DDoS at 1 Tbps: 935 Hyper-Volumetric Attacks Redefine Performance

935 DDoS attacks over 1 Tbps in six months. DNS floods and CLDAP amplification are resetting performance baselines.
Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave
By Andres SEO Expert.

Key Takeaways

  • Cloudflare mitigated 935 network-layer DDoS attacks exceeding 1 Tbps in H1 2026.
  • DNS floods and CLDAP amplification dominate, with CLDAP attacks surging 580% QoQ.
  • Attacks are fast: 90.6% under 10 minutes; even 35-second bursts can cause hour-long degradation.

935 Hyper-Volumetric Assaults in Six Months: A New Baseline for Network Performance

The DDoS threat landscape has crossed a sobering threshold. Cloudflare’s H1 2026 DDoS Threat Report documents that the company mitigated a combined 935 network-layer attacks exceeding 1 terabit per second in the first half of the year.

Between Q1 and Q2, the volume of such hyper-volumetric events exploded by 519 percent — a more than sixfold surge that redefines what network infrastructure must routinely absorb.

These aren’t isolated spikes. Midway through 2026, Cloudflare had already fended off 23.2 million network-layer DDoS attacks and 29.64 trillion HTTP DDoS requests, averaging 5,343 attacks every hour.

Yet, as outlined in Cloudflare’s DDoS Threat Report, the raw numbers only hint at the structural shift underway: attack vectors are pivoting from brute-force botnet floods toward reflection and amplification techniques that weaponize the internet’s own infrastructure against itself.

The Anatomy of a 1 Tbps Assault: DNS Floods and CLDAP Amplification

DNS-based attacks — both floods and amplification — dominated the network layer, accounting for 34.3 percent of all activity in H1 2026. DNS Floods alone climbed from 25.7 percent to 40.0 percent of network-layer attacks quarter-over-quarter.

The two mechanisms differ sharply. A DNS Flood directs a botnet’s raw query volume straight at a victim’s authoritative servers, exhausting query capacity until the domain’s ‘phonebook’ goes dark and every dependent service collapses.

DNS Amplification, in contrast, sends small spoofed queries to open resolvers, which reply with payloads tens of times larger, drowning the victim in reflected traffic.

The most explosive growth, however, belonged to CLDAP Floods — a reflection and amplification vector that abuses exposed Active Directory endpoints over UDP port 389.

CLDAP surged 580 percent quarter-over-quarter to become the third most prevalent attack vector in Q2. Attackers send compact spoofed queries to publicly reachable domain controllers, and the servers answer the victim’s IP with responses amplified by orders of magnitude.

No handshake is needed, making UDP-based CLDAP a trivially exploitable reflection weapon — and a direct threat to any organization still exposing LDAP services to the open internet.

Why Attack Brevity Makes Always-On Mitigation a Performance Imperative

Amid the giant figures, the median DDoS attack remained remarkably short and small. In H1 2026, 96.62 percent of network-layer attacks stayed below 500 Mbps, and 90.60 percent ended in under ten minutes.

But ‘small’ is a dangerously relative term. As the report underscores, a 100 Mbps attack is enough to overwhelm typical servers, a 100 Gbps assault can knock unprotected data centers offline, and a 1 Tbps strike stresses even the most fortified infrastructure.

Many hyper-volumetric attacks are even briefer — Cloudflare has observed record-breaking bursts that last a mere 35 seconds. Human intervention is irrelevant at that speed; manual mitigation and on-demand scrubbing arrive long after the attack has done its damage.

The aftershocks, however, can cascade for hours or days. Even a sub-minute spike triggers routing instability, TCP retransmissions, application timeouts, and downstream degradation that keeps services impaired well beyond the attack window.

For performance-conscious organizations, the message is explicit: always-on, autonomous protection isn’t a luxury — it is the only architecture capable of meeting a threat that strikes and vanishes faster than any human can respond.

Attackers are also mixing layers, combining high packet rates with moderate bandwidth, or vice versa, to exploit distinct weaknesses in network gear and bandwidth capacity. That demands mitigation systems that can handle both volumetric and protocol-level attacks simultaneously, without adding latency.

When Infrastructure Can’t Flinch

The lesson of H1 2026 isn’t simply that attacks are larger — it’s that they are too fast, too cheap to launch, and too effective at weaponizing legitimate protocols for any reactive defense to survive. For teams that need infrastructure that can absorb hyper-volumetric attacks without breaking performance, managed WordPress cloud hosting from Andres SEO Expert is built for it — let’s talk.

Frequently Asked Questions

How many network-layer attacks exceeded 1 terabit per second in H1 2026?

Cloudflare mitigated a combined 935 network-layer attacks exceeding 1 terabit per second in the first half of 2026, with a 519% quarter-over-quarter surge in such hyper-volumetric events.

What is a DNS amplification attack?

DNS amplification is a reflection and amplification technique where attackers send small spoofed queries to open resolvers, which reply with payloads tens of times larger, drowning the victim in reflected traffic.

What is a CLDAP flood and why is it effective?

A CLDAP flood abuses exposed Active Directory endpoints over UDP port 389. Attackers send compact spoofed queries to publicly reachable domain controllers, and the servers answer the victim’s IP with responses amplified by orders of magnitude. It surged 580% quarter-over-quarter to become the third most prevalent attack vector in Q2.

Why are short DDoS attacks particularly challenging to mitigate?

Many hyper-volumetric attacks last only a few seconds, with record-breaking bursts as brief as 35 seconds. Human intervention is irrelevant at that speed, and manual mitigation arrives long after damage is done. Sub-minute spikes also cause cascading routing instability and application timeouts.

What percentage of network-layer attacks are under 500 Mbps?

In H1 2026, 96.62% of network-layer attacks stayed below 500 Mbps, and 90.60% ended in under ten minutes. However, even a 100 Mbps attack can overwhelm typical servers.

Why is always-on mitigation essential for modern DDoS defense?

Because attacks are too fast, too cheap to launch, and too effective at weaponizing legitimate protocols. Always-on autonomous protection is the only architecture capable of meeting a threat that strikes and vanishes faster than any human can respond, handling both volumetric and protocol-level attacks simultaneously without adding latency.

Prev Next

Subscribe to My Newsletter

Subscribe to my email newsletter to get the latest posts delivered right to your email. Pure inspiration, zero spam.
You agree to the Terms of Use and Privacy Policy