DDoS attacks over 1 Tbps surged fivefold in the second quarter
Cloudflare reported a significant surge in extremely large network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps during the second quarter of 2026, with over 800 such attacks mitigated, a more than fivefold increase from the previous quarter. The company also mitigated a record-breaking 31.4 Tbps attack attributed to the Aisuru/Kimwolf botnet. Overall DDoS activity increased substantially in both network-layer attacks and malicious HTTP requests. Despite the rise in large-scale attacks, most incidents remained small and brief. Attack techniques shifted toward DNS-related and reflection/amplification methods. The Media, Production, and Publishing sectors were the most targeted for HTTP DDoS requests, with the government sector also seeing increased attacks linked to geopolitical events. Cloudflare attributes a decline in activity after April to an international crackdown on DDoS-for-hire services.
AI Analysis
Technical Summary
In the first half of 2026, Cloudflare mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion malicious HTTP requests. Attacks exceeding 1 Tbps surged by 519% quarter-over-quarter, with over 800 such attacks mitigated in Q2 alone compared to 130 in Q1. A record 31.4 Tbps attack was mitigated, launched by the Aisuru/Kimwolf botnet. Smaller attacks remain the majority, with 96.62% under 50 Mbps and 90.6% lasting less than 10 minutes. DNS floods and amplification attacks increased significantly, with DNS floods accounting for 40% of network-layer attacks in Q2. CLDAP floods rose by 881.9%. The increase in attacks correlates with geopolitical tensions and hacktivism, particularly targeting government sectors. An international law enforcement operation disrupted DDoS-for-hire services, leading to arrests and domain takedowns, which Cloudflare links to a subsequent decline in attack volume after April.
Potential Impact
The surge in extremely large DDoS attacks poses increased risk of service disruption for targeted organizations, particularly in Media, Production, Publishing, and government sectors. The record-breaking attack volumes demonstrate the capability of botnets like Aisuru/Kimwolf to generate unprecedented traffic levels, potentially overwhelming unprotected infrastructure. The rise in DNS-related and amplification attacks indicates evolving attacker techniques that can amplify attack traffic. While most attacks remain small and short-lived, the increase in longer-duration attacks and large-scale floods could impact availability and operational continuity for victims.
Mitigation Recommendations
Cloudflare provides mitigation for these large-scale DDoS attacks through its network infrastructure, absorbing and filtering malicious traffic. Organizations should consider deploying DDoS protection services similar to Cloudflare's to defend against high-volume attacks. The international law enforcement crackdown on DDoS-for-hire services has contributed to a reduction in attack volume, highlighting the importance of coordinated efforts against such services. No specific patches or fixes apply as this is an attack trend rather than a software vulnerability.
DDoS attacks over 1 Tbps surged fivefold in the second quarter
Description
Cloudflare reported a significant surge in extremely large network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps during the second quarter of 2026, with over 800 such attacks mitigated, a more than fivefold increase from the previous quarter. The company also mitigated a record-breaking 31.4 Tbps attack attributed to the Aisuru/Kimwolf botnet. Overall DDoS activity increased substantially in both network-layer attacks and malicious HTTP requests. Despite the rise in large-scale attacks, most incidents remained small and brief. Attack techniques shifted toward DNS-related and reflection/amplification methods. The Media, Production, and Publishing sectors were the most targeted for HTTP DDoS requests, with the government sector also seeing increased attacks linked to geopolitical events. Cloudflare attributes a decline in activity after April to an international crackdown on DDoS-for-hire services.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In the first half of 2026, Cloudflare mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion malicious HTTP requests. Attacks exceeding 1 Tbps surged by 519% quarter-over-quarter, with over 800 such attacks mitigated in Q2 alone compared to 130 in Q1. A record 31.4 Tbps attack was mitigated, launched by the Aisuru/Kimwolf botnet. Smaller attacks remain the majority, with 96.62% under 50 Mbps and 90.6% lasting less than 10 minutes. DNS floods and amplification attacks increased significantly, with DNS floods accounting for 40% of network-layer attacks in Q2. CLDAP floods rose by 881.9%. The increase in attacks correlates with geopolitical tensions and hacktivism, particularly targeting government sectors. An international law enforcement operation disrupted DDoS-for-hire services, leading to arrests and domain takedowns, which Cloudflare links to a subsequent decline in attack volume after April.
Potential Impact
The surge in extremely large DDoS attacks poses increased risk of service disruption for targeted organizations, particularly in Media, Production, Publishing, and government sectors. The record-breaking attack volumes demonstrate the capability of botnets like Aisuru/Kimwolf to generate unprecedented traffic levels, potentially overwhelming unprotected infrastructure. The rise in DNS-related and amplification attacks indicates evolving attacker techniques that can amplify attack traffic. While most attacks remain small and short-lived, the increase in longer-duration attacks and large-scale floods could impact availability and operational continuity for victims.
Defensive Guidance
Cloudflare provides mitigation for these large-scale DDoS attacks through its network infrastructure, absorbing and filtering malicious traffic. Organizations should consider deploying DDoS protection services similar to Cloudflare's to defend against high-volume attacks. The international law enforcement crackdown on DDoS-for-hire services has contributed to a reduction in attack volume, highlighting the importance of coordinated efforts against such services. No specific patches or fixes apply as this is an attack trend rather than a software vulnerability.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/ddos-attacks-over-1-tbps-surged-fivefold-in-the-second-quarter/","fetched":true,"fetchedAt":"2026-08-11T13:11:24.251Z","wordCount":805}
Threat ID: 6a7b1f7cbf8831d539c4422e
Added to database: 08/11/2026, 13:11:24 UTC
Last enriched: 08/11/2026, 13:11:38 UTC
Last updated: 08/12/2026, 01:48:49 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.