggests that attackers are increasingly capable of launching extreme DDoS events, potentially overwhelming less-protected organizations. While the majority of attacks remain small and short, the rise in prolonged and large-scale incidents could raise the stakes for businesses that rely on internet-facing services. The shift toward DNS-based techniques also indicates that attackers are adapting their methods to bypass traditional defenses. For security teams, these trends underscore the need for robust DDoS mitigation strategies that can handle both the high-volume attacks and the more frequent, smaller incidents. The post-April decline linked to Operation PowerOFF offers a glimpse of how law enforcement actions can temporarily disrupt DDoS-for-hire operations, but the underlying botnet infrastructure remains a persistent threat.
Sources
- BleepingComputer Original source
Continue Reading
Mozilla Rotates GPG Signing Key After GitHub Exposure
Mozilla replaced the GPG key for Firefox and Thunderbird after an unencrypted copy leaked to a private GitHub repo.
CISA Ties SharePoint Flaw to Ransomware
CISA adds CVE-2026-45659 to KEV catalog, confirming ransomware abuse of a Microsoft SharePoint RCE flaw.
City Cyberattack Disrupts 911 Services Amid Wave of Attacks
Suisan City declared a state of emergency after a malicious software infection disrupted emergency services, highlighting a pattern of local government attacks.