Cloudflare
Reports
All Statistics
DNS-based attacks accounted for 34.3% of network-layer attacks in the first half of 2026.
CLDAP Floods surged 580% quarter-over-quarter and became the #3 attack vector in Q2 2026.
April 2026 peaked at 6.46 trillion HTTP DDoS requests and 165 petabytes of volume.
59% of human traffic is clean from leaked credentials against 41% with leaked passwords.
Of the successful leaked password login attempts on WordPress sites, 48% are bot-driven. The remaining 52% of successful logins on WordPress sites originate from legitimate, non-bot users.
Only 5% of leaked password login attempts result in access being denied. 90% of these denied requests are bot-driven. The remaining 19% of login attempts fall under other outcomes, such as timeouts or users who changed their passwords
96.62% of network-layer DDoS attacks remained under 500 Mbps in the first half of 2026.
90.60% of network-layer DDoS attacks ended in under 10 minutes in the first half of 2026.
China absorbed 22.4% of all HTTP DDoS requests globally in Q2 2026, while the United States accounted for 18.8%.
Turkey more than doubled its share of global DDoS attack traffic to climb into the #3 most-attacked position by Q2 2026.
Brazil was the top DDoS source country in H1 2026 at 14.9%, overtaking the United States at 13.4%, and Brazil accounted for 21.4% of mitigated DDoS request traffic in Q2.
DNS Floods increased from 25.7% to 40.0% of network-layer attacks quarter-over-quarter.
When including bot-driven traffic, 52% of all detected authentication requests contain leaked passwords.
95% of login attempts involving leaked passwords are coming from bots.
Based on Cloudflare's observed traffic between September - November 2024, 41% of successful logins across websites protected by Cloudflare involve compromised passwords.
76% of leaked password login attempts for websites built on WordPress are successful.
Approximately 41% of successful human authentication attempts involve leaked credentials.