Skip to main content
Emerging ThreatsMalware & Ransomware

DDoS Attacks Surge Amid Global Conflicts, Sports Events

Newsroom setup with desk, papers, and blank broadcast monitor.

Cloudflare mitigated 805 network-layer attacks exceeding 1 Tbps in Q2 alone — a 519 percent increase compared with Q1.

Media and publishing emerged as the primary target

Cloudflare’s telemetry shows that media, production, and publishing organisations were the most-targeted sector in 2026, accounting for 14.2 percent of all distributed denial-of-service (DDoS) attacks launched since January 1. Over the first six months of the year, that sector took nearly four times as many attacks as the second most-targeted sector, gambling and casinos — and six times more in Q2 alone.

Blake Darché, Head of Cloudforce One and Threat Intelligence at Cloudflare, told The Register that DDoS attacks on publishers “can be highly effective at achieving their core goals, which differ fundamentally from attacks on other sectors.” He explained that for publishers “availability is the deliverable,” and that attacks are typically aimed at “censorship, information suppression or timing disruption.”

War, the World Cup and hacktivism drove spikes

Cloudflare linked the surge to ongoing wars in Ukraine and Iran and to the FIFA World Cup. The company’s data aligns with third-party reporting following the US starting a war with Iran in February: Akamai reported a 245 percent uplift in cybercrime in the immediate weeks after that war began, with DDoS attacks up 38 percent.

Palo Alto Networks’ Unit 42 senior manager Justin Moore told The Register that by the start of March the company’s telemetry showed “a clear increase in pro-Russia hacktivism.” The report notes that hacktivist campaigns typically rely on DDoS, are often organised on social media platforms, and are generally characterised by signals intelligence agencies as “almost always low-level and low-impact,” even as those agencies warn businesses not to underestimate them — particularly operators of critical infrastructure, where a sustained successful attack “could lead to vital service disruption.”

The geographic focus of attacks shifted too: the US and China were the two most-targeted regions, and Turkey climbed to third after hosting the Ankara NATO summit in July. The US’ war in Iran also coincided with a major uptick in attacks targeting government entities, which rose from the 29th most-targeted sector in Q1 to ninth in Q2.

Network-layer and hyper-volumetric attacks: size, speed, and impact

Cloudflare separated two related trends. First, “network-layer” attacks — those that target layer 3 of the OSI model, hitting routing, transport, and core infrastructure protocols — exploded in Q2, with 805 mitigations above 1 Tbps. Second, the company described hyper-volumetric DDoS as massive, high-packet onslaughts that transmit enough data to overwhelm networks and even robust internet infrastructure.

Despite their visibility, hyper-volumetric attacks remain a tiny fraction of total events: 1 Tbps+ attacks account for 0.004 percent of the company’s observed DDoS traffic. The vast majority of attacks are small and short: 96.62 percent transmitted less than 500 Mbps, and 90.6 percent ended in under ten minutes. Yet Cloudflare emphasised that even modest volumes can be disruptive: “a 100 Mbps attack would be sufficient to knock a website or server offline, while a 1 Gbps attack could disrupt an entire datacenter if it wasn’t protected from DDoS attacks.”

Cloudflare also warned that hyper-volumetric bursts are among the fastest observed — often lasting seconds rather than minutes — and therefore leave “no practical window for human intervention.” The company wrote, “Manual mitigation and on-demand solutions are simply too slow for this reality,” adding that short attacks can have cascading aftershocks — routing instability, TCP retransmissions, application timeouts and downstream degradation — that take hours or days to resolve.

Botnets and law enforcement action

A law enforcement operation in March disrupted infrastructure relied upon by four of the most significant botnets at that time, including Aisuru. By the end of 2025 Aisuru had recruited up to 4 million devices and was “rattling out multiple 1 Tbps attacks daily,” according to Cloudflare’s report. That prior activity helps explain both the availability of high-capacity attacks and why takedown efforts are a continuing feature of the landscape.

What this means for technologists, publishers, and policymakers

  • Technologists and security teams: expect more short, very high-bandwidth bursts that require automated, always-on mitigation. Cloudflare concluded that “there is no practical window for human intervention,” so manual or on-demand defences will miss many hyper-volumetric hits.
  • Publishers and production organisations: timing matters. Because news “expires quickly,” even a brief outage at peak readership — election nights, major conflict developments, or breaking sports coverage — can achieve the attacker’s goal of suppression or timing disruption.
  • Policymakers and government entities: geopolitical events reshape targeting. The report ties spikes in government-targeted attacks to the war with Iran and notes regional shifts after international summits, underlining the link between diplomacy, conflict, and cyber activity.

Cloudflare’s data sketches a simple but stark reality: attackers are leveraging geopolitical flashpoints and momentary surges of capacity to silence outlets and strain infrastructure, and many of the most potent strikes arrive and end faster than humans can react. The practical question the facts leave open is not whether these attacks will continue — the evidence already shows they will — but whether defenders can operationalise automated defences and resilience at the pace that modern DDoS now demands.

Source: The Register — Two wars and a World Cup lead to epic DDoS attacks on publishers