The Internet Under Siege

Every hour of every day, the web absorbs thousands of attacks it never asked for. Cloudflare just counted them.

      

Every hour of every day, the web absorbs thousands of attacks it never asked for. Cloudflare just counted them.

The world's largest internet infrastructure company published its mid-year threat report this week. The numbers are staggering. The real story is how normal this has become.


By Aaron Rose · Tech Reader Magazine · August 11, 2026


Podcast 🎧 • Video 📽 • Short 📽


DDoS Attacks

Somewhere right now, a server is being overwhelmed with traffic it didn't ask for. Then another. Then a thousand more. Distributed Denial of Service attacks — DDoS, in the shorthand of the security world — are not a new phenomenon. But a report published this week by Cloudflare, one of the companies whose job it is to absorb them, puts a number to the scale that is worth sitting with for a moment: 5,343 network-layer attacks per hour, every hour, across the first half of 2026. That is roughly 128,000 per day. Not incidents. Not alerts. Attacks.

This is Cloudflare's 25th DDoS Threat Report, and the first to consolidate a full half-year into a single volume. The company protects more than 20 percent of the web from its network of over 330 cities worldwide. Its vantage point is, by any reasonable measure, one of the best available for understanding what the internet's threat landscape actually looks like — not in theory, but in traffic.

23.2 million
Network-layer DDoS attacks mitigated by Cloudflare in the first half of 2026 alone — alongside 29.64 trillion HTTP DDoS requests. The pace works out to more than 5,300 attacks every hour of every day.


What a DDoS Attack Actually Is

The basic idea is simple, even if the execution has grown sophisticated. An attacker directs a flood of internet traffic at a target — a website, a server, a network — with the goal of overwhelming it until it can no longer respond to legitimate requests. Think of it as jamming a phone line with so many fake calls that real ones can't get through. The "distributed" part means the flood comes from many sources at once, often thousands of compromised devices scattered across the globe, making it difficult to simply block a single origin.

The targets are everywhere: media companies, financial institutions, government agencies, gaming platforms, hospitals. Any internet-connected property is a potential target, and the barriers to launching an attack have dropped considerably as tools for doing so have become widely available for hire.


The 1 Terabit Club

The headline finding in Cloudflare's report is the explosive growth of what security researchers call hyper-volumetric attacks — those exceeding one terabit per second of traffic, one billion packets per second, or one million requests per second. These are not typical attacks. They are among the largest ever recorded, capable of stressing even major internet infrastructure.

In the second quarter of 2026 alone, Cloudflare mitigated 805 such attacks. That is a more than six-fold increase over the first quarter. Across the full first half of the year, the total reached 935. The terabit-scale attack, once a rare and newsworthy event, is now a routine entry in a quarterly report.

The terabit-scale attack, once a rare and newsworthy event, is now a routine entry in a quarterly report.


Short, Small — and Still Dangerous

Here is the counterintuitive part. Despite the hyper-volumetric surge at the top end, the vast majority of attacks Cloudflare sees are neither large nor long. More than 96 percent of network-layer attacks stayed under 500 megabits per second. More than 90 percent ended in under ten minutes. The report documents attacks that lasted as few as 35 seconds from start to finish.

That brevity is not a sign of weakness. It is part of the design. By the time a security analyst receives an alert, reviews it, and moves to respond manually, an attack measured in seconds has already done its work. The cascading effects — routing instability, application timeouts, downstream service degradation — can linger for hours or days after the traffic itself has stopped. The lesson the report draws is direct: automated, always-on protection is not a convenience. It is a requirement.

And "small" is relative. A 100 megabit-per-second attack is enough to bring down an unprotected web server. A 100 gigabit attack can knock most unprotected data centers offline. The floor of what is considered routine in this threat landscape would have been extraordinary a decade ago.


When World Events Show Up in the Data

One of the more striking aspects of Cloudflare's report is how clearly geopolitical events register in the traffic. DDoS attacks do not happen in a vacuum — they follow the news cycle, or more precisely, they follow the attention and the anger that the news cycle generates.

The Media, Production and Publishing industry was the most attacked sector in both quarters, absorbing nearly 14 percent of all mitigated HTTP DDoS requests — almost four times the volume of the next closest sector. The report ties this directly to sustained global coverage of ongoing conflicts and the World Cup, drawing hacktivist attention to outlets and platforms associated with that coverage.

The Government sector told a sharper story. It entered 2026 ranked 29th among attacked industries. By the second quarter, it had jumped to ninth — one of the largest single-sector moves the report has ever recorded — following a wave of hacktivist activity tied to geopolitical events in the Middle East. Nearly half of all organizations targeted in that wave were government entities.


The Quiet Good News

April 2026 was the peak month for attack volume in the first half of the year. After that, activity declined. The report points to one likely reason: Operation PowerOFF, a coordinated action involving 21 countries that targeted the infrastructure behind DDoS-for-hire services. The operation took down 53 domains, issued 25 search warrants, and reached over 75,000 users of those platforms — the people who pay to have attacks launched on their behalf.

Law enforcement actions of this kind are slow and imperfect. Takedowns are followed, often quickly, by reconstitution under new names and domains. But the April peak followed by a meaningful decline suggests that disrupting the supply chain of attackers — not just absorbing the attacks themselves — does move the needle, at least temporarily.

On the infrastructure side, Cloudflare operates a free Botnet Threat Feed for internet service providers, sharing real-time data on attack sources so that ISPs can identify and remove compromised devices from their networks. More than 800 networks worldwide have signed up. The speed at which private-sector infrastructure can share threat data with one another continues to outpace the speed at which any regulatory or law enforcement mechanism can respond. That gap is not a criticism — it is simply the nature of a threat that moves at network speed.


A Reminder

The internet absorbs an enormous amount of punishment, continuously and largely invisibly. Cloudflare's report is a reminder that the stability most users experience — pages that load, services that respond, platforms that stay online — is not accidental. It is the product of infrastructure designed specifically to absorb what is, by any historical measure, a remarkable and sustained volume of hostile traffic. The attacks are routine. So, increasingly, is the defense.


Going Deeper on the DDoS Report

The vectors behind the surge, the geopolitics driving the targeting, and the specific attack types that security teams are watching most closely in the second half of 2026. Coming up at Tech Reader Magazine.


Copyright © 2026 Tech Reader Magazine
All Rights Reserved

Popular posts from this blog

The Paper