Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave

Blog post from Cloudflare

Post Details
Company
Date Published
Author
-
Word Count
1,558
Company Posts That Month
44
Language
English
Hacker News Points
-
Post removed?
No
Summary

Cloudflare’s H1 2026 DDoS Threat Report, based on telemetry from its network, describes a substantial rise in network-layer attacks, including 935 attacks exceeding 1 Tbps and a more than sixfold quarterly increase in such hyper-volumetric events during Q2. It reports mitigating 23.2 million network-layer attacks and 29.64 trillion HTTP DDoS requests from January through June, while noting that most attacks remained below 500 Mbps and lasted under 10 minutes, making automated protection important because even brief attacks can cause extended disruption. DNS-related attacks represented 34.3% of network-layer activity, with DNS floods growing sharply and CLDAP amplification attacks increasing 580% quarter over quarter. Geopolitical events appeared to coincide with targeting patterns: media organizations were the most attacked industry, government-sector targeting rose following Operation Epic Fury, and Turkey became the third most-attacked location amid the Ankara NATO Summit buildup. China and the United States were the most targeted countries, while Brazil became the leading apparent source country for DDoS traffic. The report also links a decline after April’s activity peak to the multinational Operation PowerOFF crackdown on DDoS-for-hire services and highlights Cloudflare’s global capacity, automated mitigation systems, and botnet threat-sharing program.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 1 4,120 979 214 -36%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.