We already know DDoS attacks are getting bigger. If you have followed Cloudflare’s DDoS reports over the past few years, this is hardly a surprise. We have covered several of them on Techlomedia, including record-breaking attacks that went from 7.3 Tbps to 11.5 Tbps and eventually 22.2 Tbps in 2025. The 22.2 Tbps attack lasted only around 40 seconds, yet it generated enough traffic to make it one of the largest DDoS attacks ever reported.
Now the company has published its latest DDoS Threat Report, which covers the first half of 2026. The report again shows that the scale of DDoS attacks continues to grow, but there is more to it than another increase in terabits per second.
Cloudflare mitigated 935 network-layer DDoS attacks above 1 Tbps during the first half of 2026. A remarkable 805 of them happened in Q2, representing a 519% increase from the previous quarter.
We have already seen individual attacks that were much larger than 1 Tbps. What makes this number interesting is the frequency. Crossing the 1 Tbps mark is becoming less unusual.
Most attacks are still much smaller. Cloudflare says 96.62% of network-layer attacks remained below 500 Mbps, and 90.60% ended within 10 minutes.
The largest attacks tell us how much capacity attackers can bring to bear, but they do not represent the typical attack. A smaller attack can still be enough to disrupt a poorly protected website or server.
From a security perspective, I would therefore pay more attention to the increasing frequency of extreme attacks than to the next record number alone.
Cloudflare says it has observed record-breaking DDoS attacks lasting just 35 seconds. That creates a very different challenge for defenders. A manual response process is simply too slow for an attack that can start and finish in less than a minute.
By the time an analyst identifies the traffic, confirms the attack and begins mitigation, the main event may already be over. A short burst can also cause routing instability, TCP retransmissions and application timeouts that continue after the attack stops.
This is the area where automation is not just convenient. For internet-facing services, it is becoming necessary.
The most interesting part of the report, in my view, is the connection between DDoS activity and geopolitical events. The government sector moved from 29th place in Q1 to ninth in Q2 based on its share of mitigated HTTP DDoS requests. Cloudflare links the increase to the military conflict involving Israel, the United States and Iran.
Within 72 hours of the February 28 operation, security researchers recorded 149 hacktivist DDoS claims involving 110 organisations across 16 countries. Nearly 48% of the targeted organisations were in the government sector.
This is an important reminder that DDoS attacks do not always follow the traditional logic of finding a technically vulnerable target. Sometimes the target is selected because of what it represents.
A government website can become a target because of a military action or political decision. A company can be targeted because of its association with a particular country. For hacktivist groups, DDoS also provides a relatively simple way to create visible disruption without first gaining access to the target’s network.
Media, Production & Publishing was the most attacked industry in both Q1 and Q2, accounting for 14.2% of all mitigated HTTP DDoS requests.

The timing is relevant. Cloudflare points to developments involving Iran and Ukraine as well as the World Cup among the events driving global attention during the period.
Media organisations become especially visible during major events. Disrupting a news platform at that moment can have more impact than taking the same service offline on an ordinary day. The outage itself can become part of the story.
That makes timing an important part of DDoS campaigns. Attackers do not necessarily need to find a new vulnerability if they can identify a moment when disruption will have maximum visibility.
Cloudflare also saw a significant change in attack techniques. DNS-based attacks accounted for 34.3% of network-layer DDoS activity during the first half of 2026. DNS Floods alone increased from 25.7% of network-layer attacks in Q1 to 40% in Q2.
DNS Floods overwhelm DNS infrastructure with large numbers of queries, while DNS Amplification attacks abuse publicly accessible resolvers to generate larger responses toward the victim.

Cloudflare also recorded a 580% quarter-over-quarter increase in CLDAP Flood attacks, making it the third-largest network-layer attack vector in Q2.
I do not think the important point here is any individual protocol. It is that attackers continue to look for internet-facing infrastructure that can provide amplification or otherwise increase the impact of an attack.
That makes exposure management and configuration security relevant to DDoS defence as well.
April was the busiest month in Cloudflare’s H1 data, with 6.46 trillion HTTP DDoS requests and 165 petabytes of traffic. Activity declined afterward.
Cloudflare suggests that Operation PowerOFF may have contributed to the decline. The international operation targeted more than 75,000 DDoS-for-hire users, took down 53 domains, issued 25 search warrants, and resulted in four arrests.
I would not call the connection proven yet. A decline after an operation does not by itself establish causation, and we need more data to know whether the reduction will continue.
But the possibility is important because DDoS-for-hire services have changed the economics of these attacks.
An attacker does not necessarily need to build a botnet or understand the underlying infrastructure. They can simply pay for an attack. Disrupting those services could therefore reduce access to DDoS capabilities for a large number of less technically sophisticated attackers.
I have followed DDoS activity and Cloudflare’s reports for years, and I think it would be easy to focus too much on the 1 Tbps numbers.
The more interesting development is that DDoS is becoming a routine part of the broader threat landscape. The attacks are becoming more frequent at extreme volumes, but their targets and timing are also increasingly influenced by what is happening outside the network.
That makes DDoS a security problem that cannot be assessed only by looking at server capacity. A security team needs to understand its exposure, automate mitigation and also consider whether a geopolitical event, major public event or change in the organisation’s visibility could suddenly make it a more attractive target.
Cloudflare naturally has a commercial interest in emphasising the need for DDoS protection, so its recommendations should be viewed in that context. But the underlying data points to a trend that is difficult to ignore.
The next big DDoS story may not be interesting simply because it breaks another traffic record. It may be interesting because of why that particular target was chosen and why the attack happened at that particular moment.






