SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Cloudflare sees surge in hyper-volumetric DDoS attacks

Cloudflare sees surge in hyper-volumetric DDoS attacks

Wed, 12th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Cloudflare mitigated 23.2 million network-layer distributed denial of service attacks in the first half of 2026, equivalent to 5,343 attacks an hour.

The figures came as the company linked shifts in attack patterns to geopolitical tensions, media attention and major public events. Government and media were among the most affected sectors during the period.

Its half-year data also showed a steep rise in the largest attacks. Cloudflare mitigated 935 network-layer attacks exceeding 1 terabit per second in the first six months of the year, including 805 in the second quarter alone.

That was a 519% quarter-on-quarter increase in attacks above 1 Tbps between the first and second quarters. The report described hyper-volumetric incidents as a growing category, even as the typical attack remained far smaller and shorter.

According to Cloudflare, 96.62% of network-layer attacks stayed below 500 Mbps, while 90.60% ended in under 10 minutes. Even short attacks can still disrupt services, however, because there is often little or no time for manual intervention once traffic begins to surge.

Sector shifts

One of the sharpest changes was in attacks on government organisations. The sector rose 20 places between quarters, moving from number 29 in the first quarter to number nine in the second by share of mitigated HTTP DDoS requests.

The shift followed military strikes involving Israel, the United States and Iran, which Cloudflare said were followed by a wave of hacktivist activity against public institutions. It cited reporting that nearly 47.8% of organisations targeted globally during that period were in the government sector.

Media, Production & Publishing ranked as the most-attacked industry in both quarters, accounting for 14.2% of all mitigated HTTP DDoS requests. Cloudflare linked that to sustained coverage of conflict in Iran and Ukraine, as well as the World Cup, which drew attention to media outlets.

Country rankings

By destination, China was the most-attacked location in the second quarter, absorbing 22.4% of global HTTP DDoS requests measured by Cloudflare. The United States ranked second with 18.8%.

Turkey moved into third place after its share of attack traffic more than doubled. Cloudflare linked the increase to the period around security operations ahead of the NATO summit in Ankara.

On the source side, Brazil overtook the United States as the leading origin of DDoS request traffic in the first half. Brazil accounted for 14.9% of mitigated request traffic across the period, compared with 13.4% for the United States, while Indonesia remained in third place in both quarters.

Tactical changes

The report pointed to a marked change in the techniques attackers used. DNS-based attacks accounted for 34.3% of all network-layer incidents during the first half, and DNS floods alone rose from 25.7% of such attacks in the first quarter to 40.0% in the second.

Cloudflare said this suggested a shift away from direct botnet flooding towards reflection and amplification methods. Those methods rely on internet-facing services to magnify traffic and direct it at a victim.

CLDAP floods also rose sharply, climbing 881.9% quarter on quarter to become the third most common attack vector in the second quarter. The vector abuses exposed LDAP-over-UDP endpoints.

The change matters because reflection attacks can generate outsized traffic from relatively small queries, making them efficient for attackers and harder to trace. In CLDAP attacks, spoofed requests are sent to publicly reachable directory servers, which then send much larger replies to the target.

April peak

April was the busiest month in the half-year period for DDoS activity tracked by Cloudflare. Attack traffic reached 6.46 trillion requests and 165 petabytes during the month before declining afterwards.

Cloudflare said the drop may have been partly linked to Operation PowerOFF, a multinational law enforcement effort targeting users of DDoS-for-hire services. The operation involved 21 countries, the takedown of 53 domains, 25 search warrants and four arrests.

The decline after April suggests enforcement pressure may have disrupted some attack infrastructure, at least temporarily. Even so, the overall half-year figures indicate that attackers are still able to launch very large incidents at a frequent pace.

Cloudflare said: "Midway through the year, Cloudflare has already mitigated 23.2 million network-layer and 29.64 trillion HTTP DDoS requests. That works out to approximately 5,343 network-layer DDoS attacks per hour, or about 128,000 per day."

It added: "During the second quarter, Cloudflare mitigated 805 network-layer attacks exceeding 1 Tbps, representing a more than six-fold increase over the previous quarter."