Threat Research

DDoS Attack Statistics 2026 - Records, Trends and Data

DDoS attacks hit record frequency in 2026, with 935 floods above 1 Tbps in six months. The verified numbers behind the 2026 threat landscape, sourced and explained.

10 min readVerified security research
DDoS threat report dashboard showing record attack volumes and the rise of terabit-scale floods in 2026

Every year the DDoS record books get rewritten, and 2026 is no exception. The headline shift is no longer the size of a single attack but the cadence: floods above one terabit per second, once a career event for a network engineer, now arrive by the hundreds each quarter.

The most complete public dataset comes from Cloudflare’s DDoS Threat Report for the first half of 2026, built from the company’s global network by its Cloudforce One threat intelligence team. The numbers below are drawn from that report and the independent coverage that followed it.


The Headline Numbers of 2026

  • 935 attacks above 1 TbpsNetwork-layer floods exceeding one terabit per second mitigated in the first half of 2026 alone, a category that barely existed a few years ago.
  • +519% in one quarterGrowth in 1 Tbps-class attacks between Q1 and Q2 2026, from 130 events to 805. Hyper-volumetric attacks are now a routine, not a record.
  • 23.2 million attacksTotal network-layer DDoS attacks mitigated in six months, a pace of roughly 5,343 per hour or 128,000 per day.
  • 29.64 trillion requestsHTTP DDoS requests absorbed at the application layer in the same period, with April 2026 peaking at 6.46 trillion requests in a single month.
  • 1.23 exabitsTotal attack traffic volume for the half year. April alone accounted for 165 petabytes of network-layer attack traffic.

For context, 2025 closed with 47.1 million DDoS attacks observed across the year, more than double the prior year, and 19 separate world-record events. The largest, a UDP flood launched by the Aisuru botnet in November 2025, peaked at 31.4 Tbps, nearly six times the biggest attack of 2024. Botnets like Aisuru and KimWolf, estimated at one to four million infected devices, are the engines behind this scale, which is why the March and April 2026 seizures of botnet infrastructure mattered so much.


The 1 Tbps Club Grew

Network-layer attacks above 1 Tbps per quarterQ4 2025219Q1 2026130Q2 2026805
Attacks exceeding 1 Tbps mitigated per quarter, as reported by Cloudflare. The Q1 to Q2 2026 jump represents a 519 percent increase.

The dip from Q4 2025 to Q1 2026 followed the holiday peak that booter services traditionally drive. The sixfold surge in Q2 shows how quickly capacity returns when new botnets come online, and why single takedowns never hold the line for long.


Where the Attacks Come From and Where They Land

Two shifts defined the first half of 2026. First, the center of gravity moved from raw botnet floods toward reflection and amplification: DNS-based attacks accounted for 34.3 percent of all network-layer activity, with DNS floods climbing from 25.7 to 40 percent of network-layer attacks in one quarter. CLDAP reflection, which abuses exposed LDAP-over-UDP services, surged 580 percent quarter over quarter to become the number three vector.

Second, the target map moved. China received 22.4 percent of attacks in Q2 2026, overtaking the United States at 18.8 percent, with Turkey third during the quarter Ankara hosted the NATO summit. Geopolitical events now show up in DDoS telemetry within hours.

The typical attack is still small: 96.6 percent of network-layer attacks in H1 2026 stayed under 500 Mbps, and 90.6 percent ended within ten minutes. The terabit headlines coexist with a constant background hum of short, cheap floods, the exact product that booter panels sell for a few dollars.


What the Data Means for Defenders

Three practical conclusions fall out of the 2026 numbers.

  1. Assume terabit-class floods exist in your threat model. Even if your likely attackers are smaller, shared infrastructure absorbs their neighbors’ attacks. Capacity planning that stops at your own traffic is not enough.
  2. Watch DNS and CLDAP exposure. Reflection attacks need open resolvers and exposed directory services. Auditing what your network answers to the internet removes you from the amplifier pool and reduces your attack surface at the same time.
  3. Test before an attacker does. The median attack ends in ten minutes because attackers abandon targets that hold. A defense validated by authorized stress testing is the difference between a non-event and an outage. Our DDoS protection guide covers the mitigation layers, and the DDoS explainer breaks down each attack family.

For live numbers between reports, Cloudflare Radar publishes free dashboards of attack trends by country, industry, and vector.


Sources and Further Reading

This article draws on primary sources from law enforcement agencies, government cybersecurity bodies, and independent security researchers. We link them so you can verify every claim.


Frequently Asked Questions

How many DDoS attacks happen per day in 2026?

Cloudflare mitigated roughly 128,000 network-layer attacks per day in the first half of 2026, about 5,343 per hour, on top of 29.64 trillion HTTP DDoS requests across the six-month period.

What is the largest DDoS attack ever recorded?

The largest publicly disclosed attack peaked at 31.4 Tbps in November 2025. It was a UDP flood launched by the Aisuru botnet, nearly six times the size of the largest 2024 attack.

What is the most common DDoS attack type in 2026?

DNS-based attacks lead the network layer, accounting for 34.3 percent of activity in the first half of 2026. DNS floods alone climbed from 25.7 to 40 percent of network-layer attacks between Q1 and Q2.

How long do most DDoS attacks last?

Most attacks are short and small. In the first half of 2026, 96.6 percent of network-layer attacks stayed under 500 Mbps and 90.6 percent ended within ten minutes.