Aug 11, 2026
Enterprise

Cloudflare says 1 Tbps DDoS attacks rose sixfold in Q2

Cloudflare counted 805 network-layer DDoS attacks above 1 Tbps in Q2, though its data shows most attacks remained far smaller.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 2 min read

Cloudflare says 1 Tbps DDoS attacks rose sixfold in Q2
Photo: SiliconANGLE

Cloudflare says it mitigated 805 network-layer DDoS attacks exceeding 1 Tbps in the second quarter of 2026, more than six times the first-quarter count. The Cloudflare 1 Tbps DDoS attacks figure points to a growing number of extreme incidents on the company’s network, but not to a typical attack becoming terabit-scale.

The company reported 935 network-layer attacks above the 1 Tbps threshold across the first half, in the 25th edition of its DDoS Threat Report. Cloudflare described the quarter-over-quarter increase as 519%. SiliconANGLE reported that the Q1 count was 130, compared with 805 in Q2.

The report is Cloudflare’s first half-year edition, combining January through June rather than issuing separate quarterly reports. Its Cloudforce One threat-intelligence group based the findings on traffic observed and mitigated on Cloudflare’s network. That makes the data a view of activity reaching Cloudflare, not a census of DDoS attacks across the internet.

What does Cloudflare count as a hyper-volumetric DDoS attack?

Cloudflare defines a hyper-volumetric attack as one exceeding at least one of three thresholds: 1 Tbps of bandwidth, 1 billion packets per second, or 1 million HTTP requests per second. The 805 figure concerns only network-layer attacks that crossed the bandwidth threshold, rather than every attack in the broader hyper-volumetric category.

The company’s broader numbers show how unusual that threshold remains. Cloudflare said it mitigated 23.2 million network-layer attacks during the six months, or about 5,343 each hour. It reported that 96.62% were below 500 Mbps, while 90.60% ended in less than 10 minutes. Those proportions mean the rise in very large attacks occurred alongside a much larger population of smaller, short-lived incidents.

Which attack methods grew in Cloudflare’s data?

Cloudflare reported a shift toward DNS-related and amplification techniques. DNS-based attacks represented 34.3% of network-layer activity in the first half, according to the company. DNS Floods increased from 25.7% of network-layer attacks in Q1 to 40.0% in Q2.

Cloudflare also said CLDAP Floods, an amplification method that abuses the Connectionless Lightweight Directory Access Protocol, increased 580% from the first quarter and became the third-ranked attack vector in Q2. The report does not establish who launched the attacks or whether those methods alone drove the increase in incidents above 1 Tbps.

For comparison, Cloudflare’s Q2 2025 report said it blocked more than 6,500 hyper-volumetric attacks under its wider definition, which also includes packet-rate and HTTP-request thresholds. It said attacks above 1 Tbps and 1 billion packets per second had doubled from the preceding quarter. The 2026 result is therefore a more narrowly defined count, and should not be compared directly with that broader 2025 total.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →