DDoS Attacks Over 1 Tbps Surge Fivefold in Q2, Threatening Service Availability
What Happened — Cloudflare reported mitigating more than 800 network‑layer DDoS attacks that exceeded 1 Tbps in Q2 2026, a five‑fold increase versus Q1. The largest single attack peaked at 31.4 Tbps and 200 M requests per second, launched by the Aisuru/Kimwolf botnet.
Why It Matters for Compliance & Audit Readiness
- The spike tests the Availability trust principle of SOC 2; organizations must demonstrate resilient infrastructure and documented DDoS‑mitigation controls.
- Continuous evidence of traffic‑scrubbing, rate‑limiting, and incident‑response actions is essential to satisfy auditors and to provide a defensible audit trail.
- Mapping these controls to a centralized Trust Center gives stakeholders verifiable proof of ongoing protection.
Who Is Affected — Cloud‑service providers, SaaS platforms, e‑commerce sites, financial services, and any organization that relies on public‑facing web assets.
Recommended Actions
- Review and map your DDoS‑mitigation controls (e.g., traffic‑scrubbing services, CDN rate limits) to SOC 2 Availability criteria.
- Implement continuous monitoring and automated evidence collection for attack‑mitigation events.
- Document incident‑response playbooks and retain logs in a trusted repository for audit review.
Source: BleepingComputer
Technical Notes
- Attack vector: botnet‑driven network‑layer floods (DNS reflection, CLDAP, UDP amplification).
- Peak volume: 31.4 Tbps, 200 M requests/sec; overall Q2 traffic: 23.2 M attacks, 29.64 T HTTP requests.
- Shift toward DNS‑related and amplification techniques; CLDAP floods up 881.9 % QoQ.