DDoS attacks are getting bigger, faster, and more political

Cloudflare’s latest DDoS Threat Report, covering January to June 2026, paints a sobering picture: cyberattacks meant to knock websites and services offline are growing in scale and increasingly tracking real-world conflict and politics. The report, compiled by Cloudflare’s threat intelligence arm Cloudforce One, marks the first time the company has combined two quarters into a single half-year analysis.

The numbers are staggering

Cloudflare mitigated 23.2 million network-layer attacks and 29.64 trillion HTTP-based attacks in just six months, roughly 5,343 attacks every hour, or 128,000 a day. April was the peak month, with 6.46 trillion requests and 165 petabytes of malicious traffic, comparable to the data volumes that major streaming platforms handle in a day.

Massive attacks are multiplying

The report’s headline finding is the explosive growth of “hyper-volumetric” attacks, those exceeding 1 terabit per second. Cloudflare mitigated 935 such attacks in H1 2026, with a 519% jump between the first and second quarters alone. Yet most attacks remain small and brief: over 96% stayed under 500 Mbps, and 90% lasted less than 10 minutes. The report stresses this isn’t reassuring; even a “small” 100 Mbps burst can take down an unprotected website, and attacks strike too fast for human security teams to respond in time.

Geopolitics is driving targets

Real-world conflict is shaping who gets attacked. After Israel and the U.S. launched military strikes on Iran in late February, hacktivist groups claimed 149 DDoS attacks against 110 organisations in 16 countries within 72 hours, nearly half targeting government bodies. As a result, the government sector jumped from the 29th to the 9th most-attacked industry, the sharpest single move of the year. Media, Production & Publishing companies remained the single most-targeted industry overall, absorbing 14.2% of attacks amid heavy news coverage of Iran, Ukraine, and the World Cup. Turkey also surged to the third most-attacked country as it prepared to host the NATO Summit in Ankara.

Where attacks come from and go

China ended the half-year as the most-attacked location (22.4% of traffic), followed by the United States. On the source side, Brazil overtook the U.S. as the top launchpad for DDoS traffic, while Indonesia held steady in third place.

Attackers are changing tactics

Rather than relying purely on botnets, attackers increasingly favour “reflection and amplification” techniques. DNS-based attacks made up over a third of all network-layer activity, while CLDAP floods, which exploit exposed Active Directory servers, surged 580% quarter-over-quarter to become the third-largest attack type.

The takeaway

Law enforcement isn’t sitting still: a 21-country operation dismantled over 75,000 DDoS-for-hire accounts and made several arrests, which may explain the traffic decline after April. But with attacks arriving in seconds and causing hours of downstream disruption, Cloudflare’s report makes clear that automated, always-on defence, not manual response, is now essential infrastructure for any organisation operating online.

Author