Cloudflare Says Terabit-Scale DDoS Attacks Jumped Fivefold This Spring

The web-infrastructure giant mitigated more than 800 network attacks above 1 Tbps in the second quarter, up from 130 the quarter before.

ThreatVectr Newsdesk· 4 min read
A young male hacker in handcuffs, with digital devices and a network diagram in the background
Share

Key points

  • Cloudflare blocked more than 800 network-layer DDoS attacks larger than 1 Tbps in the second quarter of 2026, up from 130 in the first quarter.
  • The company mitigated 23.2 million network-layer attacks and 29.64 trillion malicious web requests across the first half of the year.
  • One recent attack peaked at 31.4 Tbps and 200 million requests per second, launched by the Aisuru/Kimwolf botnet.
  • Attacks abusing DNS reached 40% of network-layer traffic in Q2, and CLDAP-based floods rose 881.9% quarter over quarter.
  • Activity dipped after April, which Cloudflare tentatively links to Operation PowerOFF, an international police effort against DDoS-for-hire services.

Cloudflare, the company that shields roughly a fifth of the web from attack, says the biggest kind of denial-of-service attack got a lot more common this spring.

A denial-of-service attack, or DDoS, is when criminals flood a website or network with so much junk traffic that real visitors cannot get through. Think of a shop doorway jammed with people who have no intention of buying anything.

In the three months to the end of June, Cloudflare says it stopped more than 800 of these floods that crossed 1 terabit per second. That is an enormous volume of traffic. The quarter before, it saw only 130 attacks that big.

The figures came in a report Cloudflare shared with BleepingComputer and presented at the Black Hat security conference.

How big are these attacks getting?

Very big, and one recent record shows the ceiling. Cloudflare says it recently absorbed a strike that peaked at 31.4 Tbps and 200 million requests every second, blamed on a botnet called Aisuru/Kimwolf. A botnet is a network of hacked devices, often home routers and cameras, that criminals use to fire traffic at a target.

Across the first half of 2026, Cloudflare counted 23.2 million network-layer attacks and 29.64 trillion malicious web requests.

Attacks in the middle brackets also grew. Floods between 500 Gbps and 1 Tbps rose 143%. Those between 100 and 500 Gbps went up 105%.

Attack size (Q2 2026) Change vs Q1
Over 1 Tbps +519% (130 to 800+)
500 Gbps to 1 Tbps +143%
100 to 500 Gbps +105%
Network-layer attacks overall +31.2%

Most attacks are still small and short. Cloudflare says 96.62% of network-layer attacks stayed below 50 Mbps, and 90.6% ended within ten minutes. But the tail is getting longer: attacks lasting over three hours roughly doubled, from 0.387% to 0.828% of the total.

Why did things quieten down after April?

Cloudflare thinks the police had something to do with it. Activity peaked in April at 6.46 trillion malicious web requests and 165 petabytes of network traffic, then slid.

The firm tentatively credits Operation PowerOFF, an international crackdown on "booter" and "stresser" sites that rent DDoS firepower by the hour. That operation led to four arrests, the seizure of 53 domains, and warning notices sent to 75,000 users of those services.

Warning letters may sound gentle. In practice, telling a teenager that police know their name tends to change behaviour fast.

What kinds of attacks are trending?

Old tricks with new volume. The dominant technique this quarter was the DNS flood, which hammers the internet's phonebook system, the Domain Name System that translates website names into numeric addresses. DNS floods accounted for 40% of network-layer attacks in Q2, up from 25.7%.

A related trick called CLDAP reflection, which bounces traffic off exposed directory servers to make it hit harder, jumped 881.9% quarter over quarter. This is the DDoS equivalent of a classic amplifier attack: send a small question, get a giant answer sent to your victim.

Who is getting hit?

Media, production and publishing companies took the biggest share of malicious web traffic in the first half, at 14.2% of mitigated requests. Government sites also saw a notable rise, which Cloudflare links to hacktivism around the US-Israeli military operation against Iran.

For ordinary readers, DDoS attacks rarely leak personal data. What they do is knock services offline. If your bank app, streaming service or council website is unreachable for a stretch, this is often why.

© 2026 Threat Vectr