# A Terabit Used to Break the Internet. Now It's Tuesday.
Eight hundred times in a single quarter, Cloudflare absorbed a network-layer DDoS attack exceeding one terabit per second. That's a fivefold surge over the same period last year. Read that again: not eight hundred attacks total — eight hundred that crossed the threshold that, less than a decade ago, was considered catastrophic enough to knock a major DNS provider offline and destabilize a significant chunk of the internet.
The infrastructure protecting the modern web is more resilient than it was in 2016. What's changed is that the attackers have caught up, and then some.
## When a Terabit Became a Floor, Not a Ceiling
Cast your mind back to October 2016. The Mirai botnet — assembled from compromised webcams, DVRs, and home routers running default credentials — launched roughly 1.1 Tbps against Dyn, a DNS provider used by Twitter, Spotify, Reddit, and dozens of other major platforms. The internet broke. News cycles ran hot for days. The security industry treated it as a watershed moment, a proof-of-concept for what an army of cheap, forgotten devices could do.
That attack would not make headlines today. It wouldn't even crack Cloudflare's top tier.
The Q2 2026 numbers tell a story not just about volume, but about normalization. When hyper-volumetric attacks happen at the rate of roughly nine per day, they stop being events and start being weather. The defenders running the big CDN networks have built infrastructure that absorbs them — often automatically, without a human ever reviewing the traffic. The implication is unsettling: for anyone not sitting behind a hyperscale network, the calculus has fundamentally shifted.
## What's Actually Driving the Volume
Three forces are converging here, and none of them are going away.
Botnet infrastructure has matured. Mirai was a blunt instrument built from consumer IoT trash. Modern botnets combine compromised cloud VMs, misconfigured servers with legitimate bandwidth, and residential proxy networks that let attackers route traffic through real ISP addresses. The result is fire hoses instead of garden hoses — and attackers can rent them by the hour from DDoS-for-hire services that look increasingly like SaaS products, complete with dashboards and tiered pricing.
Amplification techniques have proliferated. Network-layer DDoS often exploits reflection and amplification protocols — DNS, NTP, memcached, SSDP, and others that return responses far larger than the original query. Attackers spoof the victim's IP as the source and let the internet's own infrastructure do the heavy lifting. The attack traffic arriving at the target is a multiplier of what the attacker actually sent.
Geopolitical conflict has industrialized DDoS. The Russia-Ukraine war, Middle East tensions, and Southeast Asian regional disputes have all produced sustained, politically motivated DDoS campaigns against government sites, media outlets, financial institutions, and critical infrastructure. Hacktivist groups that emerged or radicalized in these contexts have refined their tooling and often share infrastructure with actors operating closer to state-sponsor territory.
## Who Actually Gets Hit
Cloudflare's data covers what Cloudflare sees — which means organizations already sophisticated enough to route their traffic through a major network protection service. The headline stat of 800+ terabit-class attacks is an artifact of what hyperscale infrastructure can detect and absorb. It says nothing about what's hitting everyone else.
The real exposure sits in three categories:
The financial sector has generally done the right things here. Regulatory pressure post-2012 (when Operation Ababil campaigns targeted major U.S. banks) forced banks into serious DDoS mitigation investments early. Healthcare and operational technology environments have not historically faced the same pressure, and the exposure shows.
## What Defenders Should Actually Do
If your organization is still thinking about DDoS mitigation as "buy more bandwidth," stop. Volumetric attacks have outpaced that strategy at scale.
The practical checklist looks like this:
## HackWire Analysis
The fivefold surge in terabit-class DDoS is the wrong thing to focus on. The right signal is what it reveals about the two-tier internet that's emerging: organizations behind hyperscale protection networks operating in a different threat reality than everyone else.
Cloudflare, Akamai, AWS Shield Advanced, and a handful of others have effectively built the only viable defense against modern volumetric attacks. That creates a dependency structure the industry should be uncomfortable with. When critical infrastructure operators, healthcare systems, and regional financial institutions can only achieve meaningful DDoS resilience by routing their traffic through a small number of commercial intermediaries, you've centralized the internet's attack surface in a new way — one that isn't visible in any single incident report.
The geopolitical angle compounds this. State-aligned actors using DDoS as a soft-power tool — disrupting government services, silencing media during critical moments, harassing NGOs — have found that attacks in the 500 Gbps to 3 Tbps range are cheap, plausibly deniable, and effective against targets that can't afford enterprise-grade mitigation. This is the DDoS threat environment that matters for election infrastructure, civil society organizations, and municipal governments — not the headline numbers that Cloudflare's backbone absorbs without breaking a sweat.
The industry keeps reporting on the attacks the defenders stopped. What needs more coverage is the systematic exposure of the targets that weren't behind the right infrastructure when the flood came.
— HackWire Editorial
---