Record Surge in Massive DDoS Attacks: 1 Tbps Attacks Are Becoming More Common
Distributed denial-of-service (DDoS) attacks are reaching unprecedented levels in both scale and frequency. According to Cloudflare’s latest DDoS Threat Report for the first half of 2026, the number of extremely large attacks exceeding 1 Tbps increased dramatically during the second quarter, highlighting a growing challenge for companies operating websites, online services and network infrastructure.
935 attacks above 1 Tbps in just six months
Cloudflare reports that it mitigated 935 network-layer DDoS attacks exceeding 1 Tbps between January and June 2026. Even more concerning is the acceleration recorded during the second quarter.
In Q2 alone, Cloudflare blocked 805 attacks above 1 Tbps, more than six times the number recorded during the previous quarter. Overall, the number of hyper-volumetric attacks increased by 519% quarter over quarter.
For comparison, a 1 Tbps attack generates enough traffic to put enormous pressure on network connections, firewalls, routers and server infrastructure.

More than 23 million DDoS attacks
The threat landscape is not defined only by record-breaking attacks.
During the first half of 2026, Cloudflare mitigated approximately 23.2 million network-layer DDoS attacks. That translates into roughly 5,343 attacks every hour, or around 128,000 attacks per day.
The company also recorded 29.64 trillion HTTP DDoS requests during the same period.
This shows that massive attacks above 1 Tbps represent only a fraction of the overall problem. Smaller attacks remain a serious threat, particularly for websites and servers without dedicated DDoS protection.
DNS attacks are becoming increasingly important
Another major trend identified by Cloudflare is the growing role of DNS-based attacks.
DNS attacks accounted for 34.3% of network-layer DDoS activity during the first half of 2026. DNS floods alone increased from 25.7% of network-layer attacks in Q1 to 40% in Q2.
Cloudflare also reported a 580% increase in CLDAP flood attacks between the first and second quarters, making this technique the third-largest network-layer attack vector in Q2.
The shift is significant because attackers are increasingly relying on reflection and amplification techniques rather than simply using large botnets to generate traffic.
Most DDoS attacks are short
Despite the growing number of extremely large attacks, the majority of DDoS incidents remain relatively small and short-lived.
Cloudflare says that 96.62% of network-layer attacks stayed below 500 Mbps, while 90.60% lasted less than 10 minutes during the first half of the year. Some of the largest attacks observed lasted only seconds.
This creates an important challenge for administrators: by the time a human notices the attack and begins responding, the incident may already be over.
For this reason, effective DDoS protection increasingly depends on automatic detection and mitigation rather than manual intervention.
Why is this important for hosting customers?
The latest figures are a warning not only for large technology companies but also for businesses running their websites, applications and online stores on traditional hosting or dedicated servers.
An unprotected server can become unavailable even during a much smaller attack than 1 Tbps. The actual impact depends on available bandwidth, network architecture, server resources and the protection mechanisms deployed in front of the infrastructure.
For businesses, downtime can mean lost sales, unavailable services and reputational damage.
DDoS is becoming a permanent infrastructure challenge
The latest Cloudflare figures suggest that enormous DDoS attacks are no longer isolated events. Attacks exceeding 1 Tbps are appearing with increasing frequency, while millions of smaller attacks continue to target internet infrastructure every month.
For website owners and server administrators, the conclusion is straightforward: DDoS protection should be treated as a permanent component of infrastructure security, not something activated only after an attack begins.
As attack techniques evolve and traffic volumes continue to grow, hosting providers, CDN operators and businesses need to rely increasingly on automated traffic analysis, scalable network capacity and multi-layer DDoS mitigation.
The era in which a terabit-per-second DDoS attack was considered an exceptional event is rapidly coming to an end.






