DDoS in the First Half of 2026: Record Attack Volumes, Short Attacks, and the Return of Amplification Attacks
Analytics2026-08-24, 11:01
Cloudflare has published a report on the DDoS landscape for the first half of 2026. The overall picture has become noticeably harsher: the number of attacks remains enormous, hyper-volumetric DDoS attacks are being recorded increasingly often, and their duration is shrinking to minutes or even tens of seconds.
Several key trends can be identified within this picture:
-
The scale of DDoS attacks remains historically high. During the first half of 2026, Cloudflare mitigated 23.2 million network-layer DDoS attacks (L3/4) and processed 29.64 trillion HTTP requests associated with DDoS attacks—an average of approximately 128,000 attacks per day. April stood out in particular: approximately 6.46 trillion DDoS requests and 165 PB of attack traffic were recorded during the month.
-
Hyper-volumetric attacks have increased sharply. During the first half of the year, Cloudflare recorded 935 attacks exceeding 1 Tbps, 805 of which occurred in Q2. Compared with the first quarter, the number of such attacks increased by 519%. At the same time, 96.6% of network-layer attacks still did not exceed 500 Mbps.
-
Attacks are becoming shorter, while manual response is becoming less effective. Approximately 90.6% of network-layer DDoS attacks lasted less than 10 minutes, while some hyper-volumetric attacks lasted only around 35 seconds. This duration makes manual response virtually useless: by the time the attack is detected and filtering is enabled, it may already be over.
-
DNS floods and amplification attacks are once again coming to the forefront. DNS floods and DNS amplification attacks accounted for approximately 34.3% of network-layer DDoS attacks, while the share of DNS floods increased from 25.7% in Q1 to 40% in Q2. The number of CLDAP flood attacks grew by more than 580% quarter over quarter, making this vector the third most prevalent.
The return of classic reflection and amplification attacks is particularly important: attackers generate large volumes of traffic by leveraging third-party misconfigured infrastructure without having comparable resources of their own.
-
DDoS attacks are increasingly correlated with geopolitics. Media, content production, and publishing became the most heavily targeted sector, accounting for 14.2% of HTTP DDoS traffic. The government sector rose from 29th to 9th place in attack levels within a single quarter, while Cloudflare links individual spikes to international conflicts and major political events.
-
The geographic picture is becoming less clear-cut. In the second quarter, the most heavily targeted countries included China, the United States and Turkey. Indonesia, France, Vietnam, the United Kingdom, Hong Kong, Malaysia, and Latvia also made the top 10 for the first half of the year. At the same time, the leading source of DDoS traffic during the first half of the year was Brazil — 14.9%, rising to 21.4% in the second quarter.
Most DDoS attacks remain small in volume, but the number of terabit-class attacks is growing rapidly at the same time. Amplification mechanisms are once again gaining importance, and DDoS attacks are increasingly being used as a tool of hacktivism and political pressure. Meanwhile, the shortening duration of attacks leaves less and less time for manual response, so protection increasingly depends on continuously enabled automated filtering.
Vendors
Products