Cloudflare Says Terabit-Scale DDoS Attacks Jumped Fivefold This Spring

The web-infrastructure giant mitigated more than 800 network attacks above 1 Tbps in the second quarter, up from 130 the quarter before.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
Network traffic visualization displaying massive terabit-scale DDoS attack waves, with comparative data showing 800+ attacks above 1 Tbps intensity spike across
Share

Key points

  • Cloudflare blocked more than 800 network-layer DDoS attacks larger than 1 Tbps in the second quarter of 2026, up from 130 in the first quarter.
  • The company mitigated 23.2 million network-layer attacks and 29.64 trillion malicious web requests across the first half of the year.
  • One recent attack peaked at 31.4 Tbps and 200 million requests per second, launched by the Aisuru/Kimwolf botnet.
  • Attacks abusing DNS reached 40% of network-layer traffic in Q2, and CLDAP-based floods rose 881.9% quarter over quarter.
  • Activity dipped after April, which Cloudflare tentatively links to Operation PowerOFF, an international police effort against DDoS-for-hire services.

Cloudflare, which shields roughly a fifth of the web from attack, says the biggest kind of denial-of-service attack got a lot more common this spring. The numbers aren't subtle.

A denial-of-service attack, or DDoS, is when criminals flood a website or network with so much junk traffic that real visitors can't get through. In the three months to the end of June, Cloudflare stopped more than 800 of these floods crossing 1 terabit per second, against only 130 that big the quarter before.

The figures came in a report shared with BleepingComputer and presented at the Black Hat security conference.

How big are these attacks getting?

Very big. Cloudflare recently absorbed a strike peaking at 31.4 Tbps and 200 million requests every second, blamed on a botnet called Aisuru/Kimwolf. A botnet is a network of compromised devices that criminals marshal to fire traffic at a target. We've followed this particular operation since May: our story from 28 May 2026, "Justice Department Charges Ottawa Man With Operating Kimwolf DDoS Botnet", covered federal charges against a 23-year-old accused of renting out the Aisuru variant for paid attacks.

Across the first half of 2026, Cloudflare counted 23.2 million network-layer attacks and 29.64 trillion malicious web requests.

The middle brackets also grew. Floods between 500 Gbps and 1 Tbps rose 143%; those between 100 and 500 Gbps went up 105%.

Attack size (Q2 2026) Change vs Q1
Over 1 Tbps +519% (130 to 800+)
500 Gbps to 1 Tbps +143%
100 to 500 Gbps +105%
Network-layer attacks overall +31.2%

Most attacks are still small and short. Cloudflare says 96.62% of network-layer attacks stayed below 50 Mbps, and 90.6% ended within ten minutes. The tail is lengthening, though: attacks lasting over three hours roughly doubled, from 0.387% to 0.828% of the total.

Why did things quieten down after April?

Cloudflare thinks the police had something to do with it. Activity peaked in April at 6.46 trillion malicious web requests and 165 petabytes of network traffic, then slid. The firm tentatively credits Operation PowerOFF, an international crackdown on "booter" and "stresser" sites that rent DDoS firepower by the hour. That operation produced four arrests, the seizure of 53 domains, and warning notices sent to 75,000 users of those services.

Warning letters may sound gentle. Telling someone that police have their name tends to change behaviour fast, and the April peak suggests the timing wasn't coincidental.

What kinds of attacks are trending?

Old tricks, new volume. The dominant technique this quarter was the DNS flood, hammering the Domain Name System that translates website names into numeric addresses. DNS floods accounted for 40% of network-layer attacks in Q2, up from 25.7% in Q1.

A related method called CLDAP reflection, which bounces traffic off exposed directory servers to amplify its force, jumped 881.9% quarter over quarter. Send a small query, get a giant answer delivered to your victim: it's a classic amplifier attack dressed in fresh clothes.

Who is getting hit?

Media, production and publishing companies took the largest share of malicious web traffic in the first half, at 14.2% of mitigated requests. Government sites also saw a notable rise, which Cloudflare links to hacktivism around the US-Israeli military operation against Iran.

For most readers, DDoS attacks don't leak personal data. What they do is knock services offline. If your bank's app or your council's website is unreachable for a stretch, a flood like this is often the reason. The record at 31.4 Tbps is a useful reminder that the infrastructure absorbing these hits is doing genuinely heavy lifting on everyone's behalf.

© 2026 Threat Vectr