Skip to main content
Emerging ThreatsMalware & Ransomware

DDoS Attacks Over 1 Tbps Surge Fivefold in Q2

Busy internet exchange with technicians monitoring screens and networking equipment.

Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year.

How big the surge was — raw numbers and trends

Cloudflare, the web infrastructure and security firm that the company says protects roughly 20% of the web, reported a dramatic rise in extremely large DDoS events. In the first half of the year it mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion malicious HTTP requests. Quarter-to-quarter comparisons show the sharpest escalation at the very high end: attacks above 1 Tbps rose from 130 in Q1 to more than 800 in Q2, a 519% increase.

  • Network-layer attacks rose from 10.04 million in Q1 to 13.17 million in Q2 (a 31.2% increase).
  • Malicious HTTP request volume grew from 12.75 trillion to 16.89 trillion (up 32.4%).
  • Less extreme large attacks also climbed: 500 Gbps–1 Tbps events increased 143% and 100–500 Gbps events rose 105%.

The record spike and the Aisuru/Kimwolf botnet

Cloudflare highlighted a record-breaking mitigation that peaked at 31.4 Tbps and 200 million requests per second, an attack the company attributed to the Aisuru/Kimwolf botnet. That single incident underscored the platform-scale absorptive capacity Cloudflare says it has by virtue of sitting between DDoS botnets and their intended targets.

Despite headline-grabbing extremes, most incidents remained small and brief: 96.62% of network-layer attacks were below 50 Mbps, and 90.6% of attacks ended within 10 minutes. Still, the proportion of attacks lasting more than three hours rose slightly from 0.387% in Q1 to 0.828% in Q2.

Technique shift: DNS, reflection and amplification

Cloudflare reported a clear shift in the playbook used by attackers. DNS-related techniques gained ground in Q2: DNS floods accounted for 40% of network-layer attacks in Q2, up from 25.7% in Q1. Looking across H1, Cloudflare said DNS floods and DNS amplification together represented 34.3% of network-layer attacks.

  • CLDAP floods rose dramatically, increasing 881.9% quarter-over-quarter.
  • UDP floods ranked second in Q2 at 14.06% of network-layer attacks.

Operational context: April peak and Operation PowerOFF

Overall DDoS activity peaked in April, when Cloudflare recorded 6.46 trillion HTTP DDoS requests and 165 petabytes of network-layer attack traffic. The firm reported a notable decline after April and tentatively attributed that drop to the international Operation PowerOFF crackdown on DDoS-for-hire services.

Operation PowerOFF, as described in Cloudflare's reporting shared with BleepingComputer and presented at Black Hat, resulted in four arrests, the takedown of 53 domains, and warnings distributed to 75,000 users of such services. Cloudflare characterized the attribution to the operation as tentative but presented it as a plausible factor in the post-April decline.

What this means for Media, Government, and security teams

Media, Production, and Publishing: Cloudflare reports this sector received the largest share of mitigated HTTP DDoS requests during H1 2026, at 14.2%. Organizations in this sector should expect high-volume HTTP DDoS pressure and plan for capacity and mitigation options that can absorb surges.

Government: Cloudflare noted a notable increase in attacks on government targets and linked that to geopolitical events, including the US-Israeli military operation against Iran, which the company said prompted heightened hacktivism. Government agencies may therefore see elevated targeting connected to real-world events.

Security teams: The shift toward DNS-related and reflection/amplification attacks — and the growth in both very large and more numerous mid-sized attacks — implies defenders must watch protocol abuse patterns as closely as raw bandwidth. Cloudflare’s visibility, derived from sitting between botnets and targets, allowed it to observe both the headline incidents and the large volume of smaller, short-duration attacks.

Cloudflare’s data sketches a dual reality: the DDoS threat is simultaneously concentrated in a small number of enormous, internet-scale assaults and dispersed across millions of brief, low-volume incidents. Whether law enforcement actions such as Operation PowerOFF will produce a sustained reduction in attack volumes remains an open question; the company reports a post-April decline that it tentatively credits to that international crackdown.

Original reporting at BleepingComputer