grid
Abstract circular gradient with concentric rings in blue, green, yellow, and red fading into black background.
5 min read

DDoS Attacks Over 1 Tbps Rose Fivefold as Trends Shift to DNS

DDoS attack trends
Published on
August 14, 2026

Attacks large enough to swamp an entire network stopped being rare events this year. More than 800 network-layer distributed denial-of-service attacks crossed the 1 Tbps threshold in the second quarter of 2026, up from 130 in the first. The latest DDoS attack telemetry puts that jump at the center, and the trends behind it point one way. A small group of operators has reached a scale that looked extraordinary twelve months ago.

Overall growth was far less dramatic. Total attack volume rose by roughly a third quarter over quarter, in line with the pattern of recent years. The gap between that steady climb and the surge at the very top end carries the real weight of the story.

Terabit Attacks Grew Six Times Faster Than Total Volume

Network-layer attacks rose from 10.04 million in the first quarter to 13.17 million in the second, an increase of 31.2%. Malicious HTTP requests followed a similar path, climbing from 12.75 trillion to 16.89 trillion, up 32.4%. Across the first half of the year, the totals reached 23.2 million network-layer attacks and 29.64 trillion malicious HTTP requests.

Against that baseline, the 519% growth in attacks above 1 Tbps stands out. The bands just below it moved as well. Attacks between 500 Gbps and 1 Tbps grew 143%, while those in the 100 to 500 Gbps range rose 105%.

So the DDoS attack figures that matter most here are not about frequency, and the trends they reveal concern raw capacity. The record for a single attack stands at 31.4 Tbps and 200 million requests per second. The Aisuru and Kimwolf botnet family generated it. Law enforcement dismantled much of that infrastructure earlier this year, but the capability it proved has become the benchmark rival operators chase.

Most Attacks Remain Small and Brief

Volume records draw attention, but the median incident looks nothing like them. Some 96.62% of network-layer attacks stayed below 50 Mbps. More than nine in ten ended within 10 minutes.

Duration is creeping up at the far end. Attacks running longer than three hours grew from 0.387% of the total to 0.828%, roughly doubling in a single quarter. That remains a tiny share, but sustained floods demand different defenses than short bursts do.

The split matters for planning. A brief DDoS attack rarely gives a human team time to react, and both trends point toward automated mitigation. Static playbooks and on-call escalation belong to an earlier era of this threat.

DDoS Attack Vectors Shift to DNS, Reversing Older Trends

Attackers shifted method as well as scale. DNS floods accounted for 40% of network-layer attacks in the second quarter, up from 25.7% in the first. Combined with DNS amplification, DNS-based techniques made up 34.3% of network-layer attacks across the half year.

CLDAP floods grew 881.9% quarter over quarter, the sharpest proportional rise of any vector. UDP floods took second place in the second quarter at 14.06%.

Reflection and amplification explain much of the growth at the top end. These techniques let a modest botnet generate enormous traffic by bouncing requests off misconfigured third-party servers. So the DDoS attack picture reflects smarter abuse of public infrastructure, and the trends favor skill over scale. Operators who understand protocols now outrank those who simply control more devices.

Media and Government Absorbed the Heaviest Targeting

The media, production and publishing sector received the largest share of mitigated HTTP DDoS requests during the first half, at 14.2%. Government targets saw a notable increase, which Cloudflare connected to hacktivist activity around the US-Israeli military operation against Iran.

Geopolitics has become a reliable predictor of who gets hit. Public sector sites and news outlets attract politically motivated traffic floods during periods of open conflict. So DDoS attack activity against these targets follows news cycles, and the trends track headlines rather than commercial calendars.

For any organization with a public-facing brand, that changes the risk calculation. Exposure depends on what a site represents, not only on what it earns.

A Dent in the Market, Not a Reversal

Activity peaked in April, with 6.46 trillion HTTP DDoS requests and 165 petabytes of network-layer attack traffic in a single month. Volumes fell after that point.

One possible explanation is Operation Power OFF, the international crackdown on DDoS-for-hire services. That effort produced four arrests, took down 53 domains, and delivered warnings to 75,000 people who had used booter platforms. The link remains tentative, and nobody has established direct causation.

Enforcement pressure works best on the low end of the market. Booter customers are opportunistic and respond to visible risk. The operators running terabit-class infrastructure are a different population, and DDoS attack capacity at that tier moved against the wider downward trends.

What Defenders Should Take From This

Mitigation capacity sized against last year's ceiling now falls short. An organization planning for a 500 Gbps worst case is planning for something attackers doubled more than 800 times in three months.

Three actions follow from the numbers. First, confirm that upstream providers can absorb terabit-class traffic rather than blackholing an address range and calling it mitigation. Second, audit DNS infrastructure and resolver configurations, since DNS floods now lead the vector rankings. Third, close off any service that could amplify someone else's attack, including exposed CLDAP, NTP, and memcached endpoints.

The wider DDoS attack landscape rewards preparation over reaction, and the trends of the past six months leave almost no room for manual response. Attacks arrive fast, peak hard, and often end before an engineer opens the alert. Defense has to be sitting in the path already.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.