SAN FRANCISCO, 11 AUG 2026 — Cloudflare mitigated 935 network-layer denial-of-service attacks larger than one terabit per second in the first half of 2026, and says the count rose 519 per cent between the first quarter and the second.

That percentage has been widely reported as a fivefold increase. It is not. A 519 per cent increase means the Q2 figure is 6.19 times the Q1 figure. Getting that distinction right is what keeps a capacity plan from falling over.

The arithmetic, since it is being got wrong

An increase of 519 per cent and a multiple of 5.19 are different statements. Adding 519 per cent to a number leaves you with 619 per cent of it.

The two published figures let you check this without trusting anyone's phrasing. If the half-year total is 935 and the second quarter is 6.19 times the first, then the first quarter is about 130 attacks and the second about 805 — and 805 is precisely the Q2 figure other outlets have reported.

935Network-layer attacks above 1 Tbps mitigated in H1 2026.
+519%Quarter-on-quarter change, which is a multiple of 6.19, not 5.19.
~130 → ~805Implied Q1 and Q2 counts. The second figure matches independent reporting.
23.2 millionNetwork-layer attacks in total, plus 29.64 trillion HTTP DDoS requests.

None of this makes the underlying report wrong. Cloudflare states the percentage and the total; the slip happens in translation, and it happens in the direction that understates the problem.

The number that should worry an operations team

Terabit attacks are the headline and the wrong thing to plan around, because almost nobody absorbs one on their own infrastructure. The relevant figure is the routine rate.

Cloudflare puts network-layer attacks at roughly 5,343 per hour, or about 128,000 a day. That is the background weather of the internet in 2026, and it is what a mitigation contract is actually being bought to handle.

The vector shift matters more than the size

The composition of these attacks also changed materially between quarters, which is what has operational consequences.

DNS-based attacks accounted for 34.3 per cent of all network-layer activity in the first half. DNS Floods alone climbed from 25.7 per cent of network-layer attacks to 40.0 per cent quarter on quarter. CLDAP Floods surged 580 per cent to become the third-ranked vector in the second quarter.

Both DNS and CLDAP are reflection and amplification vectors. The attacker does not need a large botnet; they need a small request that provokes a large answer, and a supply of misconfigured servers on the internet willing to send that answer to a forged address.

The practical difference is where you can intervene. A botnet flood is somebody else's compromised machines, and there is nothing you can do about them. Reflection and amplification depend on services that should not be answering strangers, and a meaningful share of those are ordinary organisations running an open resolver or an exposed directory service without realising they are part of somebody's weapon.

Who is being hit

Media, Production and Publishing was the most-attacked industry in both quarters, at 14.2 per cent.

Consider that for a moment: publishing is not a wealthy target like finance. Attacking a publisher rarely produces a ransom. It produces silence, which is the point, and it is the cheapest form of censorship available to anyone with a few hundred dollars and a grudge.

The largest single movement of the year so far was the Government sector, which jumped from twenty-ninth most attacked to ninth. Turkey rose to third most-attacked country, which Cloudflare notes against the backdrop of July's NATO summit in Ankara.

Read together, those two facts describe denial of service returning to what it was before it became a criminal business: a political instrument, aimed at governments and at the press, timed around events.

What this means if you run something small

Two things, and neither is "buy a terabit of capacity".

First, check whether you are part of the problem. Reflection attacks are powered by services answering queries they should refuse. An open DNS resolver, an exposed CLDAP or NTP service, a misconfigured memcached — these are the ammunition, and closing them costs nothing but attention.

Second, understand that a DDoS is now cheap enough that being unimportant is not protection. A publisher with a strong opinion and a modest audience is a plausible target, and the volumes described here are far beyond what any single origin server absorbs.

What to watch

Whether the reflection shift holds into the second half. Amplification vectors rise and fall as the pool of misconfigured servers is found and then cleaned up, and CLDAP's 580 per cent quarter is the signature of a newly discovered pool rather than a permanent change.

Whether anyone publishes comparable figures. This is one network's view, and it is a very large one, but a second vantage point would turn a measurement into a fact about the internet.

And whether the government-sector jump persists past the events that produced it. A sector moving twenty places in a quarter is usually a campaign, not a trend, and campaigns end.