Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year.
Compared with the first quarter, when the company recorded just 130 attacks above 1 Tbps, the latest figure represents a more than fivefold increase.
Cloudflare is a major web infrastructure and security firm that provides CDN, DNS, reverse-proxy, and DDoS protection services to customers worldwide, protecting roughly 20% of the web.
The company's services sit between DDoS botnets and their intended targets, allowing it to observe and absorb attacks at enormous scale.
Recently, the company mitigated a record-breaking attack that peaked at 31.4 Tbps and 200 million requests per second, launched by the Aisuru/Kimwolf botnet.
In a new report shared with BleepingComputer and presented earlier today at the Black Hat security conference, Cloudflare says that in the first half of the year it mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion malicious HTTP requests.
The most significant increase refers to extremely large network-layer attacks exceeding 1 Tbps, which rose 519% quarter over quarter.
However, the company observed an overall jump in less severe attacks, too. Those between 500 Gbps and 1 Tbps, increased by 143%, while those between 100 and 500 Gbps rose 105%.
Despite the growth in very large attacks, most incidents remained comparatively small and brief, according to Cloudflare, with 96.62% of network-layer attacks remaining below 50 Mbps and 90.6% ending within 10 minutes.
Some of them lasting for more than three hours increased slightly from 0.387% in Q1 to 0.828% in Q2 2026.
DDoS attacks at the network-layer rose from 10.04 million to 13.17 million, a 31.2% increase, while malicious HTTP request volume grew from 12.75 trillion to 16.89 trillion, up by 32.4%.
Cloudflare saw the overall DDoS activity peaking in April, with 6.46 trillion HTTP DDoS requests and 165 PB of network-layer attack traffic.
This was followed by a notable decline after April, which the firm tentatively attributes to the international Operation PowerOFF crackdown on DDoS-for-hire services.
The operation resulted in the arrest of four individuals, the takedown of 53 domains, and the distribution of warnings to 75,000 users of such services.
Among the trends emerging in the last quarter, Cloudflare saw that attacks shifted toward DNS-related and reflection/amplification techniques.
DNS floods accounted for 40% in Q2, up from 25.7% in Q1; together DNS floods and DNS amplification attacks represented 34.3% of H1 network-layer attacks; CLDAP floods increased 881.9% quarter-over-quarter; and UDP floods ranked second in Q2 at 14.06%.
Finally, regarding the targets, Cloudflare reports that the Media, Production, and Publishing sector received the largest share of mitigated HTTP DDoS requests during H1 2026, at 14.2%.
The government sector also saw a notable increase, which Cloudflare linked to geopolitical events, including the US-Israeli military operation against Iran, prompting heightened hacktivism.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Get the whitepaper