Attacks on Demand: Scale, Supply, and the Shrinking Cost of DDOS

DDoS Threat Intelligence Report

Issue 17: Findings from 1H 2026

  • 9 Million + DDoS attacks
  • Download report for exclusive insights
  • Explore in-depth analysis
Download Report

Download the Report

Explore DDoS attack stats, trends, and impacts.

Key Findings

1

Attack Volume and High-Impact Growth

NETSCOUT ATLAS recorded more than 9.1 million DDoS attacks across 209 countries and territories in 1H 2026. Attacks clearing 1Tbps or 1Gpps increased 1,286 percent year over year.
2

Terabit IPv6 Attacks Arrive

ATLAS observed its first IPv6 attack exceeding 1Tbps. Active mitigation of IPv6 attacks rose more than 300 percent year over year, while IPv6's share of observed attacks held roughly flat.
3

Direct-Path and Carpet-Bombing Gained Share

Direct-path methods accounted for 64.40 percent of observed attacks in 1H 2026 and gained share for a third consecutive half-year. Separately, carpet-bombing rose from 3.97 percent of attacks in 1H 2025 to 4.54 percent in 1H 2026.
4

The Shortest Attacks Gained Share

Attacks lasting one minute or less increased from 1.6 percent of observed attacks in 2H 2023 to 3.1 percent in 1H 2026.
5

Residential Proxy Sources Participated in DDoS Attacks

ASERT paired residential proxy network tracking with DDoS telemetry to identify proxy sources participating in attacks.

Executive Summary

NETSCOUT ATLAS recorded more than 9.1 million DDoS attacks in the first half of 2026, but the larger story is a shift in how attacks are launched and sourced. High-impact attacks became more frequent, direct-path methods accounted for roughly two-thirds of observed attacks, and carpet-bombing continued to gain share. DDoS-for-hire services made attacks easier to launch, while residential proxy networks supplied source addresses that looked like ordinary subscribers. Together, these developments put more pressure on defenses to distinguish malicious traffic from legitimate demand.

That distinction matters because attacks can disrupt services without saturating a link. Connection state and application capacity can fail first, while traffic spread across many destinations can evade per-host detection thresholds. Preserving service therefore requires more than bandwidth or coarse filtering. Providers need greater dedicated scrubbing capacity at their network edges, with selective mitigation and headroom for concurrent attacks. Enterprises need on-premises protection close to the services they operate themselves. For both, cloud-delivered mitigation remains a necessary complement for distributed attacks, overflow, and events that exceed local capacity.

Download the full report to explore the latest DDoS threats with ASERT and Arbor Cloud SOC expert insights into the current attack landscape.

In-Depth Analysis

Download the full report for exclusive insights Download Report

Download the Report

Explore DDoS attack stats, trends, and impacts.