What changed
Cloudflare’s first H1 DDoS Threat Report combines Q1 and Q2 2026 telemetry and reports 935 network-layer attacks above 1 Tbps, with a 519% quarter-over-quarter increase from Q1 to Q2. DNS-based attacks represented 34.3% of network-layer activity, while DNS Floods rose from 25.7% to 40.0% quarter-over-quarter and CLDAP Floods rose 580% to become the third-largest vector in Q2. At the same time, 96.62% of network-layer attacks remained below 500 Mbps and 90.60% lasted under 10 minutes. Cloudflare says it mitigated 23.2 million network-layer and 29.64 trillion HTTP DDoS requests in the first half of the year.
Why it matters
The operational implication is asymmetric: the largest attacks are becoming more common, but most attacks finish faster than a human response cycle. Teams therefore need preconfigured, continuously active network and application-layer protection, DNS hardening and tested escalation paths rather than relying on on-demand mitigation. The report also suggests that capacity planning based only on headline bandwidth misses shorter reflection/amplification and low-and-slow attack patterns.
The extreme tail is growing
Cloudflare reports 935 network-layer attacks exceeding 1 Tbps in H1 2026 and a 519% increase from Q1 to Q2. It also reports 23.2 million network-layer attacks and 29.64 trillion HTTP DDoS requests mitigated across its network.
DNS and reflection vectors are moving
DNS-based attacks accounted for 34.3% of network-layer activity. DNS Floods rose from 25.7% to 40.0% quarter-over-quarter, while CLDAP Floods increased 580% quarter-over-quarter to become the third-largest vector in Q2.
Most attacks leave little time for intervention
Despite the growth in hyper-volumetric attacks, Cloudflare says 96.62% of network-layer attacks were below 500 Mbps and 90.60% ended in under 10 minutes. A small attack can still overwhelm an unprotected origin, so duration and bandwidth should not be treated as safety thresholds.
The data is directional, not universal
These measurements come from traffic Cloudflare mitigated on its own network. They reveal useful attack patterns and preparedness implications, but should not be read as a complete global incidence rate or as proof that every provider sees the same mix.