Hyper-Volumetric DDoS Attacks Surge Fivefold in Q2 2026
Cloudflare reports a massive spike in network-layer attacks exceeding 1 Tbps, signaling a shift toward more powerful botnets and amplification techniques.
Global internet infrastructure is facing a new era of "hyper-volumetric" threats as massive network-layer DDoS attacks surged in the second quarter of 2026. This spike indicates that attackers are successfully leveraging more powerful botnets and efficient amplification methods to overwhelm targets at an unprecedented scale.
According to data from Cloudflare, network-layer DDoS attacks exceeding 1 Tbps increased by 519% quarter-over-quarter, jumping from 130 incidents in Q1 to more than 800 in Q2. This trend extended across other high-volume tiers: attacks between 500 Gbps and 1 Tbps rose by 143%, while those in the 100 to 500 Gbps range increased by 105%. In total, Cloudflare mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion malicious HTTP requests during the first half of 2026.
The Shift in Attack Vectors
This surge is characterized by a distinct shift toward DNS-related and reflection/amplification techniques. DNS floods now account for 40% of all Q2 attacks, a significant increase from the 25.7% recorded in the first quarter. Even more dramatic was the rise in CLDAP floods, which saw a quarter-over-quarter increase of 881.9%.
While the volume of attacks has scaled, the targets remain diverse. For the first half of the year, the Media, Production, and Publishing sector emerged as the most targeted industry for HTTP DDoS requests, absorbing 14.2% of the total volume. This activity occurs against a backdrop of evolving geopolitical tensions, including US-Israeli operations against Iran, which have historically fueled hacktivism against government and public sectors.
Infrastructure Implications
The transition from Gigabits per second (Gbps) to Terabits per second (Tbps) as a standard for high-end attacks puts immense pressure on global network capacities. The fivefold increase in 1 Tbps+ events suggests that threat actors have gained access to more sophisticated botnets, such as Aisuru and Kimwolf. For security providers and enterprise networks, traditional mitigation strategies are no longer sufficient; they must now scale to handle traffic volumes that can dwarf standard network capacities.
Law Enforcement Response
Despite the quarterly surge, some data indicates a decline in DDoS activity following April. This dip is tentatively attributed to "Operation PowerOFF," a coordinated law enforcement crackdown targeting DDoS-for-hire services.
Industry analysts are now monitoring whether the disruption of these "booter" services can permanently curb the availability of high-volume attack tools, or if the rise of hyper-volumetric botnets will continue to outpace the efforts of global security agencies.