Hyper-volumetric DDoS attacks surge 519% as DNS floods and geopolitics collide

The numbers that matter
In its H1 2026 DDoS Threat Report, Cloudflare reveals a 519% year-over-year surge in hyper-volumetric attacks across its network. That is not a rounding error. Attacks regularly exceeded 1 Tbps, and the volume curve bent sharply upward.
DNS floods and CLDAP: the amplifier du jour
The culprit vectors are DNS reflection and CLDAP amplification. A DNS flood bombards a target with spoofed queries, each returning a response up to 50 times larger. CLDAP (Connectionless Lightweight Directory Access Protocol) reflection tricks unsecured servers into amplifying traffic by 56x on average. Combined, these techniques let attackers forge multi-Tbps firehoses without needing a giant botnet.
Why geopolitics lit the fuse
The report ties the surge directly to ongoing geopolitical conflicts. Digital warfare now runs in lockstep with kinetic operations, and DDoS is the cheap, deniable first strike. Critical infrastructure, government portals, and financial services are on the front line.
"A 519% jump in hyper-volumetric DDoS is not a trend. It's a structural shift in how digital warfare is waged."
The Radar picture
Cloudflare Radar data shows that attack traffic increasingly originates from regions embroiled in conflict, while the most targeted sectors map directly to national vulnerabilities. The pattern is consistent: as tensions escalate, DDoS volumes spike.
Defense that doesn’t buckle
Traditional mitigation fails against multi-Tbps barrages. Blackholing, on-premise boxes, and ISP scrubbing are not built for this scale. Cloudflare’s anycast network absorbed it, but most organizations are not Cloudflare. The report is a nudge to rethink edge architecture:
- Shift to always-on, cloud-delivered DDoS mitigation.
- Harden DNS resolvers and block open CLDAP servers at the edge.
- Monitor geopolitical threat feeds for early warning.
- Test incident response plans against 1+ Tbps simulations.