Cloudflare reports a sharp rise in massive DDoS attacks in 2026
Cloudflare mitigated 935 attacks above 1 Tbps in the first half of 2026, raising the stakes for always-on protection of AI services.

Cloudflare says distributed denial-of-service attacks grew more intense during the first half of 2026. Its latest report combines data from January through June and records 935 network-layer attacks larger than 1 terabit per second (Tbps), including 805 in the second quarter alone—a more than six-fold quarterly increase.
The scale is significant for teams running AI APIs, model endpoints and tool-driven applications. Cloudflare says it mitigated 23.2 million network-layer attacks and 29.64 trillion HTTP DDoS requests during the period, equivalent to roughly 5,343 network-layer attacks per hour. April was the peak month, with 6.46 trillion requests and 165 petabytes of traffic.
Reflection attacks replace some botnet floods
DNS-based attacks represented 34.3% of network-layer activity across the half-year. DNS Floods increased from 25.7% of attacks in Q1 to 40.0% in Q2, while CLDAP Floods jumped 580% quarter over quarter to become the third-largest attack vector.
Most attacks were much smaller than the headline events, but that does not make them harmless: 96.62% stayed below 500 Mbps, and 90.60% lasted less than 10 minutes. Cloudflare notes that attacks can finish before a human response is possible, while outages may continue through routing problems, retransmissions and application timeouts.
Geopolitical events also shaped the targets. Media, Production & Publishing was the most attacked industry, receiving 14.2% of mitigated HTTP DDoS requests. The government sector moved from 29th place in Q1 to ninth in Q2 amid Operation Epic Fury. For AI builders, the report reinforces the need for automated, continuously active defenses rather than relying on manual intervention after an endpoint is already under pressure.
Source: CloudFlare
Comments
Log in to join the discussion