The number of DDoS attacks exceeding 1 terabit per second has surged sharply in 2026, exposing a growing weakness in the infrastructure that keeps major online services operating.
Cloudflare’s latest data shows it mitigated 935 network-layer DDoS attacks above 1Tbps during the first half of the year, with 805 occurring in the second quarter alone.
That means attacks at a scale once regarded as exceptional are now appearing with a frequency that security teams can no longer treat as an unusual event.
The increase is particularly stark between the first and second quarters, when attacks exceeding 1Tbps rose more than six-fold, according to Cloudflare’s analysis of traffic across its global network.
At the same time, the wider volume of attacks continued at an extraordinary rate. Cloudflare says it mitigated 23.2 million network-layer DDoS attacks during H1 2026.
That equates to about 5,343 network-layer attacks every hour, or roughly 128,000 attacks every day, before accounting for the separate 29.64 trillion HTTP DDoS requests also recorded.
The figures suggest the threat is no longer defined simply by the occasional record-breaking attack. What matters is the growing frequency with which extremely large attacks are appearing.
Hyper-volumetric attacks see a more than 6x surge
Hyper-volumetric DDoS — attacks defined as exceeding 1 terabit per second (Tbps), 1 billion packets per second (Bpps), or 1 million requests per second (Mrps) — has been a growth category across Radar reporting. 2026 is proving to be no different.
During the second quarter, Cloudflare mitigated 805 network-layer attacks exceeding 1 Tbps, representing a more than six-fold increase over the previous quarter.

A 1Tbps attack is not merely a large amount of unwanted traffic. It can overwhelm network connections, security equipment and data-centre infrastructure with a volume of traffic that leaves little room for conventional defensive measures.
The scale also changes the economics of disruption. Attackers don’t necessarily need to keep a target offline for hours if they can generate overwhelming traffic for a few minutes, or even seconds.
Cloudflare’s data shows most attacks are considerably smaller, with 96.62 per cent of network-layer attacks remaining below 500Mbps during the first half of 2026.
But size should not be confused with safety. A 100Mbps attack can overwhelm an inadequately protected website, while 100Gbps can put an unprotected data centre under severe pressure.
The most alarming attacks can also arrive and disappear before a human security team has time to respond. Cloudflare says 90.60 per cent of network-layer attacks in H1 lasted less than 10 minutes.
Some of the largest attacks observed by the company have lasted only seconds, making manual intervention effectively irrelevant once the attack is already underway.
The data also shows that attackers are changing the techniques used to generate these attacks. DNS-based attacks accounted for 34.3 per cent of network-layer attacks during H1.
Their share increased from 25.7 per cent in the first quarter to 40 per cent in the second, putting DNS infrastructure under substantially greater pressure.
An even sharper change occurred with CLDAP Flood attacks, which increased by 881.9 per cent quarter-on-quarter to become the third-largest network-layer attack vector in Q2.
CLDAP attacks exploit publicly exposed Active Directory services using UDP, allowing attackers to use vulnerable systems as amplifiers against a target.
The significance of the change is that attackers are not simply producing more traffic. They are looking for increasingly effective ways to generate disruptive volumes using weaknesses in widely deployed infrastructure.
The targets are changing too, and that is where the data takes on a broader public-interest dimension.
Cloudflare recorded a major increase in attacks against government organisations during the second quarter, with the sector jumping from 29th to ninth in its ranking of industries by share of mitigated HTTP DDoS requests.
The shift followed the February 28 military strikes involving Israel, the United States and Iran, after which researchers recorded a sharp increase in hacktivist DDoS activity against government organisations.
Media, Production & Publishing was the most attacked industry in both quarters, accounting for 14.2 per cent of all mitigated HTTP DDoS requests.

That finding matters because news organisations increasingly operate the digital infrastructure through which the public receives information during wars, elections, disasters and other major events.
The geographical data points to the same pattern. China accounted for 22.4 per cent of global HTTP DDoS requests in Q2, followed by the United States at 18.8 per cent.
Turkey climbed to third place after its share of global attack traffic more than doubled, coinciding with security operations surrounding the Ankara NATO Summit.
Taken together, the figures paint a picture of DDoS attacks becoming more closely connected to the world’s political calendar, rather than remaining purely opportunistic attacks against whoever happens to be vulnerable.
There was one notable interruption to that growth. April recorded the highest monthly DDoS volume, reaching 6.46 trillion requests and 165 petabytes of traffic, before activity declined.
That decline followed Operation PowerOFF, a 21-country law enforcement operation targeting more than 75,000 users of DDoS-for-hire services.
The operation resulted in 53 domains being taken down, 25 search warrants and four arrests, although the available data does not establish that the enforcement action alone caused the subsequent fall in attack activity.
For organisations running critical digital services, however, the larger trend is difficult to dismiss.
The internet is now facing millions of DDoS attacks alongside a rapidly increasing number of attacks capable of exceeding 1Tbps, while attackers continue to develop new amplification techniques.
The question is no longer whether organisations will experience DDoS activity. It is whether the infrastructure supporting essential services can absorb an attack that arrives at extraordinary scale and disappears before a human can react.
The first half of 2026 provides a clear warning: 1Tbps attacks are no longer isolated anomalies. They are becoming a recurring feature of the global threat landscape, and that changes the risk facing almost every organisation that depends on the internet.

