# A Terabit Used to Break the Internet. Now It's Tuesday.


Eight hundred times in a single quarter, Cloudflare absorbed a network-layer DDoS attack exceeding one terabit per second. That's a fivefold surge over the same period last year. Read that again: not eight hundred attacks total — eight hundred that crossed the threshold that, less than a decade ago, was considered catastrophic enough to knock a major DNS provider offline and destabilize a significant chunk of the internet.


The infrastructure protecting the modern web is more resilient than it was in 2016. What's changed is that the attackers have caught up, and then some.


## When a Terabit Became a Floor, Not a Ceiling


Cast your mind back to October 2016. The Mirai botnet — assembled from compromised webcams, DVRs, and home routers running default credentials — launched roughly 1.1 Tbps against Dyn, a DNS provider used by Twitter, Spotify, Reddit, and dozens of other major platforms. The internet broke. News cycles ran hot for days. The security industry treated it as a watershed moment, a proof-of-concept for what an army of cheap, forgotten devices could do.


That attack would not make headlines today. It wouldn't even crack Cloudflare's top tier.


The Q2 2026 numbers tell a story not just about volume, but about normalization. When hyper-volumetric attacks happen at the rate of roughly nine per day, they stop being events and start being weather. The defenders running the big CDN networks have built infrastructure that absorbs them — often automatically, without a human ever reviewing the traffic. The implication is unsettling: for anyone not sitting behind a hyperscale network, the calculus has fundamentally shifted.


## What's Actually Driving the Volume


Three forces are converging here, and none of them are going away.


Botnet infrastructure has matured. Mirai was a blunt instrument built from consumer IoT trash. Modern botnets combine compromised cloud VMs, misconfigured servers with legitimate bandwidth, and residential proxy networks that let attackers route traffic through real ISP addresses. The result is fire hoses instead of garden hoses — and attackers can rent them by the hour from DDoS-for-hire services that look increasingly like SaaS products, complete with dashboards and tiered pricing.


Amplification techniques have proliferated. Network-layer DDoS often exploits reflection and amplification protocols — DNS, NTP, memcached, SSDP, and others that return responses far larger than the original query. Attackers spoof the victim's IP as the source and let the internet's own infrastructure do the heavy lifting. The attack traffic arriving at the target is a multiplier of what the attacker actually sent.


Geopolitical conflict has industrialized DDoS. The Russia-Ukraine war, Middle East tensions, and Southeast Asian regional disputes have all produced sustained, politically motivated DDoS campaigns against government sites, media outlets, financial institutions, and critical infrastructure. Hacktivist groups that emerged or radicalized in these contexts have refined their tooling and often share infrastructure with actors operating closer to state-sponsor territory.


## Who Actually Gets Hit


Cloudflare's data covers what Cloudflare sees — which means organizations already sophisticated enough to route their traffic through a major network protection service. The headline stat of 800+ terabit-class attacks is an artifact of what hyperscale infrastructure can detect and absorb. It says nothing about what's hitting everyone else.


The real exposure sits in three categories:


  • Mid-market enterprises that run their own origin infrastructure without scrubbing services, or with cloud-provider DDoS protection that caps out far below 1 Tbps thresholds
  • Critical infrastructure operators — water utilities, regional power grid management, hospital networks — that have improved their cybersecurity posture but often lack the bandwidth headroom to survive a modern volumetric attack
  • Gaming and streaming platforms at the second tier, which are perennially among the most targeted verticals for DDoS and often can't afford the same level of upstream mitigation as the largest players

  • The financial sector has generally done the right things here. Regulatory pressure post-2012 (when Operation Ababil campaigns targeted major U.S. banks) forced banks into serious DDoS mitigation investments early. Healthcare and operational technology environments have not historically faced the same pressure, and the exposure shows.


    ## What Defenders Should Actually Do


    If your organization is still thinking about DDoS mitigation as "buy more bandwidth," stop. Volumetric attacks have outpaced that strategy at scale.


    The practical checklist looks like this:


  • Move your DNS behind a protective resolver. Authoritative DNS is often the weakest point — take it down and everything else becomes irrelevant.
  • Map your actual blast radius. Most organizations don't know which services go dark if their upstream pipe gets saturated. Run the scenario before an attacker does.
  • Verify your mitigation SLAs, not just their existence. A scrubbing service that takes 15 minutes to activate during an attack is nearly worthless. Know your provider's actual response time guarantees and test them.
  • Prepare for multi-vector attacks. The most sophisticated campaigns pair volumetric floods with application-layer attacks designed to exhaust connection tables and backend resources simultaneously. Your volumetric defense and your application-layer WAF need to operate as a coordinated system.
  • Build runbooks for degraded operations. Assume you will get hit and that mitigation will be imperfect. Which services get prioritized? Who makes that call at 2 AM?

  • ## HackWire Analysis


    The fivefold surge in terabit-class DDoS is the wrong thing to focus on. The right signal is what it reveals about the two-tier internet that's emerging: organizations behind hyperscale protection networks operating in a different threat reality than everyone else.


    Cloudflare, Akamai, AWS Shield Advanced, and a handful of others have effectively built the only viable defense against modern volumetric attacks. That creates a dependency structure the industry should be uncomfortable with. When critical infrastructure operators, healthcare systems, and regional financial institutions can only achieve meaningful DDoS resilience by routing their traffic through a small number of commercial intermediaries, you've centralized the internet's attack surface in a new way — one that isn't visible in any single incident report.


    The geopolitical angle compounds this. State-aligned actors using DDoS as a soft-power tool — disrupting government services, silencing media during critical moments, harassing NGOs — have found that attacks in the 500 Gbps to 3 Tbps range are cheap, plausibly deniable, and effective against targets that can't afford enterprise-grade mitigation. This is the DDoS threat environment that matters for election infrastructure, civil society organizations, and municipal governments — not the headline numbers that Cloudflare's backbone absorbs without breaking a sweat.


    The industry keeps reporting on the attacks the defenders stopped. What needs more coverage is the systematic exposure of the targets that weren't behind the right infrastructure when the flood came.


    — HackWire Editorial


    ---


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)