Full Report
Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year. [...]
Analysis Summary
# Industry News: Terabit-Scale DDoS Attacks Surge 519% in Q2 2026
## Summary
Cloudflare has reported a dramatic escalation in high-capacity distributed denial-of-service (DDoS) activity, with attacks exceeding 1 Tbps increasing fivefold in the second quarter of 2026. Despite a global law enforcement crackdown on DDoS-for-hire services, the emergence of sophisticated botnets like Aisuru/Kimwolf is driving record-breaking attack volumes, peaking at 31.4 Tbps.
## Key Details
- **Date:** August 11, 2026
- **Companies Involved:** Cloudflare (Primary Reporter), Aisuru/Kimwolf (Threat Actor)
- **Category:** Market Analysis / Threat Intelligence Report
## The Story
According to data presented at the Black Hat security conference, the DDoS landscape has undergone a massive volumetric shift. Cloudflare mitigated 812 attacks exceeding 1 Tbps in Q2, compared to just 130 in Q1—a 519% increase. This surge is punctuated by a new record-breaking attack of 31.4 Tbps, which represents a significant leap in the "ceiling" of what modern botnets can achieve.
The report highlights a "barbell" distribution in attack trends: while the vast majority of attacks remain small (under 50 Mbps) and short-lived, the "high end" is growing exponentially. Furthermore, attackers are pivoting their techniques, with DNS-related floods now accounting for 40% of all activity, and CLDAP (Connectionless Lightweight Directory Access Protocol) amplification attacks growing by over 880%.
## Business Impact
### For the Companies Involved
- **Cloudflare:** Solidifies its position as the "shield of the internet," leveraging its visibility into 20% of web traffic to drive thought leadership and product necessity.
- **Infrastructure Providers:** Increased operational costs associated with scrubbing and absorbing massive volumetric spikes.
### For Competitors
- **Akamai, AWS Shield, and Google Cloud:** Will face pressure to demonstrate similar mitigation capacities (30+ Tbps) to remain competitive in the enterprise and government sectors.
- **Consolidation:** Smaller DDoS mitigation players may struggle to keep up with the massive capital expenditure required to build networks capable of absorbing 30+ Tbps attacks.
### For Customers
- **Higher Security Tiers:** Organizations may need to move from "best effort" protection to guaranteed high-capacity mitigation plans.
- **Industry Vulnerability:** The "Media, Production, and Publishing" sector is currently at the highest risk, receiving over 14% of all mitigated requests.
### For the Market
- **Insurance Premiums:** Likely rise in cyber insurance premiums for industries targeted by these high-volume attacks.
- **Service Demand:** Increased demand for DNS security and "always-on" DDoS protection rather than reactive on-demand services.
## Technical Implications
The surge is driven by **amplification techniques** (CLDAP and DNS) and the maturation of the **Aisuru/Kimwolf botnet**. The shift to DNS-layer attacks is particularly concerning as it targets the foundational routing of the internet rather than just the application layer, requiring more sophisticated, protocol-aware filtering.
## Strategic Analysis
- **Market Positioning:** Cloudflare is positioning itself as the only provider capable of handling "hyper-scale" threats, effectively making DDoS protection a prerequisite for any global digital business.
- **Competitive Advantage:** The ability to provide real-time data from a global network provides a "flywheel effect"—more attacks mitigated leads to better intelligence, which attracts more customers.
- **Challenges:** The "arms race" between botnet operators and mitigation firms is accelerating. If attack sizes continue to quintuple quarterly, even the largest CDNs will face bandwidth capacity constraints.
## Industry Reactions
- **Analyst Opinions:** Analysts at Black Hat noted that while **Operation PowerOFF** successfully disrupted the "low-end" retail DDoS market, it may have inadvertently pushed sophisticated actors to develop more powerful, private botnets to bypass increased law enforcement scrutiny.
- **Market Response:** Renewed focus on "Zero Trust" for DNS and infrastructure-level hardening.
## Future Outlook
- **Predictions:** Expect the first 50 Tbps attack within the next 12 months as botnets exploit poorly secured IoT devices and high-speed 5G/6G connections.
- **What to watch for:** Potential regulatory requirements for ISPs to implement stricter egress filtering to prevent amplification attacks at the source.
## For Security Professionals
- **Action Item:** Review your DNS infrastructure. Given that DNS floods now account for 40% of attacks, traditional firewall rules are likely insufficient.
- **Context:** While the 1 Tbps+ attacks grab headlines, remember that 90% of attacks last less than 10 minutes. Resilience strategies must focus on **automated detection and mitigation**—human intervention is too slow for these durations.