Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Gaming
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Contact Us
Reading: 1 Tbps Attacks Soar as DNS Floods And Geopolitical Tensions Drive A New Wave
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > IT Security > 1 Tbps Attacks Soar as DNS Floods And Geopolitical Tensions Drive A New Wave
IT Security

1 Tbps Attacks Soar as DNS Floods And Geopolitical Tensions Drive A New Wave

Cloudflare’s H1 2026 DDoS Threat Report shows 935 network-layer attacks exceeding 1Tbps in the first half of the year, with hyper-volumetric attacks surging 519% between Q1 and Q2 as DNS floods and geopolitical tensions drove a new wave of increasingly powerful attacks.

Matthew Giannelis
Last updated: August 12, 2026 6:05 pm
Matthew Giannelis
Share
SHARE

The number of DDoS attacks exceeding 1 terabit per second has surged sharply in 2026, exposing a growing weakness in the infrastructure that keeps major online services operating.

Cloudflare’s latest data shows it mitigated 935 network-layer DDoS attacks above 1Tbps during the first half of the year, with 805 occurring in the second quarter alone.

That means attacks at a scale once regarded as exceptional are now appearing with a frequency that security teams can no longer treat as an unusual event.

The increase is particularly stark between the first and second quarters, when attacks exceeding 1Tbps rose more than six-fold, according to Cloudflare’s analysis of traffic across its global network.

At the same time, the wider volume of attacks continued at an extraordinary rate. Cloudflare says it mitigated 23.2 million network-layer DDoS attacks during H1 2026.

That equates to about 5,343 network-layer attacks every hour, or roughly 128,000 attacks every day, before accounting for the separate 29.64 trillion HTTP DDoS requests also recorded.

The figures suggest the threat is no longer defined simply by the occasional record-breaking attack. What matters is the growing frequency with which extremely large attacks are appearing.

Hyper-volumetric attacks see a more than 6x surge

Hyper-volumetric DDoS — attacks defined as exceeding 1 terabit per second (Tbps), 1 billion packets per second (Bpps), or 1 million requests per second (Mrps) — has been a growth category across Radar reporting. 2026 is proving to be no different.

During the second quarter, Cloudflare mitigated 805 network-layer attacks exceeding 1 Tbps, representing a more than six-fold increase over the previous quarter.

Hyper-volumetric attacks

A 1Tbps attack is not merely a large amount of unwanted traffic. It can overwhelm network connections, security equipment and data-centre infrastructure with a volume of traffic that leaves little room for conventional defensive measures.

The scale also changes the economics of disruption. Attackers don’t necessarily need to keep a target offline for hours if they can generate overwhelming traffic for a few minutes, or even seconds.

Cloudflare’s data shows most attacks are considerably smaller, with 96.62 per cent of network-layer attacks remaining below 500Mbps during the first half of 2026.

But size should not be confused with safety. A 100Mbps attack can overwhelm an inadequately protected website, while 100Gbps can put an unprotected data centre under severe pressure.

The most alarming attacks can also arrive and disappear before a human security team has time to respond. Cloudflare says 90.60 per cent of network-layer attacks in H1 lasted less than 10 minutes.

Some of the largest attacks observed by the company have lasted only seconds, making manual intervention effectively irrelevant once the attack is already underway.

The data also shows that attackers are changing the techniques used to generate these attacks. DNS-based attacks accounted for 34.3 per cent of network-layer attacks during H1.

Their share increased from 25.7 per cent in the first quarter to 40 per cent in the second, putting DNS infrastructure under substantially greater pressure.

An even sharper change occurred with CLDAP Flood attacks, which increased by 881.9 per cent quarter-on-quarter to become the third-largest network-layer attack vector in Q2.

CLDAP attacks exploit publicly exposed Active Directory services using UDP, allowing attackers to use vulnerable systems as amplifiers against a target.

The significance of the change is that attackers are not simply producing more traffic. They are looking for increasingly effective ways to generate disruptive volumes using weaknesses in widely deployed infrastructure.

The targets are changing too, and that is where the data takes on a broader public-interest dimension.

Cloudflare recorded a major increase in attacks against government organisations during the second quarter, with the sector jumping from 29th to ninth in its ranking of industries by share of mitigated HTTP DDoS requests.

The shift followed the February 28 military strikes involving Israel, the United States and Iran, after which researchers recorded a sharp increase in hacktivist DDoS activity against government organisations.

Media, Production & Publishing was the most attacked industry in both quarters, accounting for 14.2 per cent of all mitigated HTTP DDoS requests.


Top 10 Most Attacked Industries:H1 2026 - 1Tbps Attacks

That finding matters because news organisations increasingly operate the digital infrastructure through which the public receives information during wars, elections, disasters and other major events.

The geographical data points to the same pattern. China accounted for 22.4 per cent of global HTTP DDoS requests in Q2, followed by the United States at 18.8 per cent.

Turkey climbed to third place after its share of global attack traffic more than doubled, coinciding with security operations surrounding the Ankara NATO Summit.

Taken together, the figures paint a picture of DDoS attacks becoming more closely connected to the world’s political calendar, rather than remaining purely opportunistic attacks against whoever happens to be vulnerable.

There was one notable interruption to that growth. April recorded the highest monthly DDoS volume, reaching 6.46 trillion requests and 165 petabytes of traffic, before activity declined.

That decline followed Operation PowerOFF, a 21-country law enforcement operation targeting more than 75,000 users of DDoS-for-hire services.

The operation resulted in 53 domains being taken down, 25 search warrants and four arrests, although the available data does not establish that the enforcement action alone caused the subsequent fall in attack activity.

For organisations running critical digital services, however, the larger trend is difficult to dismiss.

The internet is now facing millions of DDoS attacks alongside a rapidly increasing number of attacks capable of exceeding 1Tbps, while attackers continue to develop new amplification techniques.

The question is no longer whether organisations will experience DDoS activity. It is whether the infrastructure supporting essential services can absorb an attack that arrives at extraordinary scale and disappears before a human can react.

The first half of 2026 provides a clear warning: 1Tbps attacks are no longer isolated anomalies. They are becoming a recurring feature of the global threat landscape, and that changes the risk facing almost every organisation that depends on the internet.

ByMatthew Giannelis
Follow:
Secondary editor and executive officer at Tech Business News. An IT support engineer for 20 years he's also an advocate for cyber security and anti-spam laws.
Previous Article Australian Cyber Security Leader Jamie Norton To Help Guide ISACA Global Strategy, Supporting The Digital Trust Workforce Australian Cyber Security Leader Reappointed To ISACA Board
Next Article TIO calls on Government to act on telco inequality - Overhaul Of Australia’s Telecommunications Regulatory Framework - Cynthia Gebert TIO Calls For Overhaul Of Australia’s Telecommunications Regulatory Framework
Leave a Comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks

Tech Articles

Your Phone Is Spying on You and tracking location

Your Phone Is Spying on You — Here’s How to Stop It

Your phone is spying, tracking your location, searches, app activity,…

July 11, 2026
What Building My Own News Startup Taught Me - Matthew Giannelis

What Building My Own News Startup Taught Me About Journalism, Business and the Internet

Building my own news startup taught me that great journalism…

August 6, 2026
Online Privacy - Ways to protect your personal information

Want Complete Online Privacy? Disconnecting From the Internet May Be The Only Certain Option

Complete online privacy is becoming increasingly difficult as websites, apps…

August 8, 2026

Recent News

Samsung’s Exynos chipset “Internet-to-baseband Google
IT Security

Google’s Project Zero Calls Urgent Attention To 18 Security Vulnerabilities Found In Samsung’s Exynos Chipsets

3 Min Read
Configuration Probing backup weakness
IT Security

Your Backups Might Be Your Greatest Weakness

5 Min Read
Passkeys are winning, but security leaders must raise the bar says Yubico - Christopher Harrell
IT Security

Passkeys Are Gaining Ground, But Yubico Urges Security Leaders To Step Up

8 Min Read
WordFence 116 Vulnerabilities Disclosed in 88 WordPress Plugins - tech news
IT Security

WordFence Discloses 116 Vulnerabilities Found In 88 WordPress Plugins

3 Min Read
Tech News - Technology Business

Tech Business News

In 2026, technology news is shaping business outcomes faster than ever—driven by AI adoption, rising cyber risk, cloud modernisation, data regulation, and constant platform change.
 
Tech News keeps Australian organisations and industry professionals informed with timely reporting and practical coverage across AI, cybersecurity, cloud, enterprise IT, startups, science, people and business, plus major world and local news impacting the tech sector.
 
Tech Business News publishes news and analysis designed to be clear, relevant, and easy to act on. It supports the industry with technology news reports, whitepaper publishing services, and a range of media, advertising and publishing options 

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

September, 26, 2026

Contact

Tech Business News
Melbourne, Australia
Werribee 3030
Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.

Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2026

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?