Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave
Curated from Cloudflare Blog
The recent surge in hyper-volumetric DDoS attacks, particularly those leveraging DNS and CLDAP reflection vectors, demands immediate attention from infrastructure teams. While the headline figures highlight a dramatic increase in attack volume, the underlying shift toward amplified reflection techniques presents a distinct operational challenge. Traditional mitigation strategies often fail to account for the sheer volume of legitimate-looking traffic generated by these protocols. Engineers must reassess their ingress filtering rules and upstream scrubbing capabilities to handle these specific vectors effectively. This is not merely about absorbing bandwidth but ensuring that critical services remain available during sustained, high-volume incidents. The geopolitical context adds another layer of complexity, suggesting that these attacks may be sustained and targeted rather than opportunistic. Practitioners should prioritize validating their network edge configurations against reflection amplification risks to maintain service continuity.
In the first half of 2026, Cloudflare detected a 519% surge in hyper-volumetric DDos attacks across its network. These attacks were driven heavily by DNS and CLDAP reflection vectors. This report breaks down how major geopolitical conflicts reshaped the global cyber threat landscape.
— Cloudflare Blog