Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave
- ID
- 13048
- Status
- summarized
- Published
- 11 Aug 2026, 9:00 PM
- Fetched
- 11 Aug 2026, 9:24 PM
- Provider
- Cloudflare Blog
- Category
- infrastructure
- Original URL
- https://blog.cloudflare.com/ddos-threat-report-2026-h1/
- Source URL
- https://blog.cloudflare.com/rss/
Summary
- Score
- 6.5
- Created
- 11 Aug 2026, 9:24 PM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
Cloudflare's H1 2026 DDoS report covers Jan-Jun, mitigating 23.2M network-layer attacks and 29.64T HTTP DDoS requests (~5,343 attacks/hour). 935 attacks exceeded 1 Tbps with a 519% QoQ surge in Q2, DNS floods rose to 40% of network-layer attacks, and Operation PowerOFF targeted 75,000 DDoS-for-hire users across 21 countries.
Why it matters
If you run any public-facing infrastructure, DNS-based amplification attacks are now the dominant vector at 40% of network-layer attacks—review your DNS resolver exposure and upstream rate-limiting. The 1 Tbps attack volume means self-hosted mitigation is increasingly impractical; evaluate whether your CDN/WAF provider's DDoS tier covers hyper-volumetric attacks before you need it.
Discussion angle
With DNS floods now 40% of network-layer attacks and 1 Tbps attacks becoming routine, what's the practical baseline for DDoS protection for a Malaysian startup on a budget—Cloudflare free tier, local telco scrubbing, or something else?