Back Uk.Pcmag Major DDoS Attacks Are Booming, But US No Longer the Most Targeted Country
Cloudflare has now racked up 25 years of regularly publishing data on the distributed denial-of-service attacks it works to thwart, and a Tuesday report marking what we have to think of as a tarnished silver anniversary reveals they’re bigger and badder than ever. Researchers quantify these coordinated assaults on servers in terms of how much data an attacker can throw at one to stymie or stop its operations, and those per-second figures increasingly feature terabits instead of gigabits or mere megabits . As a summary of the report covering the first half of 2026 leads off: “The 1 Tbps club grew.” A brief typology in the report explains that a Tbps-scale DDoS attack “stresses even major internet infrastructure,” while a 100Gbps attack “can knock most unprotected data centers offline” and 100Mbps can “overwhelm a server or website.” The report says Cloudflare dealt with 935 1Tbps-and-up attacks in the first half of 2026, with their numbers spiking by 519% from Q1 to Q2. The San Francisco firm provides free basic DDoS protection and sells higher-end plans to sites that might require added defenses; it’s become an enormously influential interface layer for the entire web. At least this year does not seem to have set new records for the size of individual attacks after 2025, when the record kept ratcheting up: 5.6Tbps in January , 7.3Tbps in June , 11.5 Tbps in September , 29.7Tbps and then 31.4Tbps in December. Over the first half of 2026, April was the cruelest month. Cloudflare clocked a peak of 6.46 trillion site requests to attacked sites that added up to 165 petabytes, which the report calls “equivalent to streaming 4K video continuously for years.” The problem has eased since, which Cloudflare suggests could be the result of law-enforcement agencies across 21 countries, the US included, that targeted customers of DDoS services with warnings and, in far fewer cases, domain takedowns and arrests . The report observes that the paths of DDoS attacks increasingly trace the outlines of physical-world conflicts. In particular, the attacks on Iran by the US and Israel starting in late February led to a rise in counterattacks , which should not have surprised anybody, given the years of advance warning of Iran’s growing cyber capabilities . But by the end of the first half of the year, the US was no longer the most-attacked country; in Q2, China claimed that dubious honor, receiving 22.4% of DDoS attacks while the US was hit by 18.8%. Turkey took third place in that quarter, which featured the NATO summit in its capital, Ankara. Network administrators should find some utility in the report’s details attack vectors: While flooding domain-name-system servers with bogus requests remains the most common tactic, a networking standard called Connectionless Lightweight Directory Access Protocol, which is vulnerable to source spoofing, became a much bigger target from Q1 to Q2. Individual internet users may find less to work on in this report. But since so many DDoS attacks have involved botnets of hacked consumer IoT devices, from 2016’s Mirai to the Aisuru botnet behind last year’s 31.4Tbps record, we’ll offer our usual reminder to keep your gadgets updated. And to choose connected- hardware with security in mind, which remains harder than it should be, thanks to the government’s Cyber Trust Mark label ’s stalled development and the Matter smart- standard still being hard to shop for .
Researchers quantify these coordinated assaults on servers in terms of how much data an attacker can throw at one to stymie or stop its operations, and those per-second figures increasingly feature terabits instead of gigabits or mere megabits . As a summary of the report covering the first half of 2026 leads off: “The 1 Tbps club grew.” A brief typology in the report explains that a Tbps-scale DDoS attack “stresses even major internet infrastructure,” while a 100Gbps attack “can knock most unprotected data centers offline” and 100Mbps can “overwhelm a server or website.” The report says Cloudflare dealt with 935 1Tbps-and-up attacks in the first half of 2026, with their numbers spiking by 519% from Q1 to Q2. The San Francisco firm provides free basic DDoS protection and sells higher-end plans to sites that might require added defenses; it’s become an enormously influential interface layer for the entire web. At least this year does not seem to have set new records for the size of individual attacks after 2025, when the record kept ratcheting up: 5.6Tbps in January , 7.3Tbps in June , 11.5 Tbps in September , 29.7Tbps and then 31.4Tbps in December. Over the first half of 2026, April was the cruelest month. Cloudflare clocked a peak of 6.46 trillion site requests to attacked sites that added up to 165 petabytes, which the report calls “equivalent to streaming 4K video continuously for years.” The problem has eased since, which Cloudflare suggests could be the result of law-enforcement agencies across 21 countries, the US included, that targeted customers of DDoS services with warnings and, in far fewer cases, domain takedowns and arrests . The report observes that the paths of DDoS attacks increasingly trace the outlines of physical-world conflicts. In particular, the attacks on Iran by the US and Israel starting in late February led to a rise in counterattacks , which should not have surprised anybody, given the years of advance warning of Iran’s growing cyber capabilities . But by the end of the first half of the year, the US was no longer the most-attacked country; in Q2, China claimed that dubious honor, receiving 22.4% of DDoS attacks while the US was hit by 18.8%. Turkey took third place in that quarter, which featured the NATO summit in its capital, Ankara. Network administrators should find some utility in the report’s details attack vectors: While flooding domain-name-system servers with bogus requests remains the most common tactic, a networking standard called Connectionless Lightweight Directory Access Protocol, which is vulnerable to source spoofing, became a much bigger target from Q1 to Q2. Individual internet users may find less to work on in this report. But since so many DDoS attacks have involved botnets of hacked consumer IoT devices, from 2016’s Mirai to the Aisuru botnet behind last year’s 31.4Tbps record, we’ll offer our usual reminder to keep your gadgets updated. And to choose connected- hardware with security in mind, which remains harder than it should be, thanks to the government’s Cyber Trust Mark label ’s stalled development and the Matter smart- standard still being hard to shop for .
A brief typology in the report explains that a Tbps-scale DDoS attack “stresses even major internet infrastructure,” while a 100Gbps attack “can knock most unprotected data centers offline” and 100Mbps can “overwhelm a server or website.” The report says Cloudflare dealt with 935 1Tbps-and-up attacks in the first half of 2026, with their numbers spiking by 519% from Q1 to Q2. The San Francisco firm provides free basic DDoS protection and sells higher-end plans to sites that might require added defenses; it’s become an enormously influential interface layer for the entire web. At least this year does not seem to have set new records for the size of individual attacks after 2025, when the record kept ratcheting up: 5.6Tbps in January , 7.3Tbps in June , 11.5 Tbps in September , 29.7Tbps and then 31.4Tbps in December. Over the first half of 2026, April was the cruelest month. Cloudflare clocked a peak of 6.46 trillion site requests to attacked sites that added up to 165 petabytes, which the report calls “equivalent to streaming 4K video continuously for years.” The problem has eased since, which Cloudflare suggests could be the result of law-enforcement agencies across 21 countries, the US included, that targeted customers of DDoS services with warnings and, in far fewer cases, domain takedowns and arrests . The report observes that the paths of DDoS attacks increasingly trace the outlines of physical-world conflicts. In particular, the attacks on Iran by the US and Israel starting in late February led to a rise in counterattacks , which should not have surprised anybody, given the years of advance warning of Iran’s growing cyber capabilities . But by the end of the first half of the year, the US was no longer the most-attacked country; in Q2, China claimed that dubious honor, receiving 22.4% of DDoS attacks while the US was hit by 18.8%. Turkey took third place in that quarter, which featured the NATO summit in its capital, Ankara. Network administrators should find some utility in the report’s details attack vectors: While flooding domain-name-system servers with bogus requests remains the most common tactic, a networking standard called Connectionless Lightweight Directory Access Protocol, which is vulnerable to source spoofing, became a much bigger target from Q1 to Q2. Individual internet users may find less to work on in this report. But since so many DDoS attacks have involved botnets of hacked consumer IoT devices, from 2016’s Mirai to the Aisuru botnet behind last year’s 31.4Tbps record, we’ll offer our usual reminder to keep your gadgets updated. And to choose connected- hardware with security in mind, which remains harder than it should be, thanks to the government’s Cyber Trust Mark label ’s stalled development and the Matter smart- standard still being hard to shop for .
The report says Cloudflare dealt with 935 1Tbps-and-up attacks in the first half of 2026, with their numbers spiking by 519% from Q1 to Q2. The San Francisco firm provides free basic DDoS protection and sells higher-end plans to sites that might require added defenses; it’s become an enormously influential interface layer for the entire web. At least this year does not seem to have set new records for the size of individual attacks after 2025, when the record kept ratcheting up: 5.6Tbps in January , 7.3Tbps in June , 11.5 Tbps in September , 29.7Tbps and then 31.4Tbps in December. Over the first half of 2026, April was the cruelest month. Cloudflare clocked a peak of 6.46 trillion site requests to attacked sites that added up to 165 petabytes, which the report calls “equivalent to streaming 4K video continuously for years.” The problem has eased since, which Cloudflare suggests could be the result of law-enforcement agencies across 21 countries, the US included, that targeted customers of DDoS services with warnings and, in far fewer cases, domain takedowns and arrests . The report observes that the paths of DDoS attacks increasingly trace the outlines of physical-world conflicts. In particular, the attacks on Iran by the US and Israel starting in late February led to a rise in counterattacks , which should not have surprised anybody, given the years of advance warning of Iran’s growing cyber capabilities . But by the end of the first half of the year, the US was no longer the most-attacked country; in Q2, China claimed that dubious honor, receiving 22.4% of DDoS attacks while the US was hit by 18.8%. Turkey took third place in that quarter, which featured the NATO summit in its capital, Ankara. Network administrators should find some utility in the report’s details attack vectors: While flooding domain-name-system servers with bogus requests remains the most common tactic, a networking standard called Connectionless Lightweight Directory Access Protocol, which is vulnerable to source spoofing, became a much bigger target from Q1 to Q2. Individual internet users may find less to work on in this report. But since so many DDoS attacks have involved botnets of hacked consumer IoT devices, from 2016’s Mirai to the Aisuru botnet behind last year’s 31.4Tbps record, we’ll offer our usual reminder to keep your gadgets updated. And to choose connected- hardware with security in mind, which remains harder than it should be, thanks to the government’s Cyber Trust Mark label ’s stalled development and the Matter smart- standard still being hard to shop for .
At least this year does not seem to have set new records for the size of individual attacks after 2025, when the record kept ratcheting up: 5.6Tbps in January , 7.3Tbps in June , 11.5 Tbps in September , 29.7Tbps and then 31.4Tbps in December. Over the first half of 2026, April was the cruelest month. Cloudflare clocked a peak of 6.46 trillion site requests to attacked sites that added up to 165 petabytes, which the report calls “equivalent to streaming 4K video continuously for years.” The problem has eased since, which Cloudflare suggests could be the result of law-enforcement agencies across 21 countries, the US included, that targeted customers of DDoS services with warnings and, in far fewer cases, domain takedowns and arrests . The report observes that the paths of DDoS attacks increasingly trace the outlines of physical-world conflicts. In particular, the attacks on Iran by the US and Israel starting in late February led to a rise in counterattacks , which should not have surprised anybody, given the years of advance warning of Iran’s growing cyber capabilities . But by the end of the first half of the year, the US was no longer the most-attacked country; in Q2, China claimed that dubious honor, receiving 22.4% of DDoS attacks while the US was hit by 18.8%. Turkey took third place in that quarter, which featured the NATO summit in its capital, Ankara. Network administrators should find some utility in the report’s details attack vectors: While flooding domain-name-system servers with bogus requests remains the most common tactic, a networking standard called Connectionless Lightweight Directory Access Protocol, which is vulnerable to source spoofing, became a much bigger target from Q1 to Q2. Individual internet users may find less to work on in this report. But since so many DDoS attacks have involved botnets of hacked consumer IoT devices, from 2016’s Mirai to the Aisuru botnet behind last year’s 31.4Tbps record, we’ll offer our usual reminder to keep your gadgets updated. And to choose connected- hardware with security in mind, which remains harder than it should be, thanks to the government’s Cyber Trust Mark label ’s stalled development and the Matter smart- standard still being hard to shop for .
Over the first half of 2026, April was the cruelest month. Cloudflare clocked a peak of 6.46 trillion site requests to attacked sites that added up to 165 petabytes, which the report calls “equivalent to streaming 4K video continuously for years.” The problem has eased since, which Cloudflare suggests could be the result of law-enforcement agencies across 21 countries, the US included, that targeted customers of DDoS services with warnings and, in far fewer cases, domain takedowns and arrests . The report observes that the paths of DDoS attacks increasingly trace the outlines of physical-world conflicts. In particular, the attacks on Iran by the US and Israel starting in late February led to a rise in counterattacks , which should not have surprised anybody, given the years of advance warning of Iran’s growing cyber capabilities . But by the end of the first half of the year, the US was no longer the most-attacked country; in Q2, China claimed that dubious honor, receiving 22.4% of DDoS attacks while the US was hit by 18.8%. Turkey took third place in that quarter, which featured the NATO summit in its capital, Ankara. Network administrators should find some utility in the report’s details attack vectors: While flooding domain-name-system servers with bogus requests remains the most common tactic, a networking standard called Connectionless Lightweight Directory Access Protocol, which is vulnerable to source spoofing, became a much bigger target from Q1 to Q2. Individual internet users may find less to work on in this report. But since so many DDoS attacks have involved botnets of hacked consumer IoT devices, from 2016’s Mirai to the Aisuru botnet behind last year’s 31.4Tbps record, we’ll offer our usual reminder to keep your gadgets updated. And to choose connected- hardware with security in mind, which remains harder than it should be, thanks to the government’s Cyber Trust Mark label ’s stalled development and the Matter smart- standard still being hard to shop for .
The problem has eased since, which Cloudflare suggests could be the result of law-enforcement agencies across 21 countries, the US included, that targeted customers of DDoS services with warnings and, in far fewer cases, domain takedowns and arrests . The report observes that the paths of DDoS attacks increasingly trace the outlines of physical-world conflicts. In particular, the attacks on Iran by the US and Israel starting in late February led to a rise in counterattacks , which should not have surprised anybody, given the years of advance warning of Iran’s growing cyber capabilities . But by the end of the first half of the year, the US was no longer the most-attacked country; in Q2, China claimed that dubious honor, receiving 22.4% of DDoS attacks while the US was hit by 18.8%. Turkey took third place in that quarter, which featured the NATO summit in its capital, Ankara. Network administrators should find some utility in the report’s details attack vectors: While flooding domain-name-system servers with bogus requests remains the most common tactic, a networking standard called Connectionless Lightweight Directory Access Protocol, which is vulnerable to source spoofing, became a much bigger target from Q1 to Q2. Individual internet users may find less to work on in this report. But since so many DDoS attacks have involved botnets of hacked consumer IoT devices, from 2016’s Mirai to the Aisuru botnet behind last year’s 31.4Tbps record, we’ll offer our usual reminder to keep your gadgets updated. And to choose connected- hardware with security in mind, which remains harder than it should be, thanks to the government’s Cyber Trust Mark label ’s stalled development and the Matter smart- standard still being hard to shop for .
The report observes that the paths of DDoS attacks increasingly trace the outlines of physical-world conflicts. In particular, the attacks on Iran by the US and Israel starting in late February led to a rise in counterattacks , which should not have surprised anybody, given the years of advance warning of Iran’s growing cyber capabilities . But by the end of the first half of the year, the US was no longer the most-attacked country; in Q2, China claimed that dubious honor, receiving 22.4% of DDoS attacks while the US was hit by 18.8%. Turkey took third place in that quarter, which featured the NATO summit in its capital, Ankara. Network administrators should find some utility in the report’s details attack vectors: While flooding domain-name-system servers with bogus requests remains the most common tactic, a networking standard called Connectionless Lightweight Directory Access Protocol, which is vulnerable to source spoofing, became a much bigger target from Q1 to Q2. Individual internet users may find less to work on in this report. But since so many DDoS attacks have involved botnets of hacked consumer IoT devices, from 2016’s Mirai to the Aisuru botnet behind last year’s 31.4Tbps record, we’ll offer our usual reminder to keep your gadgets updated. And to choose connected- hardware with security in mind, which remains harder than it should be, thanks to the government’s Cyber Trust Mark label ’s stalled development and the Matter smart- standard still being hard to shop for .
But by the end of the first half of the year, the US was no longer the most-attacked country; in Q2, China claimed that dubious honor, receiving 22.4% of DDoS attacks while the US was hit by 18.8%. Turkey took third place in that quarter, which featured the NATO summit in its capital, Ankara. Network administrators should find some utility in the report’s details attack vectors: While flooding domain-name-system servers with bogus requests remains the most common tactic, a networking standard called Connectionless Lightweight Directory Access Protocol, which is vulnerable to source spoofing, became a much bigger target from Q1 to Q2. Individual internet users may find less to work on in this report. But since so many DDoS attacks have involved botnets of hacked consumer IoT devices, from 2016’s Mirai to the Aisuru botnet behind last year’s 31.4Tbps record, we’ll offer our usual reminder to keep your gadgets updated. And to choose connected- hardware with security in mind, which remains harder than it should be, thanks to the government’s Cyber Trust Mark label ’s stalled development and the Matter smart- standard still being hard to shop for .
Network administrators should find some utility in the report’s details attack vectors: While flooding domain-name-system servers with bogus requests remains the most common tactic, a networking standard called Connectionless Lightweight Directory Access Protocol, which is vulnerable to source spoofing, became a much bigger target from Q1 to Q2. Individual internet users may find less to work on in this report. But since so many DDoS attacks have involved botnets of hacked consumer IoT devices, from 2016’s Mirai to the Aisuru botnet behind last year’s 31.4Tbps record, we’ll offer our usual reminder to keep your gadgets updated. And to choose connected- hardware with security in mind, which remains harder than it should be, thanks to the government’s Cyber Trust Mark label ’s stalled development and the Matter smart- standard still being hard to shop for .
Individual internet users may find less to work on in this report. But since so many DDoS attacks have involved botnets of hacked consumer IoT devices, from 2016’s Mirai to the Aisuru botnet behind last year’s 31.4Tbps record, we’ll offer our usual reminder to keep your gadgets updated. And to choose connected- hardware with security in mind, which remains harder than it should be, thanks to the government’s Cyber Trust Mark label ’s stalled development and the Matter smart- standard still being hard to shop for .
And to choose connected- hardware with security in mind, which remains harder than it should be, thanks to the government’s Cyber Trust Mark label ’s stalled development and the Matter smart- standard still being hard to shop for .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
