H1 2026 DDoS observations: prepare for scale and short bursts
Interpret Cloudflare’s half-year report without confusing observed attack sizes with product guarantees.
Contents of this article
A combined half-year report
Cloudflare’s August 11, 2026 report combines Q1 and Q2 and reports 935 network-layer attacks exceeding 1 Tbps mitigated on its network. This is a provider observation, not an Internet-wide census or a WAFPRO capacity claim.
Look beyond the record peak
The report also highlights short attack durations. Brief failures can produce retries and queued work. Align bandwidth, packet rate, duration and successful transactions to distinguish attack pressure from recovery load.
Prepare a plan for each entry point
Inventory web, API, game, DNS and management entry points. Confirm mitigation and escalation paths, and rehearse manual transitions. One headline capacity figure does not establish equivalent protection across protocols or directions.
Validate through completed operations
Use authorized tests to verify logins, callbacks and reconnections, and check bypass paths to the origin. Compare legitimate bandwidth, geography, protocols and recovery requirements alongside mitigation capacity.
References
Cloudflare H1 2026 DDoS report
