Every year the DDoS record books get rewritten, and 2026 is no exception. The headline shift is no longer the size of a single attack but the cadence: floods above one terabit per second, once a career event for a network engineer, now arrive by the hundreds each quarter.
The most complete public dataset comes from Cloudflare’s DDoS Threat Report for the first half of 2026, built from the company’s global network by its Cloudforce One threat intelligence team. The numbers below are drawn from that report and the independent coverage that followed it.
The Headline Numbers of 2026
- 935 attacks above 1 TbpsNetwork-layer floods exceeding one terabit per second mitigated in the first half of 2026 alone, a category that barely existed a few years ago.
- +519% in one quarterGrowth in 1 Tbps-class attacks between Q1 and Q2 2026, from 130 events to 805. Hyper-volumetric attacks are now a routine, not a record.
- 23.2 million attacksTotal network-layer DDoS attacks mitigated in six months, a pace of roughly 5,343 per hour or 128,000 per day.
- 29.64 trillion requestsHTTP DDoS requests absorbed at the application layer in the same period, with April 2026 peaking at 6.46 trillion requests in a single month.
- 1.23 exabitsTotal attack traffic volume for the half year. April alone accounted for 165 petabytes of network-layer attack traffic.
For context, 2025 closed with 47.1 million DDoS attacks observed across the year, more than double the prior year, and 19 separate world-record events. The largest, a UDP flood launched by the Aisuru botnet in November 2025, peaked at 31.4 Tbps, nearly six times the biggest attack of 2024. Botnets like Aisuru and KimWolf, estimated at one to four million infected devices, are the engines behind this scale, which is why the March and April 2026 seizures of botnet infrastructure mattered so much.
The 1 Tbps Club Grew
The dip from Q4 2025 to Q1 2026 followed the holiday peak that booter services traditionally drive. The sixfold surge in Q2 shows how quickly capacity returns when new botnets come online, and why single takedowns never hold the line for long.
Where the Attacks Come From and Where They Land
Two shifts defined the first half of 2026. First, the center of gravity moved from raw botnet floods toward reflection and amplification: DNS-based attacks accounted for 34.3 percent of all network-layer activity, with DNS floods climbing from 25.7 to 40 percent of network-layer attacks in one quarter. CLDAP reflection, which abuses exposed LDAP-over-UDP services, surged 580 percent quarter over quarter to become the number three vector.
Second, the target map moved. China received 22.4 percent of attacks in Q2 2026, overtaking the United States at 18.8 percent, with Turkey third during the quarter Ankara hosted the NATO summit. Geopolitical events now show up in DDoS telemetry within hours.
The typical attack is still small: 96.6 percent of network-layer attacks in H1 2026 stayed under 500 Mbps, and 90.6 percent ended within ten minutes. The terabit headlines coexist with a constant background hum of short, cheap floods, the exact product that booter panels sell for a few dollars.
What the Data Means for Defenders
Three practical conclusions fall out of the 2026 numbers.
- Assume terabit-class floods exist in your threat model. Even if your likely attackers are smaller, shared infrastructure absorbs their neighbors’ attacks. Capacity planning that stops at your own traffic is not enough.
- Watch DNS and CLDAP exposure. Reflection attacks need open resolvers and exposed directory services. Auditing what your network answers to the internet removes you from the amplifier pool and reduces your attack surface at the same time.
- Test before an attacker does. The median attack ends in ten minutes because attackers abandon targets that hold. A defense validated by authorized stress testing is the difference between a non-event and an outage. Our DDoS protection guide covers the mitigation layers, and the DDoS explainer breaks down each attack family.
For live numbers between reports, Cloudflare Radar publishes free dashboards of attack trends by country, industry, and vector.
