Cloudflare said it mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion malicious HTTP requests in the first half of 2026, with April marking the peak of activity. The sharpest growth came from hyper-volumetric attacks: 935 network-layer attacks exceeded 1 Tbps in H1, including 805 in Q2, up from about 130 in Q1. The company said attackers increasingly shifted from traditional botnet floods to reflection and amplification methods, with DNS-based attacks becoming the leading network-layer vector and CLDAP floods rising 580 percent quarter over quarter to become the third most common vector in Q2.
Cloudflare linked the wave to geopolitical flashpoints and major events, saying media, production, and publishing became the most targeted sector as attackers sought to disrupt reporting and suppress information around the wars involving Ukraine and Iran and the FIFA World Cup. Government entities also saw increased targeting following the US-Israeli operation against Iran, while the US, China, and Turkey ranked among the most-targeted regions, including elevated attacks around the Ankara NATO Summit. Cloudflare said DDoS activity declined after April and suggested the drop may be tied to Operation PowerOFF, a multinational law-enforcement crackdown on DDoS-for-hire services.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
On August 13, 2026, Cloudflare's Cloudforce One published the 25th edition of its DDoS Threat Report covering January through June 2026. The report summarized 23.2 million network-layer attacks, 29.64 trillion HTTP DDoS requests, and a sharp rise in hypervolumetric attacks above 1 Tbit/s.
Cloudflare published its H1 2026 DDoS Threat Report, stating it mitigated 23.2 million network-layer attacks and 29.64 trillion HTTP DDoS requests during the first half of the year. The report highlighted DNS floods as the dominant vector and media organizations as the most-targeted sector.
Cloudflare reported that Turkey rose to the third most-targeted country or region in Q2 after more than doubling its share of global attack traffic. The increase was linked to the Ankara NATO summit held in July.
Cloudflare observed the highest DDoS activity in April 2026, including 6.46 trillion HTTP DDoS requests and 165 petabytes of network-layer attack traffic. The company said activity declined after this peak.
On February 28, 2026, Israel and the United States launched Operation Epic Fury targeting Iran’s leadership and infrastructure. Cloudflare later linked subsequent hacktivist DDoS activity and increased attacks on government entities to this geopolitical event.
Within 72 hours of Operation Epic Fury, security researchers recorded 149 hacktivist DDoS claims against 110 organizations across 16 countries. Nearly 47.8% of the claimed targets were in the government sector.
In December 2025, Cloudflare mitigated a 31.4 Tbps DDoS attack, which the article attributes to the Aisuru/Kimwolf botnet. The incident illustrated how compromised devices such as routers, cameras, servers, appliances, and smart TVs can be assembled into massive botnets.
Cloudflare mitigated 805 network-layer DDoS attacks exceeding 1 Tbps in Q2 2026, a 519% increase over Q1. The quarter also saw a shift toward DNS-related reflection and amplification techniques.
Cloudflare said DDoS activity dropped after April 2026 partly because of Operation PowerOFF, a 21-country law-enforcement effort against DDoS-for-hire networks. The operation seized 53 domains, executed 25 search warrants, arrested four suspects, and targeted more than 75,000 users to date.
Cloudflare recorded 130 network-layer DDoS attacks exceeding 1 Tbps during Q1 2026. This served as the baseline before a much larger surge in the following quarter.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
11 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecyberveille.ch
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourceblog.cloudflare.com
Open sourcebleepingcomputer.com
Open sourcesdxcentral.com
Open sourceblog.cloudflare.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.