# Cloudflare’s H1 2026 DDoS report shows hyper-volumetric attacks surging while most attacks stay short

Cloudflare reports a sharp rise in 1 Tbps-plus attacks and DNS amplification activity in the first half of 2026, while most mitigated attacks remained brief and below 500 Mbps—an argument for automated always-on controls rather than manual response.

Cloudflare’s first half-year DDoS report records 935 network-layer attacks above 1 Tbps and a 519% Q1-to-Q2 increase, but says 96.62% of attacks stayed below 500 Mbps and 90.60% ended within 10 minutes. The figures are Cloudflare-network telemetry, not a neutral census of the internet.

- Status: Active
- Published: 2026-09-03T22:47:40+12:00
- Updated: 2026-09-03T22:47:40+12:00
- Categories: Cloud & Infrastructure, Edge & CDN
- Tags: always-on mitigation, bot attacks, Cloudflare, DDoS, DNS amplification, network security
- Canonical HTML: https://beyondthe.news/dossiers/cloudflare-h1-2026-ddos-hypervolumetric-attacks

## What changed

Cloudflare’s first H1 DDoS Threat Report combines Q1 and Q2 2026 telemetry and reports 935 network-layer attacks above 1 Tbps, with a 519% quarter-over-quarter increase from Q1 to Q2. DNS-based attacks represented 34.3% of network-layer activity, while DNS Floods rose from 25.7% to 40.0% quarter-over-quarter and CLDAP Floods rose 580% to become the third-largest vector in Q2. At the same time, 96.62% of network-layer attacks remained below 500 Mbps and 90.60% lasted under 10 minutes. Cloudflare says it mitigated 23.2 million network-layer and 29.64 trillion HTTP DDoS requests in the first half of the year.

## Why it matters

The operational implication is asymmetric: the largest attacks are becoming more common, but most attacks finish faster than a human response cycle. Teams therefore need preconfigured, continuously active network and application-layer protection, DNS hardening and tested escalation paths rather than relying on on-demand mitigation. The report also suggests that capacity planning based only on headline bandwidth misses shorter reflection/amplification and low-and-slow attack patterns.

## The extreme tail is growing

Cloudflare reports 935 network-layer attacks exceeding 1 Tbps in H1 2026 and a 519% increase from Q1 to Q2. It also reports 23.2 million network-layer attacks and 29.64 trillion HTTP DDoS requests mitigated across its network.

## DNS and reflection vectors are moving

DNS-based attacks accounted for 34.3% of network-layer activity. DNS Floods rose from 25.7% to 40.0% quarter-over-quarter, while CLDAP Floods increased 580% quarter-over-quarter to become the third-largest vector in Q2.

## Most attacks leave little time for intervention

Despite the growth in hyper-volumetric attacks, Cloudflare says 96.62% of network-layer attacks were below 500 Mbps and 90.60% ended in under 10 minutes. A small attack can still overwhelm an unprotected origin, so duration and bandwidth should not be treated as safety thresholds.

## The data is directional, not universal

These measurements come from traffic Cloudflare mitigated on its own network. They reveal useful attack patterns and preparedness implications, but should not be read as a complete global incidence rate or as proof that every provider sees the same mix.

## Key details

- Cloudflare reports 935 network-layer DDoS attacks above 1 Tbps in H1 2026.
- The report records a 519% quarter-over-quarter increase in 1 Tbps-plus attacks from Q1 to Q2.
- DNS-based attacks were 34.3% of network-layer activity; DNS Floods rose from 25.7% to 40.0% quarter-over-quarter.
- CLDAP Floods increased 580% quarter-over-quarter and became the third-largest network-layer vector in Q2.
- 96.62% of network-layer attacks were below 500 Mbps and 90.60% lasted under 10 minutes.
- Cloudflare says it mitigated 23.2 million network-layer and 29.64 trillion HTTP DDoS requests in H1.
- The report is based on Cloudflare network telemetry and is not an independent global census.

## Builder takeaways

- Keep network and application-layer mitigation enabled before an incident; the reported attack durations are shorter than a manual procurement or escalation cycle.
- Harden authoritative and recursive DNS paths and monitor for reflection/amplification signatures, not only volumetric bandwidth.
- Test origin exposure and failover assumptions against attacks well below 500 Mbps; that threshold is not a survivability guarantee.
- Use provider telemetry as one input to capacity and incident planning, and compare it with your own logs and another source where possible.
- Document post-attack recovery steps because short attacks can still cause retransmissions, timeouts and downstream degradation after traffic falls.

## What to watch

- Whether subsequent quarters confirm the reported rise in hyper-volumetric and DNS-reflection activity.
- Independent measurements from other network operators and security researchers.
- Changes in managed DDoS pricing, automatic mitigation defaults and origin-protection requirements.
- Whether CLDAP and other reflection vectors continue to move up the attack ranking.
- Post-incident data on recovery time and downstream service degradation after short attacks.

## Uncertainties

- Cloudflare’s telemetry reflects attacks reaching or mitigated by Cloudflare and may not represent providers or origins outside its network.
- The report combines heterogeneous customers, geographies and protection configurations.
- Quarter-over-quarter percentage changes can be sensitive to a low prior-quarter baseline.
- The report describes attack traffic, not the fraction of customer incidents that caused user-visible downtime.

## Sources

- [Cloudflare DDoS Threat Report H1 2026](https://blog.cloudflare.com/ddos-threat-report-2026-h1/) — Cloudflare · primary_report · 2026-08-11T00:00:00+12:00. First-party H1 2026 report with attack-volume, vector, duration and bandwidth statistics based on Cloudflare network telemetry.
- [Cloudflare DDoS protection](https://www.cloudflare.com/ddos/) — Cloudflare · primary_documentation. First-party product and mitigation context; does not independently validate the report’s global prevalence claims.

