QCKL News

Cloudflare reports a 519% quarter-over-quarter rise in attacks exceeding 1 Tbps

Across Cloudflare’s network, attacks exceeding 1 Tbps increased by 519% from the first to the second quarter. The company mitigated 935 such attacks in H1.

Most attacks remain small and short, but the largest ones require always-on automated protection because manual response is too slow.

Cloudflare reports a 519% quarter-over-quarter rise in attacks exceeding 1 Tbps

In its H1 2026 report, Cloudflare said it mitigated 935 network-layer DDoS attacks exceeding 1 Tbps. The number of these attacks in the company’s telemetry rose by 519% from the first quarter to the second.

DNS Flood and DNS Amplification accounted for 34.3% of observed network-layer attacks combined. DNS Flood’s share increased from 25.7% in Q1 to 40.0% in Q2, while CLDAP Flood activity rose 580% quarter over quarter.

At the same time, 96.62% of network-layer attacks stayed below 500 Mbps, and 90.60% ended within ten minutes. A smaller attack can still saturate a limited uplink, while a short attack is usually over before a team can enable mitigation manually.

These figures describe traffic seen and handled by Cloudflare’s network, not the entire Internet. For infrastructure operators, the practical response is always-on filtering and a check that exposed DNS or CLDAP services cannot be abused as amplifiers.

Primary sources