DDoS in the terabit era — the threat landscape in numbers
With our threat analysis 2026 we present our own assessment of the global security landscape. The data basis is the published research of Cloudflare — the network that carries a substantial share of the world's internet traffic and on which our managed services are built. Here we summarise the key numbers and findings on DDoS in the terabit era, bots, APIs and DNS — with a focus on what they mean for your organisation's resilience.
How much has the DDoS threat really grown?
Cloudflare mitigated 47.1 million DDoS attacks in 2025 — up 121 percent on 2024 and more than three times the 2023 figure. The first half of 2026 shows this has become the steady state: another 23.2 million mitigated attacks, roughly 128,000 per day on average. Mitigated HTTP DDoS requests alone added up to 29.64 trillion in the half-year. Anyone still treating DDoS as a rare exception in their risk planning is working from an outdated picture.
Why are 35 seconds the new nightmare scenario?
The largest attack ever measured reached 31.4 terabits per second in December 2025 — and was over after 35 seconds. That is not an outlier but a tactic: 90.6 percent of all attacks last less than ten minutes. At the same time the extremes are becoming a series: terabit-scale attacks jumped from 130 in the first quarter of 2026 to 805 in the second — a sixfold increase. The Christmas campaign of the Aisuru/Kimwolf botnet — at times one to four million compromised devices, mostly Android TV boxes — delivered 902 hypervolumetric attacks in just 13 days.
The consequence is uncomfortable but clear: when attacks are over in seconds, human reaction stands no chance. On-demand rerouting, manually activated scrubbing centres and phone-based escalation chains are structurally too late. What is needed is an always-on architecture that detects and mitigates attacks autonomously at the network edge — in seconds, with no one having to intervene. And for the acute case: our DDoS emergency response at stop-ddos.team is available around the clock.
Why does the most dangerous traffic often stay invisible?
In parallel with the volume escalation, the quiet attack is becoming professionalised. 31.2 percent of all application traffic comes from bots — 93 percent of it unverified and thus potentially malicious. The typical application-layer attack respects protocols, stays below rate limits and looks like pleasing growth in the logs. Its effect only shows up in the numbers: rising infrastructure costs, falling conversion, distorted analytics. On top of that comes a new category: AI crawlers already account for 20 percent of verified bot traffic, and agentic AI traffic grew by 1,500 percent within a year.
The picture is even starker for interfaces: APIs carry 60 percent of dynamic HTTP traffic, yet machine-led discovery finds on average 33 percent more active endpoints than the organisation itself has documented — shadow APIs that nobody protects because nobody knows them. And the window is shrinking towards zero: in the documented extreme case, only 22 minutes passed between the publication of an exploit proof-of-concept and the first observed attack attempt. No patch process is that fast — the practical way out is virtual patching at the network edge, as we run it in our managed application security service.
Why is DNS the underestimated attack vector?
DNS floods were the single most common vector in the second quarter of 2026, accounting for 40 percent of all network-layer attacks: if name resolution fails, every service above it becomes unreachable — no matter how well protected it is itself. At the same time, the integrity of name resolution remains patchy: around 80 percent of all DNS queries concern domains without a DNSSEC signature, even though Germany's BSI has recommended signing for years. On modern DNS platforms, DNSSEC is one click; the real work is the decision to prioritise it.
5 tips: how to protect yourself against current DDoS attacks
The numbers show where DDoS attacks are currently heading: shorter, larger, more targeted. Five measures follow from that which make the difference in practice — ordered by impact.
1. Always-on protection instead of switching over in an emergency
When a record attack is over after 35 seconds, every model that only switches to mitigation during the incident loses. What works is permanent protection — such as Cloudflare DDoS mitigation via a global anycast network — that absorbs volumetric attacks at the edge before they reach your connectivity — as managed application security including operations and tuning.
2. Shrink the attack surface: hide the origin, close services
What attackers cannot reach directly, they cannot flood: origin servers belong exclusively behind the protection network (no directly routed IP in old DNS records), unused ports and services get closed, open resolvers and amplification-prone services such as NTP or memcached get hardened — otherwise your own infrastructure becomes part of other people's reflection attacks.
3. Protect layer 7 and APIs too — not just bandwidth
The most dangerous traffic is often the quiet kind: HTTP floods that look like real users, and targeted API attacks. WAF/WAAP, bot management and rate limiting with clean baselines per endpoint help against this — bandwidth protection alone leaves exactly this layer open.
4. Treat DNS as a protection target of its own
When 40 percent of network-layer attacks target DNS, name resolution is no side stage: put authoritative DNS on a DDoS-protected anycast network, keep zones redundant, set caching and TTLs deliberately — if DNS falls, even the best web defence is invisible.
5. Rehearse the runbook, sharpen detection, name owners
Technology without a rehearsed procedure stays theory: baselines and alerting, a runbook with clear responsibilities (who activates what, who communicates with whom), emergency contacts at provider and protection vendor — and at least one live drill per year. If you don't want to staff this internally, bring in operations as a managed service.
What does DDoS mean — and how does it differ from DoS?
DDoS stands for distributed denial of service: a service is overloaded with mass requests or traffic until it fails for legitimate users. The difference to plain DoS lies in the “distributed” — the attack does not come from a single source but from thousands of systems (usually a botnet), which makes filtering and tracing considerably harder.
Where can you see current DDoS attacks in real time?
A live view of current DDoS attacks and attack waves is offered by Cloudflare Radar — including trends by country, industry and attack type. Such maps show the situation, but they do not replace your own defence: what counts is what your architecture intercepts automatically within seconds.
What decision-makers should check now
Germany was among the three most attacked countries worldwide in the fourth quarter of 2025, and with the NIS2 obligations at the latest, availability is a leadership topic. Three review questions from the analysis for your next risk board:
- Does DDoS appear as a distinct scenario in your business continuity plan — including a communication plan for customers, partners and regulators?
- Is your protection always-on, with a rehearsed runbook — or does your operation still rely on manual rerouting in an emergency?
- Do you rehearse the emergency under realistic conditions, with management and business units at the table rather than only in the NOC?
The most important observation of the analysis: whether an organisation survives an attack unscathed is decided long before the attack — in the architecture and in the responsibilities. The full threat analysis with all sources will be published shortly. If you want to check your own environment against these patterns: as a Cloudflare partner we run DDoS protection, WAAP and DNS security as a managed service — the entry point is a no-obligation first conversation with a look at your real traffic.