UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber Security

DDoS Attack Statistics 2026: Mid-Year Analysis

Servnet Editorial · IT infrastructure analysis6 min read
Share

Public telemetry published across the first half of 2026 exposes a structural change in distributed denial-of-service threats: Cloudflare mitigated 935 network-layer attacks exceeding 1 Tbps in H1 2026, with 805 occurring in Q2 alone—a 519% quarter-over-quarter surge. Cloudflare reported 23.2 million mitigated network-layer DDoS attacks from January through June 2026—an average of approximately 5,343 per hour—alongside 29.64 trillion HTTP DDoS requests. Concurrently, in Akamai’s two-year dataset, EMEA was the most targeted region for Layer 3 and Layer 4 DDoS attacks, with 4,750 attacks. Navigating this environment requires unpicking significant vendor telemetry discrepancies, evaluating vectors like DNS floods and CLDAP reflection, and aligning defences with enterprise network security solutions under current UK statutory resilience mandates.

Attacks Above 1 Tbps Mitigated in 2026
810 Attacks608 Attacks405 Attacks203 Attacks0 Attacks130 AttacksQ1 2026805 AttacksQ2 20261 Tbps+ Attacks
View the data behind this chart
Attacks Above 1 Tbps Mitigated in 2026
Q1 2026Q2 2026
1 Tbps+ AttacksAttacks130Attacks805

The Mid-2026 DDoS Landscape: Mitigated Scale vs Internet Telemetry

Evaluating DDoS attack statistics in mid-2026 requires dismantling the common industry mistake of aggregating vendor figures into a single headline number. Network security telemetry is fundamentally shaped by collection points and architectural vantage points. Cloudflare's mid-year release, the DDoS Threat Report H1 2026, consolidates Q1 and Q2 data across its own globally distributed anycast network. The dataset tracks blocked traffic delivered directly against customer endpoints, capturing 23.2 million mitigated network-layer attacks and 29.64 trillion malicious HTTP requests between January and June 2026.

Conversely, NETSCOUT tracks activity through broad Internet transit telemetry, observing volumetric adversary movements across backbone transit fabrics rather than proprietary mitigation thresholds. Akamai captures yet another operational plane in its Apps, APIs, and DDoS 2026 report, prioritising customer-edge observations, application and API exposure, and Layer 3 and Layer 4 incidents. As outlined in the methodology, these distinct observational vantage points serve as complementary threat lenses rather than additive metrics.

When evaluated as complementary lenses, however, the vendors show identical directional vectors. Volumetric saturation at the network tier has expanded rapidly, while application layers face sustained computational exhaustion through API-targeted floods and high-rate request bursts.

  • Cloudflare observed an average of 5,343 network-layer DDoS attacks mitigated every hour during H1 2026.
  • Total mitigated HTTP request volume reached 29.64 trillion requests across the first six months of 2026.
  • Vendor telemetry models must be treated as independent observational planes rather than direct cumulative metrics.
Illustration: DDoS Attack Statistics 2026: Mid-Year Analysis

Hyper-Volumetric Attacks: The 1 Tbps Threshold in H1 2026

The defining operational metric of 2026 is the normalisation of the hyper-volumetric attack. In H1 2026, Cloudflare recorded 935 network-layer attacks exceeding 1 Tbps. What distinguishes this dataset from historical baselines is the sudden, steep acceleration between quarters: Q1 2026 recorded 130 attacks surpassing the 1 Tbps mark, whereas Q2 2026 logged 805 attacks. This represents a 519% quarter-over-quarter expansion.

A 1 Tbps attack can rapidly overwhelm many unprotected enterprise links and perimeter devices; the impact depends on available capacity, packet rate and architecture. Organisations should arrange upstream or cloud-based mitigation before traffic reaches constrained infrastructure.

Cloudflare’s data shows a sharp Q2 increase in attacks above 1 Tbps; it does not by itself establish that terabit-scale attacks are standard across the wider threat landscape.

Vector Shifts: DNS Dominance and the CLDAP Resurgence

DNS floods dominated network-layer activity in Q2 2026, accounting for 40.0% of all Cloudflare-mitigated network attacks—up from 25.7% in Q1. The wider vector distribution reveals that SYN floods constituted the second largest category at 21.4%, followed by generic UDP floods at 14.8% and ICMP floods at 5.2%, showing that established volumetric flood methods persist alongside application-protocol exploitation.

Within amplification vectors, Cloudflare reported a 580% quarter-over-quarter surge in CLDAP (Connectionless Lightweight Directory Access Protocol) reflection attacks. This increase propelled CLDAP to Cloudflare's third-ranked network-layer vector in Q2 2026, accounting for approximately 185,000 mitigated attacks (~3.1% of network-layer incidents). Attackers exploit exposed Active Directory servers to achieve amplification factors up to 70x, transforming legitimate directory infrastructure into potent volumetric reflectors.

  • DNS vectors led network-layer attacks at 40.0% in Q2 2026 (up from 25.7% in Q1), followed by SYN floods at 21.4% and UDP floods at 14.8%.
  • CLDAP reflection attacks surged 580% QoQ to approximately 185,000 mitigated attacks (~3.1% share), ranking as Cloudflare's third most common network vector in Q2 2026.

Industry Targeting: Media Saturation and Public Sector Surges

In Cloudflare’s dataset, Media, Production and Publishing was the most-attacked industry category, representing 14.2% of mitigated HTTP DDoS traffic.

Government rose from rank 29 in Q1 to rank 9 in Q2 in Cloudflare’s industry ranking. The ranking alone does not establish the cause of the increase.

Application-layer DDoS attacks can target resource-intensive endpoints and may be difficult to distinguish from legitimate traffic; effective controls should include application-aware monitoring and rate limiting.

Geographic Telemetry and the UK Regulatory Framework

In Akamai’s two-year dataset, EMEA was the most targeted region for Layer 3 and Layer 4 DDoS attacks, with 4,750 attacks. For UK infrastructure leaders, this persistent regional exposure places operational availability at the core of statutory compliance.

For organisations within the applicable NIS Regulations 2018 scope, appropriate and proportionate security measures are required, and incidents meeting the relevant significant-impact threshold must be reported to the appropriate authority.

The Data (Use and Access) Act 2025 reformed statutory data-governance standards, including personal data breach assessment rules under the UK GDPR framework. Where a volumetric DDoS attack functions as a diversionary tactic for data exfiltration or causes prolonged loss of system availability, organisations must document incident evaluations under revised Information Commissioner's Office (ICO) reporting criteria.

The National Cyber Security Centre (NCSC) provides direct operational mitigation guidance for UK organisations. The NCSC recommends using a specialist DDoS protection service and agreeing incident-response procedures before an attack. Integrating pre-configured incident response services ensures that when network degradation begins, escalation paths and mitigation rerouting proceed without operational delay. Additionally, the NCSC's Cloud Security Principles highlight network segregation and the robust protection of data in transit—foundational measures when organisations terminate and scrub traffic using cloud edge environments, Content Delivery Networks (CDNs), or Web Application Firewalls (WAFs).

  • In Akamai’s two-year dataset, EMEA was the most targeted region for Layer 3 and Layer 4 DDoS attacks, with 4,750 attacks.
  • Within the scope of the UK NIS Regulations 2018, relevant operators and digital service providers must implement appropriate and proportionate security measures and notify incidents meeting the applicable significant-impact threshold.
  • Under the Data (Use and Access) Act 2025, organisations responding to DDoS incidents that threaten data availability or mask exfiltration must evaluate revised ICO breach assessment thresholds.
  • NCSC guidance instructs UK organisations to use specialist DDoS mitigation and validate upstream capacity ahead of volumetric events.
Vendor DDoS Telemetry Comparison
Primary FocusCore MetricAnalysis ScopeCloudflareEdge mitigation23.2M L3/4; 29.6T HTTPProprietaryanycast edgeAkamaiApp/API & L3/44,750 EMEAattacks (2yr)Customer base and appsNETSCOUTTransit telemetryWide-area traffic flowGlobal Internetbackbones
View the data behind this chart
Vendor DDoS Telemetry Comparison
Primary FocusCore MetricAnalysis Scope
CloudflareEdge mitigation23.2M L3/4; 29.6T HTTPProprietary anycast edge
AkamaiApp/API & L3/44,750 EMEA attacks (2yr)Customer base and apps
NETSCOUTTransit telemetryWide-area traffic flowGlobal Internet backbones

The Financial Impact: Modelling Outage Costs

The commercial cost of an unmitigated DDoS attack extends far beyond temporary bandwidth saturation. Financial consequences fall into structural categories including transactional loss, operational remediation expenditure, and regulatory exposure.

Direct transactional exposure accumulates rapidly through dropped customer checkout sessions, failed API transactions, and contractual SLA violation penalties. Beyond top-line disruption, organisations face substantial downstream expenditures in post-incident forensic validation, customer attrition, and elevated cyber insurance premiums across subsequent renewal cycles.

Operational recovery introduces additional potential costs: emergency engineering escalation, technical triage, edge reconfiguration, and post-incident scrubbing adjustments. For regulated UK operators within the scope of the NIS Regulations 2018, an outage meeting the significant impact threshold requires notifying relevant authorities.

Mitigation Architecture: SME vs Enterprise Strategy

Organisations exposed to large volumetric attacks should assess whether local links and perimeter appliances can withstand expected traffic and should consider upstream or cloud-based mitigation.

For small-to-medium enterprises (SMEs), mitigation centres on cloud-delivered edge protection. SMEs should route public traffic through an established CDN or cloud-based proxy equipped with automated always-on DDoS mitigation. Enforcing DNS protection via managed providers eliminates exposure to recursive resolver floods, while basic rate-limiting rules shield backend application databases from burst requests without requiring bespoke 24/7 Security Operations Centre (SOC) monitoring.

Larger or critical organisations may use combinations of BGP diversion, anycast or provider-based scrubbing, segmentation, WAF controls and incident response. The appropriate design depends on exposure, service dependencies and risk assessment; no control guarantees full insulation.

Methodology

This data study compiles and synthesises empirical findings from public threat intelligence reports released in August 2026, specifically Cloudflare's DDoS Threat Report H1 2026 and Akamai's State of the Internet: Apps, APIs, and DDoS 2026 report, contextualised alongside broad Internet telemetry models from NETSCOUT. Legal and operational governance standards were compiled directly from UK statutory legislation (legislation.gov.uk) and published NCSC technical guidance.

Data collection occurred in mid-2026, reflecting threat activity recorded across the first two quarters of 2026 (1 January to 30 June 2026) alongside trailing multi-year regional baselines. Cloudflare's metrics represent mitigated network-layer and application-layer traffic observed across its proprietary global anycast edge. Akamai's telemetry reflects Layer 3 and Layer 4 attack activity directed against its customer base and infrastructure footprint over a 24-month observation window.

Figures were independently verified by cross-referencing vendor definitions to prevent erroneous data merging. In accordance with strict analytical standards, Cloudflare's mitigated network attack counts, HTTP request volumes, and 1 Tbps threshold counts are treated as distinct observational metrics and are not aggregated with Akamai's regional counts or NETSCOUT's transit-level telemetry.

Sources

Every figure in this article traces to the sources below.

  • Cloudflare — DDoS Threat Report H1 2026
  • Akamai — State of the Internet: Apps, APIs, and DDoS Security Report 2026
  • UK Legislation — The Network and Information Systems Regulations 2018
  • UK Legislation — Data (Use and Access) Act 2025
  • National Cyber Security Centre — Mitigating DDoS Attacks Guidance
  • National Cyber Security Centre — Cloud Security Principles
DNS Share of Network-Layer Attacks
40%30%20%10%0%25.7%Q1 202640%Q2 2026DNS Attack Share
View the data behind this chart
DNS Share of Network-Layer Attacks
Q1 2026Q2 2026
DNS Attack Share%25.7%40
Open data

The 10 data points behind this study are free to download, each with its source. The figures belong to those sources: cite the named source and check its terms before reusing a figure.

Cite as: Servnet Research, “DDoS Attack Statistics 2026: Mid-Year Analysis”, servnetuk.com, 2026.

Servnet Research publishes dated observations from public sources for information only. It is not legal, security, financial or investment advice, and data are provided without warranty. Figures from named sources belong to those sources. Spotted an error, or want something corrected or removed? See our corrections and takedown policy.

Share
Key takeaways
  • Cloudflare mitigated 935 network-layer attacks exceeding 1 Tbps in H1 2026, with 805 occurring in Q2 alone.
  • DNS accounted for 40.0% of Cloudflare-observed network-layer attacks in Q2 2026, up from 25.7% in Q1.
  • Cloudflare reported a 580% QoQ increase in CLDAP reflection attacks, reaching approximately 185,000 mitigated incidents and making CLDAP its third-ranked network-layer vector in Q2 2026.
  • In Akamai’s two-year dataset, EMEA was the most targeted region for Layer 3 and Layer 4 DDoS attacks, with 4,750 attacks.
  • Within the scope of the UK NIS Regulations 2018, relevant operators and digital service providers must implement proportionate security measures and notify significant-impact incidents.
Frequently asked

FAQsDDoS Attack Statistics 2026

How many attacks exceeding 1 Tbps did Cloudflare mitigate in H1 2026?

935, including 805 in Q2.

Why do Cloudflare, NETSCOUT, and Akamai report conflicting DDoS statistics?

Their architectures measure different telemetry planes: Cloudflare monitors edge-mitigated attacks, Akamai tracks enterprise customer Layer 3/4 and API exposure, and NETSCOUT observes backbone transit flow. As detailed in the methodology, differing denominators prevent cumulative aggregation.

What are the most common DDoS attack vectors in 2026?

DNS accounted for 40.0% of Cloudflare-observed network-layer attacks in Q2 2026 (up from 25.7% in Q1), followed by SYN floods (21.4%) and generic UDP floods (14.8%). CLDAP reflection attacks also surged 580% QoQ to roughly 185,000 incidents, making CLDAP the third-ranked vector overall.

Which industries are most targeted by DDoS attacks in 2026?

Cloudflare identified Media, Production and Publishing as its most-attacked industry category, accounting for 14.2% of mitigated HTTP DDoS traffic. Government rose from rank 29 in Q1 to rank 9 in Q2 in Cloudflare’s industry ranking. The ranking alone does not establish the cause of the increase.

What are the UK legal requirements for reporting a DDoS attack?

Within the scope of the UK NIS Regulations 2018, relevant operators and digital service providers must implement appropriate security measures and notify competent authorities of incidents meeting significant-impact thresholds. In addition, if a DDoS incident disrupts personal data availability or masks data exfiltration, the Data (Use and Access) Act 2025 requires organisations to conduct and log breach assessments under reformed ICO reporting criteria.

Related

Continue reading

More in Research

Got a question this study didn’t answer?

One conversation with an engineer who’s done this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111