Public telemetry published across the first half of 2026 exposes a structural change in distributed denial-of-service threats: Cloudflare mitigated 935 network-layer attacks exceeding 1 Tbps in H1 2026, with 805 occurring in Q2 alone—a 519% quarter-over-quarter surge. Cloudflare reported 23.2 million mitigated network-layer DDoS attacks from January through June 2026—an average of approximately 5,343 per hour—alongside 29.64 trillion HTTP DDoS requests. Concurrently, in Akamai’s two-year dataset, EMEA was the most targeted region for Layer 3 and Layer 4 DDoS attacks, with 4,750 attacks. Navigating this environment requires unpicking significant vendor telemetry discrepancies, evaluating vectors like DNS floods and CLDAP reflection, and aligning defences with enterprise network security solutions under current UK statutory resilience mandates.
View the data behind this chart
| Q1 2026 | Q2 2026 | |
|---|---|---|
| 1 Tbps+ Attacks | Attacks130 | Attacks805 |
The Mid-2026 DDoS Landscape: Mitigated Scale vs Internet Telemetry
Evaluating DDoS attack statistics in mid-2026 requires dismantling the common industry mistake of aggregating vendor figures into a single headline number. Network security telemetry is fundamentally shaped by collection points and architectural vantage points. Cloudflare's mid-year release, the DDoS Threat Report H1 2026, consolidates Q1 and Q2 data across its own globally distributed anycast network. The dataset tracks blocked traffic delivered directly against customer endpoints, capturing 23.2 million mitigated network-layer attacks and 29.64 trillion malicious HTTP requests between January and June 2026.
Conversely, NETSCOUT tracks activity through broad Internet transit telemetry, observing volumetric adversary movements across backbone transit fabrics rather than proprietary mitigation thresholds. Akamai captures yet another operational plane in its Apps, APIs, and DDoS 2026 report, prioritising customer-edge observations, application and API exposure, and Layer 3 and Layer 4 incidents. As outlined in the methodology, these distinct observational vantage points serve as complementary threat lenses rather than additive metrics.
When evaluated as complementary lenses, however, the vendors show identical directional vectors. Volumetric saturation at the network tier has expanded rapidly, while application layers face sustained computational exhaustion through API-targeted floods and high-rate request bursts.
- •Cloudflare observed an average of 5,343 network-layer DDoS attacks mitigated every hour during H1 2026.
- •Total mitigated HTTP request volume reached 29.64 trillion requests across the first six months of 2026.
- •Vendor telemetry models must be treated as independent observational planes rather than direct cumulative metrics.

Hyper-Volumetric Attacks: The 1 Tbps Threshold in H1 2026
The defining operational metric of 2026 is the normalisation of the hyper-volumetric attack. In H1 2026, Cloudflare recorded 935 network-layer attacks exceeding 1 Tbps. What distinguishes this dataset from historical baselines is the sudden, steep acceleration between quarters: Q1 2026 recorded 130 attacks surpassing the 1 Tbps mark, whereas Q2 2026 logged 805 attacks. This represents a 519% quarter-over-quarter expansion.
A 1 Tbps attack can rapidly overwhelm many unprotected enterprise links and perimeter devices; the impact depends on available capacity, packet rate and architecture. Organisations should arrange upstream or cloud-based mitigation before traffic reaches constrained infrastructure.
Cloudflare’s data shows a sharp Q2 increase in attacks above 1 Tbps; it does not by itself establish that terabit-scale attacks are standard across the wider threat landscape.
Vector Shifts: DNS Dominance and the CLDAP Resurgence
DNS floods dominated network-layer activity in Q2 2026, accounting for 40.0% of all Cloudflare-mitigated network attacks—up from 25.7% in Q1. The wider vector distribution reveals that SYN floods constituted the second largest category at 21.4%, followed by generic UDP floods at 14.8% and ICMP floods at 5.2%, showing that established volumetric flood methods persist alongside application-protocol exploitation.
Within amplification vectors, Cloudflare reported a 580% quarter-over-quarter surge in CLDAP (Connectionless Lightweight Directory Access Protocol) reflection attacks. This increase propelled CLDAP to Cloudflare's third-ranked network-layer vector in Q2 2026, accounting for approximately 185,000 mitigated attacks (~3.1% of network-layer incidents). Attackers exploit exposed Active Directory servers to achieve amplification factors up to 70x, transforming legitimate directory infrastructure into potent volumetric reflectors.
- •DNS vectors led network-layer attacks at 40.0% in Q2 2026 (up from 25.7% in Q1), followed by SYN floods at 21.4% and UDP floods at 14.8%.
- •CLDAP reflection attacks surged 580% QoQ to approximately 185,000 mitigated attacks (~3.1% share), ranking as Cloudflare's third most common network vector in Q2 2026.
Industry Targeting: Media Saturation and Public Sector Surges
In Cloudflare’s dataset, Media, Production and Publishing was the most-attacked industry category, representing 14.2% of mitigated HTTP DDoS traffic.
Government rose from rank 29 in Q1 to rank 9 in Q2 in Cloudflare’s industry ranking. The ranking alone does not establish the cause of the increase.
Application-layer DDoS attacks can target resource-intensive endpoints and may be difficult to distinguish from legitimate traffic; effective controls should include application-aware monitoring and rate limiting.
Geographic Telemetry and the UK Regulatory Framework
In Akamai’s two-year dataset, EMEA was the most targeted region for Layer 3 and Layer 4 DDoS attacks, with 4,750 attacks. For UK infrastructure leaders, this persistent regional exposure places operational availability at the core of statutory compliance.
For organisations within the applicable NIS Regulations 2018 scope, appropriate and proportionate security measures are required, and incidents meeting the relevant significant-impact threshold must be reported to the appropriate authority.
The Data (Use and Access) Act 2025 reformed statutory data-governance standards, including personal data breach assessment rules under the UK GDPR framework. Where a volumetric DDoS attack functions as a diversionary tactic for data exfiltration or causes prolonged loss of system availability, organisations must document incident evaluations under revised Information Commissioner's Office (ICO) reporting criteria.
The National Cyber Security Centre (NCSC) provides direct operational mitigation guidance for UK organisations. The NCSC recommends using a specialist DDoS protection service and agreeing incident-response procedures before an attack. Integrating pre-configured incident response services ensures that when network degradation begins, escalation paths and mitigation rerouting proceed without operational delay. Additionally, the NCSC's Cloud Security Principles highlight network segregation and the robust protection of data in transit—foundational measures when organisations terminate and scrub traffic using cloud edge environments, Content Delivery Networks (CDNs), or Web Application Firewalls (WAFs).
- •In Akamai’s two-year dataset, EMEA was the most targeted region for Layer 3 and Layer 4 DDoS attacks, with 4,750 attacks.
- •Within the scope of the UK NIS Regulations 2018, relevant operators and digital service providers must implement appropriate and proportionate security measures and notify incidents meeting the applicable significant-impact threshold.
- •Under the Data (Use and Access) Act 2025, organisations responding to DDoS incidents that threaten data availability or mask exfiltration must evaluate revised ICO breach assessment thresholds.
- •NCSC guidance instructs UK organisations to use specialist DDoS mitigation and validate upstream capacity ahead of volumetric events.
View the data behind this chart
| Primary Focus | Core Metric | Analysis Scope | |
|---|---|---|---|
| Cloudflare | Edge mitigation | 23.2M L3/4; 29.6T HTTP | Proprietary anycast edge |
| Akamai | App/API & L3/4 | 4,750 EMEA attacks (2yr) | Customer base and apps |
| NETSCOUT | Transit telemetry | Wide-area traffic flow | Global Internet backbones |
The Financial Impact: Modelling Outage Costs
The commercial cost of an unmitigated DDoS attack extends far beyond temporary bandwidth saturation. Financial consequences fall into structural categories including transactional loss, operational remediation expenditure, and regulatory exposure.
Direct transactional exposure accumulates rapidly through dropped customer checkout sessions, failed API transactions, and contractual SLA violation penalties. Beyond top-line disruption, organisations face substantial downstream expenditures in post-incident forensic validation, customer attrition, and elevated cyber insurance premiums across subsequent renewal cycles.
Operational recovery introduces additional potential costs: emergency engineering escalation, technical triage, edge reconfiguration, and post-incident scrubbing adjustments. For regulated UK operators within the scope of the NIS Regulations 2018, an outage meeting the significant impact threshold requires notifying relevant authorities.
Mitigation Architecture: SME vs Enterprise Strategy
Organisations exposed to large volumetric attacks should assess whether local links and perimeter appliances can withstand expected traffic and should consider upstream or cloud-based mitigation.
For small-to-medium enterprises (SMEs), mitigation centres on cloud-delivered edge protection. SMEs should route public traffic through an established CDN or cloud-based proxy equipped with automated always-on DDoS mitigation. Enforcing DNS protection via managed providers eliminates exposure to recursive resolver floods, while basic rate-limiting rules shield backend application databases from burst requests without requiring bespoke 24/7 Security Operations Centre (SOC) monitoring.
Larger or critical organisations may use combinations of BGP diversion, anycast or provider-based scrubbing, segmentation, WAF controls and incident response. The appropriate design depends on exposure, service dependencies and risk assessment; no control guarantees full insulation.
Methodology
This data study compiles and synthesises empirical findings from public threat intelligence reports released in August 2026, specifically Cloudflare's DDoS Threat Report H1 2026 and Akamai's State of the Internet: Apps, APIs, and DDoS 2026 report, contextualised alongside broad Internet telemetry models from NETSCOUT. Legal and operational governance standards were compiled directly from UK statutory legislation (legislation.gov.uk) and published NCSC technical guidance.
Data collection occurred in mid-2026, reflecting threat activity recorded across the first two quarters of 2026 (1 January to 30 June 2026) alongside trailing multi-year regional baselines. Cloudflare's metrics represent mitigated network-layer and application-layer traffic observed across its proprietary global anycast edge. Akamai's telemetry reflects Layer 3 and Layer 4 attack activity directed against its customer base and infrastructure footprint over a 24-month observation window.
Figures were independently verified by cross-referencing vendor definitions to prevent erroneous data merging. In accordance with strict analytical standards, Cloudflare's mitigated network attack counts, HTTP request volumes, and 1 Tbps threshold counts are treated as distinct observational metrics and are not aggregated with Akamai's regional counts or NETSCOUT's transit-level telemetry.
Sources
Every figure in this article traces to the sources below.
- •Cloudflare — DDoS Threat Report H1 2026
- •Akamai — State of the Internet: Apps, APIs, and DDoS Security Report 2026
- •UK Legislation — The Network and Information Systems Regulations 2018
- •UK Legislation — Data (Use and Access) Act 2025
- •National Cyber Security Centre — Mitigating DDoS Attacks Guidance
- •National Cyber Security Centre — Cloud Security Principles
View the data behind this chart
| Q1 2026 | Q2 2026 | |
|---|---|---|
| DNS Attack Share | %25.7 | %40 |
The 10 data points behind this study are free to download, each with its source. The figures belong to those sources: cite the named source and check its terms before reusing a figure.
Cite as: Servnet Research, “DDoS Attack Statistics 2026: Mid-Year Analysis”, servnetuk.com, 2026.
Servnet Research publishes dated observations from public sources for information only. It is not legal, security, financial or investment advice, and data are provided without warranty. Figures from named sources belong to those sources. Spotted an error, or want something corrected or removed? See our corrections and takedown policy.
