DDoS Attacks Surge Fivefold, Setting New Records in Q2
The cybersecurity landscape witnessed an alarming surge in large-scale Distributed Denial-of-Service (DDoS) attacks during the second quarter of the year. **Cloudflare** reported a more than fivefold increase in attacks exceeding 1 Tbps, highlighting an escalating threat to digital infrastructure worldwide. This rise underscores the persistent and evolving challenge posed by sophisticated botnets and malicious actors.

**Cloudflare**, a leading web infrastructure and security firm, has revealed a significant escalation in network-layer DDoS attacks. The company, which protects approximately 20% of the web, mitigated over 800 attacks exceeding 1 Tbps in Q2 alone. This figure marks a staggering 519% increase compared to the 130 such attacks recorded in Q1.
### Record-Breaking Incidents
The first half of the year saw **Cloudflare** mitigate a total of 23.2 million network-layer DDoS attacks and absorb 29.64 trillion malicious HTTP requests. Among these, a record-breaking incident launched by the **Aisuru/Kimwolf** botnet peaked at an unprecedented 31.4 Tbps and 200 million requests per second.
While the focus remains on these massive attacks, **Cloudflare** also noted an overall increase in less severe incidents. Attacks ranging from 500 Gbps to 1 Tbps rose by 143%, and those between 100 Gbps and 500 Gbps increased by 105%.

### Attack Duration and Volume Trends
Despite the surge in large-scale attacks, the majority of DDoS incidents remained relatively small and brief. **Cloudflare** reported that 96.62% of network-layer attacks were below 50 Mbps, with 90.6% concluding within 10 minutes. However, attacks lasting over three hours also saw a slight increase, from 0.387% in Q1 to 0.828% in Q2.

Overall network-layer DDoS activity increased by 31.2%, from 10.04 million to 13.17 million attacks. Malicious HTTP request volume also grew by 32.4%, from 12.75 trillion to 16.89 trillion.
### Post-Operation PowerOFF Decline
**Cloudflare** observed a peak in DDoS activity in April, with 6.46 trillion HTTP DDoS requests and 165 PB of network-layer attack traffic. This was followed by a notable decline, which the company tentatively attributes to the international **Operation PowerOFF** crackdown on DDoS-for-hire services.

**Operation PowerOFF** led to the arrest of four individuals, the takedown of 53 domains, and warnings issued to 75,000 users of such illicit services.
### Shifting Attack Vectors and Targets
Attack methodologies are also evolving. **Cloudflare** noted a shift towards DNS-related and reflection/amplification techniques. DNS floods accounted for 40% of attacks in Q2, up from 25.7% in Q1. Combined, DNS floods and DNS amplification attacks represented 34.3% of H1 network-layer attacks. CLDAP floods saw an astonishing 881.9% quarter-over-quarter increase, with UDP floods ranking as the second most common attack vector in Q2 at 14.06%.
In terms of targets, the Media, Production, and Publishing sector bore the brunt of mitigated HTTP DDoS requests in H1 2026, accounting for 14.2%. The government sector also experienced a significant increase, which **Cloudflare** linked to heightened hacktivism stemming from geopolitical events, including the US-Israeli military operation against Iran.