DDoS Attacks Over 1 Tbps

Overview

Cloudflare has reported a dramatic surge in massive distributed denial‑of‑service (DDoS) attacks, mitigating more than 800 network‑layer incidents exceeding 1 Tbps in the second quarter of 2026. This marks a fivefold increase compared to Q1, when only 130 such attacks were recorded.

Scale of the Surge

  • Record-breaking attack: Cloudflare absorbed a peak assault of 31.4 Tbps and 200 million requests per second, launched by the Aisuru/Kimwolf botnet.
  • Quarterly growth:
    • Attacks >1 Tbps rose 519% quarter‑over‑quarter.
    • Attacks between 500 Gbps–1 Tbps increased 143%.
    • Attacks between 100–500 Gbps grew 105%.
  • Overall activity:
    • 23.2 million network‑layer DDoS attacks mitigated in H1.
    • 29.64 trillion malicious HTTP requests blocked.

Attack Characteristics

  • Duration trends:
    • 90.6% ended within 10 minutes.
    • Long‑lasting attacks (>3 hours) doubled from 0.387% in Q1 to 0.828% in Q2.
  • Traffic peaks: April saw 6.46 trillion HTTP requests and 165 PB of attack traffic, followed by a decline attributed to Operation PowerOFF, an international crackdown on DDoS‑for‑hire services.

Emerging Attack Trends

  • DNS floods: Accounted for 40% of Q2 attacks, up from 25.7% in Q1.
  • Amplification techniques:
    • DNS floods + amplification represented 34.3% of H1 attacks.
    • CLDAP floods surged 881.9% quarter‑over‑quarter.
  • UDP floods: Ranked second at 14.06%.

Targeted Sectors

  • Media, Production, Publishing: Received 14.2% of mitigated HTTP DDoS requests in H1.
  • Government services: Saw a notable increase, linked to geopolitical events such as the US‑Israeli military operation against Iran, which fueled hacktivist campaigns.

Defensive Takeaways

Organizations should:

  • Deploy layered DDoS protection with CDN and reverse‑proxy services.
  • Monitor DNS traffic for flood and amplification anomalies.
  • Prepare for large‑scale attacks exceeding 1 Tbps.
  • Leverage intelligence sharing from providers like Cloudflare to anticipate evolving attack vectors.

Expert in the Cloud Insight

The fivefold surge in ultra‑large DDoS attacks shows how adversaries are scaling botnets to unprecedented levels. While most attacks remain small and short‑lived, the rise of multi‑terabit floods underscores the need for global collaboration, rapid patching, and proactive monitoring. For defenders, the lesson is clear: DDoS resilience is no longer optional—it’s foundational.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.