Cloudflare’s H1 2026 DDoS Report Turns the News Cycle Into an Attack Signal
Cloudflare's first combined half-year DDoS report shows attacks over 1 Tbps grew sixfold quarter over quarter, with targeting increasingly tracking real-world news events from the Iran strikes to a...
Cloudflare’s Cloudforce One threat intelligence team published its first combined half-year DDoS Threat Report on August 11, 2026, and the headline number is stark: network-layer attacks exceeding 1 Tbps grew more than sixfold between the first and second quarters of the year, a 519 percent quarter-over-quarter surge. The more interesting finding buried inside the report, though, is not about size. It is about timing. Across the report’s data, the clearest pattern is that DDoS targeting increasingly tracks the news cycle: strikes on Iran, the war in Ukraine, a World Cup, a NATO summit in Turkey. Attackers, it turns out, read the headlines too.
Table Of Content
- A Sixfold Jump in the Heaviest Attacks
- DNS and CLDAP Floods Push Botnets Aside
- Where the Standing Record Still Sits
- Media Outlets Take the Brunt, Gambling Sites Close the Gap
- When Geopolitics Writes the Target List
- Operation Epic Fury and the Strikes on Iran
- Turkey’s Climb Ahead of the Ankara NATO Summit
- Government’s Steepest Climb of the Year
- Brazil Overtakes the US as the Top Source of Attack Traffic
- Law Enforcement Chips Away at the Supply Side
- What This Means for Defenders
A Sixfold Jump in the Heaviest Attacks
Cloudflare mitigated 935 network-layer DDoS attacks that exceeded 1 Tbps across the first half of 2026, more than four times the 219 such attacks the company recorded in the fourth quarter of 2025 alone. Almost all of that half-year growth landed in the second quarter: 130 attacks crossed the 1 Tbps line in Q1, and roughly 805 crossed it in Q2, the 519 percent jump that anchors the report’s headline.
Zoom out and the overall volume is larger still. Cloudflare says it mitigated 23.2 million network-layer DDoS attacks and blocked 29.64 trillion malicious HTTP requests over the six-month period, an average of about 5,343 network-layer attacks every hour, or roughly 128,000 a day. April was the single busiest month, with 6.46 trillion HTTP requests and 165 petabytes of attack traffic absorbed in thirty days, a figure independently confirmed in SiliconANGLE’s review of the report.
Most of that volume is still small and short-lived: roughly nine in ten attacks resolved in under ten minutes, consistent with the throwaway, opportunistic pattern DDoS defenders have described for years. What changed is the tail. Attacks lasting more than three hours, still under 1 percent of the total, nearly tripled in raw count quarter over quarter, climbing from around 38,900 to roughly 109,000, a detail BleepingComputer and SiliconANGLE both flagged. That suggests at least some attackers are choosing to sustain pressure rather than fire once and move on.
DNS and CLDAP Floods Push Botnets Aside
The report also describes a shift in how attacks get built. Cloudflare says the center of gravity moved from botnet-driven floods toward reflection and amplification techniques: methods that bounce a small, spoofed request off a misconfigured third-party server to generate a disproportionately large response aimed at the real target. DNS-based attacks accounted for 34.3 percent of all network-layer activity in H1 2026, and DNS floods specifically climbed from 25.7 percent of network-layer attacks in Q1 to 40.0 percent in Q2. CLDAP floods, which abuse the Connectionless Lightweight Directory Access Protocol that many Active Directory environments still expose, surged sharply enough quarter over quarter to become the third most common network-layer vector by Q2.
Where the Standing Record Still Sits
For scale, it is worth remembering where the outer edge of this threat currently sits. Cloudflare’s own fourth-quarter 2025 report disclosed the current all-time record: a 31.4 Tbps attack that lasted just 35 seconds, followed within weeks by a separate flood that exceeded 200 million HTTP requests per second. Cloudflare attributed both to Aisuru-Kimwolf, a botnet built largely from compromised Android TV boxes rather than the routers and IoT devices that powered earlier Mirai-style swarms. The new H1 2026 report is not about a bigger record; it is about how often attackers are now approaching the 1 Tbps mark on a routine basis, a threshold that used to be exceptional and now shows up hundreds of times per quarter.
Media Outlets Take the Brunt, Gambling Sites Close the Gap
Sector data in the report reinforces the news-cycle theory. Media, production, and publishing companies were the single most-targeted industry in both quarters, absorbing about 14 percent of all mitigated HTTP DDoS requests, roughly four times as many as the second-place sector, gambling and casinos. The Register quoted Cloudflare’s Blake Darché, head of Cloudforce One and Threat Intelligence, offering a simple explanation: “DDoS attacks are uniquely effective against publishers because news expires quickly.” A newsroom knocked offline for even twenty minutes during a breaking story loses readers and ad revenue it cannot easily win back later, which makes publishers a soft, high-leverage target compared with infrastructure that can absorb a quiet overnight outage.
When Geopolitics Writes the Target List
Operation Epic Fury and the Strikes on Iran
The clearest evidence of news-driven targeting came on February 28, 2026, when Israel and the United States launched a series of strikes against Iranian leadership and infrastructure under the name Operation Epic Fury. Cloudflare says its researchers logged 149 hacktivist DDoS claims against 110 distinct organizations across 16 countries within 72 hours of the strikes, and government bodies made up roughly 48 percent of the organizations targeted worldwide during that window. It is one of the fastest, most concentrated bursts of politically motivated DDoS activity the report documents.
Turkey’s Climb Ahead of the Ankara NATO Summit
Turkey rose to the third most-attacked country in the report, a jump Cloudflare linked to the NATO summit the country hosted in Ankara in July. China and the United States remained the two most heavily targeted countries overall, per The Register’s review of the underlying data, though exact percentages for each were not disclosed in the coverage available.
Government’s Steepest Climb of the Year
The government sector overall posted the single largest sectoral move Cloudflare tracked in 2026 so far, jumping from the 29th most-targeted industry to 9th. Between the Iran strikes, the war in Ukraine, and a packed calendar of diplomatic and sporting events including a World Cup, the report reads less like a catalogue of random opportunistic noise and more like a map of wherever the world’s attention happened to be pointed that week.
Brazil Overtakes the US as the Top Source of Attack Traffic
The report also tracks where attacks originate, not just where they land. Brazil overtook the United States as the largest source of DDoS traffic for the half, responsible for 15 percent of mitigated attack traffic against the United States’ 13 percent, a shift driven by a second-quarter surge that pushed Brazil’s individual quarterly share to 21 percent. Indonesia held a steady third place in both quarters, according to SiliconANGLE’s reporting on the data. None of this necessarily means the people directing the attacks are sitting in Sao Paulo or Jakarta: DDoS traffic is generated by compromised devices, so a country’s ranking as a “source” mostly reflects how many poorly secured routers, cameras, and other connected gadgets sit on its networks, not the nationality of whoever is renting the botnet.
Law Enforcement Chips Away at the Supply Side
The report’s one piece of good news for defenders came from outside Cloudflare’s own telemetry. In April, a 21-country law enforcement operation called Operation PowerOFF targeted the booter and stresser services that rent out DDoS capacity to anyone with a credit card. The action produced four arrests, 53 seized domains, and warnings issued to more than 75,000 users of DDoS-for-hire platforms. It is a small dent against 23.2 million attacks, but it targets the supply side of an industry that otherwise makes launching a multi-gigabit flood about as easy as checking out on an e-commerce site.
What This Means for Defenders
The practical takeaway for security teams has less to do with the raw growth numbers and more to do with how to read them. If your organization sits in a sector Cloudflare flags as newly popular with attackers, media, gambling, or anything adjacent to a live geopolitical story, your DDoS exposure now tracks the news cycle around your industry, not just your own visibility or size. That argues for always-on mitigation rather than reactive scaling: with most attacks resolving in minutes, there usually is not time to stand up defenses after the first packets already arrive. It also argues for hardening the reflection surfaces attackers are leaning on hardest right now. DNS and CLDAP floods do not require compromising the victim at all; they require finding misconfigured, open, third-party servers elsewhere on the internet to bounce traffic off. Organizations running their own DNS or LDAP infrastructure should confirm those services are not open to abuse from arbitrary source IPs, since that exact kind of misconfiguration is what fueled the vector shift Cloudflare is describing.








No Comment! Be the first one.