top of page

DDoS attacks surge, 935 incidents exceed 1 Tbps in the first half of 2026

Cloudflare recorded 935 network-layer DDoS attacks exceeding 1 Tbps in the first half of 2026, including 805 incidents in Q2 alone, representing a 519% increase from Q1. DNS floods and CLDAP floods also increased significantly. Most network-layer attacks still ended within 10 minutes, increasing the need for automated detection and mitigation.

The scale of DDoS attacks is increasing sharply at the extreme end, but attack size is only part of the issue. Cloudflare data shows that most network-layer attacks remain short-lived, making response processes that depend entirely on manual intervention difficult to execute quickly enough.

At the same time, attacks targeting DNS and the application layer continue to expand. Akamai’s 2026 research reported a 104% increase in Layer 7 DDoS attacks over two years, indicating that enterprises should treat DDoS as a multi-layer availability risk rather than simply a bandwidth problem.

tan-cong-ddos-nua-dau-nam-2026
DDoS attacks surge in the first half of 2026

How did DDoS attacks change in the first half of 2026?

Cloudflare’s DDoS Threat Report H1 2026 shows a particularly strong increase in attacks exceeding 1 Tbps during the second quarter. The company mitigated 935 network-layer DDoS attacks above 1 Tbps during the first six months of the year, with 805 occurring in Q2 alone, representing a 519% increase compared with Q1.

During the same period, Cloudflare reported mitigating approximately 23.2 million network-layer DDoS attacks and processing 29.64 trillion malicious HTTP DDoS requests. These figures represent activity observed across Cloudflare’s infrastructure rather than the total number of DDoS attacks occurring across the Internet.

Metric

H1 2026

Network-layer DDoS attacks mitigated

23.2 million

HTTP DDoS requests

29.64 trillion

Network-layer attacks exceeding 1 Tbps

935

Attacks exceeding 1 Tbps in Q2

805

Q2 growth in attacks above 1 Tbps

519%

Network-layer attacks below 500 Mbps

96.62%

Attacks lasting less than 10 minutes

90.60%

An important contrast emerges from the data: extremely large attacks are growing rapidly, while the majority of incidents remain relatively small and short. Cloudflare reported that 96.62% of network-layer attacks remained below 500 Mbps, while 90.60% ended within 10 minutes.

Quick Summary: Cloudflare recorded 935 network-layer DDoS attacks exceeding 1 Tbps in H1 2026, while most incidents were still smaller and short-lived. This combination makes automated detection and mitigation increasingly important alongside the capacity to absorb exceptionally large attacks.

Vietnam is seeing similar pressure. Viettel Cyber Security reported that its Viettel AntiDDoS platform detected more than 1.12 million DDoS attacks in Q1 2026, with peak traffic reaching 3.7 Tbps. Enterprises can review IPSIP’ Vietnam's analysis of the Vietnam cybersecurity landscape in Q1 2026 for broader local context.

Which DDoS attack vectors are increasing most significantly?

DNS has become a prominent component of the DDoS threat landscape in H1 2026. Cloudflare reported that DNS-based attacks accounted for 34.3% of network-layer DDoS activity, while the share of DNS flood attacks increased from 25.7% in Q1 to 40% in Q2.

A DNS flood generates a large volume of DNS queries designed to exhaust the processing capacity of DNS infrastructure. If authoritative DNS servers become overwhelmed, users may be unable to resolve a domain name and reach the associated website or online service even if the application servers themselves remain operational.

Another attack vector showing substantial growth is CLDAP flooding, which increased by 580% quarter over quarter and became the third most common network-layer attack vector in Q2. Reflection and amplification techniques can abuse insecurely exposed UDP services to redirect and multiply traffic toward a target.

At the application layer, Akamai reported that Layer 7 DDoS attacks increased 104% between 2023 and 2025. Its research also indicates that modern campaigns may combine DDoS, web application attacks, and API abuse rather than targeting only one layer of an organization’s infrastructure.

Why can short DDoS attacks still cause major disruption?

With more than 90% of network-layer DDoS attacks observed by Cloudflare ending in less than 10 minutes, response speed has become a critical issue. A process that requires receiving an alert, manually validating the incident, contacting a provider, and then redirecting traffic may not react quickly enough to many modern attacks.

A short attack does not necessarily mean a low-impact attack. Depending on the architecture, a sudden traffic spike can saturate Internet bandwidth, exhaust firewall or load balancer resources, trigger application timeouts, and interrupt legitimate user sessions.

CISA categorizes denial-of-service attacks into three main groups: volumetric, protocol, and application-layer attacks. This means enterprises should not expect a single security appliance to address every DDoS scenario.

At the network edge, Next-Generation Firewalls can help enforce traffic policies and identify suspicious activity. However, when volumetric DDoS traffic exceeds an enterprise’s Internet connection capacity, malicious traffic needs to be mitigated upstream through an ISP, CDN, cloud platform, or high-capacity scrubbing infrastructure before reaching the on-premises firewall.

What should enterprises do in response to the new DDoS landscape?

  • Inventory all critical Internet-facing websites, APIs, DNS services, VPN gateways, and other public services.

  • Identify bandwidth limits and the processing capacity of routers, firewalls, load balancers, and applications.

  • Review the DDoS protection capabilities provided by existing ISPs, cloud platforms, CDNs, and security vendors.

  • Enable continuous traffic monitoring and anomaly detection.

  • Assess the redundancy and resilience of authoritative DNS infrastructure.

  • Configure rate limiting, WAF controls, and bot-management measures for web applications and APIs where appropriate.

  • Build a DDoS response playbook covering coordination among IT, Security, ISPs, cloud/CDN providers, and other vendors.

  • Retain network, DNS, firewall, and application logs for incident investigation.

  • Conduct regular exercises to test detection, escalation, mitigation, and service recovery procedures.

What does IPSIP Vietnam’s cybersecurity perspective suggest?

Enterprises should prepare for volumetric floods, protocol attacks, DNS floods, reflection/amplification techniques, and Layer 7 DDoS attacks. Data from Cloudflare and Akamai indicates that DDoS risks increasingly span both network and application layers.

Infrastructure availability monitoring should also be integrated with security monitoring. IPSIP NOC 24/7 can support continuous visibility into network, server, and IT service availability, while a SOC focuses on analyzing security signals and coordinating responses to threats.

DDoS attacks in 2026 are notable not only because some incidents now exceed terabit-scale traffic levels, but also because of their speed, diversity, and ability to target several layers of infrastructure. DNS, networks, web applications, and APIs can all become points of service disruption.

For Vietnamese enterprises, the priority should be to identify capacity limits in advance, deploy continuous monitoring, coordinate upstream mitigation with ISPs or cloud/CDN providers, and maintain an incident-response playbook that can be activated quickly. DDoS resilience should therefore be treated as part of business continuity and enterprise risk management rather than solely as an IT security issue.

References

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page