Attacks on Demand: Scale, Supply, and the Shrinking Cost of DDOS
DDoS Threat Intelligence Report
Issue 17: Findings from 1H 2026
- 9 Million + DDoS attacks
- Download report for exclusive insights
- Explore in-depth analysis
Download the Report
Explore DDoS attack stats, trends, and impacts.
Key Findings
Attack Volume and High-Impact Growth
Terabit IPv6 Attacks Arrive
Direct-Path and Carpet-Bombing Gained Share
The Shortest Attacks Gained Share
Residential Proxy Sources Participated in DDoS Attacks
Executive Summary
NETSCOUT ATLAS recorded more than 9.1 million DDoS attacks in the first half of 2026, but the larger story is a shift in how attacks are launched and sourced. High-impact attacks became more frequent, direct-path methods accounted for roughly two-thirds of observed attacks, and carpet-bombing continued to gain share. DDoS-for-hire services made attacks easier to launch, while residential proxy networks supplied source addresses that looked like ordinary subscribers. Together, these developments put more pressure on defenses to distinguish malicious traffic from legitimate demand.
That distinction matters because attacks can disrupt services without saturating a link. Connection state and application capacity can fail first, while traffic spread across many destinations can evade per-host detection thresholds. Preserving service therefore requires more than bandwidth or coarse filtering. Providers need greater dedicated scrubbing capacity at their network edges, with selective mitigation and headroom for concurrent attacks. Enterprises need on-premises protection close to the services they operate themselves. For both, cloud-delivered mitigation remains a necessary complement for distributed attacks, overflow, and events that exceed local capacity.
Download the full report to explore the latest DDoS threats with ASERT and Arbor Cloud SOC expert insights into the current attack landscape.
In-Depth Analysis
Download the Report
Explore DDoS attack stats, trends, and impacts.