Cloudflare Reports Massive Spike in High-Volume DDoS Attacks

News Room

The upper end of DDoS attacks is getting much bigger — and attacks that once looked exceptional are showing up far more often.

Cloudflare says it mitigated 805 network-layer distributed denial-of-service attacks exceeding 1 Tbps in Q2 2026, up from 130 in the previous quarter. The company also reported 13.17 million network-layer DDoS attacks overall, compared with 10.04 million in Q1.

Most attacks remain much smaller, but the sharp rise in high-bandwidth events matters because organizations increasingly need defenses capable of filtering extreme traffic volumes before they overwhelm internet links or backend infrastructure.

What did Cloudflare uncover

In a blog, Cloudflare reported that it also mitigated 13.17 million network-layer DDoS attacks in Q2 2026, up from 10.04 million in Q1. That growth is especially striking when put alongside the scale of attacks Cloudflare has already observed.

The current surge is not limited to terabit-level attacks. Attacks between 500 Gbps and 1 Tbps increased 143%. Attacks between 100 Gbps and 500 Gbps more than doubled, with a 105% increase. Meanwhile, malicious HTTP traffic reached 16.89 trillion requests, up 32.4% from the previous quarter.

Despite the reported growth, the majority of attacks remained much smaller: 96.62% of network-layer attacks transmitted less than 50 Mbps, and 90.6% lasted no more than 10 minutes.

In December 2025, Cloudflare mitigated a record-breaking 31.4 Tbps DDoS attack, demonstrating that terabit-scale attacks can reach volumes far beyond the 1 Tbps threshold, which is now being crossed hundreds of times per quarter. That record-breaking attack is attributed to the Aisuru/Kimwolf botnet.

How botnets turn ordinary devices into attack infrastructure

It’s hard to discuss DDoS without bringing in another hacker’s favorite: device takeovers.

A compromised device can become a DDoS bot, quietly waiting for instructions from an attacker and then sending traffic toward a chosen target. One infected device may have limited impact on its own, but thousands or millions of compromised machines acting together can generate sufficient volume to disrupt a service.

And those machines don’t have to be traditional computers. DDoS botnets can be built from compromised routers, security cameras, servers, network appliances, and even Smart TVs, as seen in last year’s 31.4 Tbps attack.

That gives DDoS operators an unusual advantage: they don’t need to own the infrastructure generating the attack. They can borrow the combined computing and network capacity of devices belonging to unsuspecting users and organizations, turning ordinary hardware into attack infrastructure at scale.

What organizations should do about larger DDoS attacks

For organizations, simply having enough server capacity may not be enough. It needs upstream filtering, load balancing, traffic scrubbing, or other protective infrastructure.

Then there’s also the case of blocking malicious bots. This can help distinguish legitimate users and automated traffic from bots attempting to overwhelm a website with requests, making it especially useful for platforms whose websites can’t afford to fail or go offline.

The broader lesson is that DDoS protection must work before malicious traffic reaches the systems an organization seeks to protect. The faster traffic can be identified, filtered, and routed elsewhere, the less likely a large attack is to cause an outage for legitimate users.

Other News: U.S. and South Korean authorities are warning about the growing Gunra ransomware threat, underscoring the need for organizations to strengthen defenses against increasingly aggressive ransomware campaigns.

Read the full article here

Share This Article
Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *