Decoding the world of cybersecurity

Terabit DDoS attacks surge across Cloudflare

Cloudflare says hyper-volumetric DDoS attacks rose sharply in the first half of 2026, with attacks exceeding 1 Tbps becoming substantially more common across its network.

Terabit DDoS attacks surge across Cloudflare
Summary
  • Cloudflare recorded a 519% increase in hyper-volumetric DDoS activity across its network during the first half of 2026.
  • DNS and CLDAP reflection were prominent drivers, while geopolitical events contributed to changes in attack volume and targeting.
  • The figures describe Cloudflare’s own network visibility, but show how capacity assumptions are changing as terabit-scale attacks become less exceptional.

Distributed denial-of-service attacks operating at terabit scale are becoming a more routine part of internet infrastructure risk, according to new Cloudflare data showing a sharp increase in hyper-volumetric activity during the first half of 2026.

Cloudflare said it detected a 519% surge in hyper-volumetric DDoS attacks across its network during the period. The company highlighted attacks exceeding 1 terabit per second and said DNS and Connection-less Lightweight Directory Access Protocol reflection were prominent sources of the increase.

The figures should not be read as a measurement of every DDoS attack on the internet. Cloudflare’s visibility is shaped by the customers, networks, applications, and traffic that pass through its infrastructure. It nevertheless operates at a scale that gives its telemetry value as an indicator of changing attack characteristics, particularly when the issue is not the absolute number of incidents but the capacity required to absorb them.

DDoS has long occupied an unusual position in enterprise risk. The underlying techniques are well understood, many attacks are technically unsophisticated, and specialist mitigation capacity is widely available. The business consequence, however, depends on whether the organisation and its providers can absorb traffic that may be orders of magnitude larger than normal demand without allowing the attack to consume upstream connectivity or service resources.

Growth in attacks above 1 Tbps changes that capacity calculation. Infrastructure that could withstand yesterday’s volumetric incidents may still depend on external mitigation when traffic arrives at a scale beyond the organisation’s own network links. That places resilience partly in the hands of content-delivery networks, telecommunications operators, cloud providers, and specialist DDoS services that can distribute or filter hostile traffic before it reaches the customer environment.

Cloudflare also linked changes in the threat landscape to geopolitical events during the first half of the year. DDoS remains attractive in politically motivated campaigns because attacks can be launched quickly, are visible to victims and the public, and can create disruption without requiring the attacker to maintain long-term access to internal systems. The same techniques are also used for extortion, distraction, criminal competition, and opportunistic disruption.

The technical simplicity of many reflection attacks does not remove their infrastructure consequence. DNS and CLDAP can be abused to generate amplified traffic when exposed systems respond to spoofed requests. At sufficient scale, the resulting flood becomes an engineering problem for networks rather than an application-security problem at the individual server.

For European organisations, that moves DDoS planning into the wider resilience discussion already being shaped by regulatory requirements and concentration in digital service providers. Banks, public services, transport operators, retailers, media organisations, and other internet-dependent businesses may have little tolerance for prolonged external unavailability even when no internal data has been compromised.

It also complicates the interpretation of successful defence. A large attack that causes no visible outage can disappear from conventional incident reporting even though significant provider capacity was required to absorb it. As mitigation becomes more automated, the absence of disruption can mask the scale of hostile traffic being handled upstream.

Cloudflare’s numbers are vendor telemetry rather than a universal internet census, but the direction is difficult to ignore. Terabit-scale DDoS is moving away from the category of exceptional attack reserved for a handful of major targets and towards a condition that infrastructure providers increasingly have to engineer around as part of normal service resilience.

×