Published 2026-09-29 · Updated 2026-09-29
Cloudflare's H1 2026 DDoS Report: What a 31.4 Tbps Record Means for a Small Business Server
Cloudflare mitigated a record 31.4 Tbps DDoS attack in December 2025, attributed to the Aisuru/Kimwolf botnet, and its H1 2026 DDoS Threat Report shows the scale of the largest attacks continuing to climb through the first half of the year. Headlines built around numbers like that are easy to write and easy to misread. The report itself, read past the record, tells a more useful and more specific story about what a small business running a Linux VPS is actually up against, and it is a smaller, shorter, more mundane threat than the record-setting numbers suggest.
In this article
The headline number, and why it is not the story What actually changed in H1 2026 The three attack categories, revisited What the median attack really looks like Why short and small still matters What this means operationally Frequently asked questionsQuick win (10 minutes)
- Confirm your site sits behind a CDN or reverse proxy rather than exposing the origin server's IP directly.
- Check current connection limits on your web server:
nginx -T | grep limit_reqif you run nginx. - Confirm your firewall has a sensible connection-rate limit on public-facing ports, not just an allow list.
- Check whether fail2ban or an equivalent is watching for repeated connection floods, not just failed logins.
- If you have never actually tested what your server does under a traffic spike, treat that as the real gap, not the size of the largest attack in the news.
The headline number, and why it is not the story
According to Cloudflare's own H1 2026 DDoS Threat Report, the company mitigated a record-breaking 31.4 Tbps attack in December 2025, attributed to the Aisuru/Kimwolf botnet, and recorded 935 individual attacks exceeding 1 Tbps during the first half of 2026 alone, 805 of which landed in the second quarter. Numbers at that scale are aimed at large, high-value targets with the network capacity to even register a terabit-scale flood as a meaningful event; a small business VPS on a shared hosting network or a modest cloud instance would be overwhelmed by a small fraction of that traffic, which is precisely why attackers do not spend botnet capacity at that scale against small targets. The record matters for understanding botnet capability and internet-scale infrastructure risk. It is a poor guide to what an individual small business server needs to defend against.
What actually changed in H1 2026
Cloudflare's report puts real numbers behind the trend: 23.2 million network-layer DDoS attacks mitigated in the first half of 2026, alongside 29.64 trillion HTTP requests associated with DDoS activity, an average of roughly 128,000 attacks per day across Cloudflare's network. April 2026 was the single most intense month, hitting 6.46 trillion requests and 165 petabytes of DDoS-related traffic. Independent DDoS intelligence, including analysis published by Positive Technologies, describes the same period as marked by a return of amplification-based attacks alongside the record volumes, meaning attackers are combining raw scale with older, resource-efficient techniques rather than abandoning them.
The three attack categories, revisited
Volumetric attacks saturate a network's bandwidth with raw traffic volume, which is the category behind the headline terabit-scale numbers. Protocol attacks exhaust connection-handling resources on firewalls, load balancers and the server's own connection tables rather than raw bandwidth, using techniques like TCP SYN floods. Application-layer attacks target the web application itself with requests that look legitimate, making them the hardest category to filter automatically and the one most likely to actually reach a small business's origin server rather than being absorbed upstream. Our full DDoS protection guide for small businesses covers realistic, budget-appropriate mitigation for each category in detail.
What the median attack really looks like
The single most useful figure in Cloudflare's H1 2026 report for a small business is not the 31.4 Tbps record. It is this: 96.62% of network-layer DDoS attacks Cloudflare mitigated in the period stayed under 500 Mbps, and 90.60% ended in under 10 minutes. The typical attack Cloudflare's own infrastructure actually processes is short and comparatively small, sitting alongside a small number of extreme outliers that generate the headlines. A small business server does not need to survive a terabit flood; it needs to survive the kind of short, modest-volume burst that makes up the overwhelming majority of real-world DDoS activity.
Want to see this handled in real time?
Open the Security Lab and watch protected versus unprotected servers respond to the same simulated traffic pattern side by side.
Open the Security Lab Get your free server checkWhy short and small still matters
A VPS with a 1 Gbps port and a database that starts struggling past a few hundred concurrent connections does not need a multi-terabit flood to go offline. A few hundred Mbps of junk traffic, or a few thousand malicious requests per second aimed at a slow endpoint like a login page or search function, is enough to take down infrastructure sized for a small or mid-sized business's normal traffic. The realistic scenarios small businesses actually encounter tend to be a botnet scanning broad IP ranges that happens to include theirs, a competitor or disgruntled party paying for a cheap booter service, scrapers or credential-stuffing tools disguised as high-volume normal traffic, or collateral damage from an attack aimed at another site on shared infrastructure.
What this means operationally
For most small business websites, a CDN or reverse proxy in front of the origin server absorbs the large majority of volumetric and protocol-layer traffic realistically encountered, since that traffic is filtered before it ever reaches the origin. What a CDN typically does not include is application-specific tuning: rate limiting on a login form, a search box, or an API endpoint that is expensive to compute per request, which is exactly the category most likely to slip through a general-purpose network defense. Fail2ban does not stop network-layer volumetric floods, since those overwhelm a connection before requests reach an application log, but it is effective against the application-layer abuse pattern that a CDN alone typically will not catch, banning IPs based on repeated patterns in logs it can actually see.
The practical takeaway from a report full of record-breaking numbers is almost the opposite of what the headline implies: the growth in extreme, terabit-scale attacks is real and worth tracking as an internet-infrastructure trend, but it does not change what a small business server needs to defend against day to day. That defense still comes down to a CDN or proxy for the bulk of volumetric and protocol traffic, rate limiting and monitoring at the application layer for what gets through, and a realistic understanding that the median attack, not the record one, is the one your own infrastructure will actually face.
Frequently asked questions
What was the largest DDoS attack Cloudflare has mitigated?
Cloudflare mitigated a record 31.4 Tbps DDoS attack in December 2025, attributed to the Aisuru/Kimwolf botnet. It remains the largest publicly disclosed attack Cloudflare has reported handling.
How many DDoS attacks did Cloudflare mitigate in H1 2026?
Cloudflare mitigated 23.2 million network-layer DDoS attacks and processed 29.64 trillion HTTP requests associated with DDoS activity in the first half of 2026, an average of roughly 128,000 attacks per day.
Does a record-breaking terabit-scale attack mean small servers are at higher risk?
Not directly. Cloudflare's own H1 2026 data shows 96.62% of network-layer attacks stayed under 500 Mbps and 90.60% ended within 10 minutes. The record-scale attacks are real and growing, but they target large, high-value infrastructure, not the realistic threat profile a small business server faces.
What size of DDoS attack can actually take down a small business server?
A VPS with a 1 Gbps uplink and a database that struggles past a few hundred concurrent connections does not need anywhere close to a terabit-scale flood to go offline. A few hundred Mbps of junk traffic, or a few thousand malicious requests per second aimed at a slow endpoint, is enough for most small business infrastructure.
What are the three categories of DDoS attack Cloudflare tracks?
Volumetric attacks saturate network bandwidth with raw traffic volume. Protocol attacks exhaust connection-handling resources on firewalls and load balancers. Application-layer attacks target the web application itself with requests that look legitimate. Each exhausts a different resource and needs a different defense.
Is a CDN or proxy enough DDoS protection for a small business?
For most small business sites, a CDN or proxy in front of the origin server handles the large majority of volumetric and protocol-layer DDoS traffic realistically encountered. It typically does not include application-specific tuning, so rate limiting and monitoring at the server level remain necessary on top of it.
Not sure where your server stands?
Get a free, read-only security check, or talk to a security engineer about managed protection.
Get your free server check Talk to a security engineer