Q2 2026 DDoS, bad bots, and BGP incidents: statistics and overview

20 July 2026

Executive summary

  • The largest DDoS botnet observed during Q2 2026 consisted of 2.09 million devices. While still substantial, this is significantly lower than the record 13.5 million devices observed in the previous quarter. One possible reason for this sharp decline was the law enforcement operation carried out by authorities in the United States, Canada, and Germany, which disrupted the infrastructure used by several major botnets.
  • The two most intensive DDoS attacks recorded during Q2 2026 targeted organizations in the Betting segment. Their peak bitrates reached 1.64 Tbps and 1.58 Tbps, while packet rates peaked at 553 Mpps and 638 Mpps, respectively.
  • The upward trend in the number of DDoS attacks exceeding 1 Tbps continues. During Q2 2026 alone, we mitigated 12 such incidents — twice as many as throughout 2025.
  • The share of multi-vector DDoS attacks increased to 11.7% in Q2 2026, up from 8.0% in 2025 and 10.7% in Q1 2026. At the same time, the share of attacks combining L3-L4 and L7 vectors returned to the previous year’s level, accounting for 3.6% of all incidents.
  • The largest share of DDoS attacks during Q2 2026 targeted the FinTech (31.9%), Information and communication technology (16.8%), and Media (14.0%) segments. Together, these three segments accounted for approximately two-thirds of all DDoS attacks we recorded.
  • The microsegments most frequently targeted by DDoS attacks during Q2 2026 were Media, TV, radio, and bloggers (12.7%), Payment systems (10.0%), Banks (9.5%), Betting shops (9.0%), and Trading platforms (7.9%).
  • In Q2 2026, the largest sources of L7 DDoS attacks were the United States (15.9%), Vietnam (9.5%), and Russia (7.2%). Brazil, the leader in the previous quarter, dropped to fourth place with 6.2%.
  • The geographic distribution of L7 DDoS attack sources remains more balanced than last year: the combined share of the top five countries was almost unchanged compared to Q1 (42.0% → 41.9%).
  • The average monthly number of blocked bad bot requests declined by 27.8% compared to the record-breaking first quarter, totaling 1.8 billion in Q2 2026.
  • The overall bot index declined to 1.56% in Q2 2026. The highest values were recorded in the EdTech (16.92%), Transport&Logistics (7.70%), and Betting (3.83%) segments.
  • The most intensive bad bot attack recorded during Q2 2026 targeted an organization in the Media segment. At its peak, it reached 180,000 malicious requests per second.
  • During Q2 2026, the number of unique ASes responsible for route leaks remained at the same level as in the corresponding period of last year. Meanwhile, the number of ASes involved in BGP hijacking declined by 34% compared to Q2 2025.
  • As for global BGP incidents, we recorded seven route leaks and no BGP hijacking incidents during Q2 2026.

Prevalent DDoS attack vectors in Q2 2026

Starting from Q2 2025, we changed our methodology for analyzing DDoS attacks. Previously, we considered network- and transport-layer attacks (L3-L4 DDoS) and application-layer attacks (L7 DDoS) separately. We now use a unified approach based on incidents, which may consist of multiple attacks across different vectors.

We filter out L3-L4 DDoS attacks with an intensity below 1 Gbps, considering them background noise. For L7 DDoS attacks, we also apply threshold criteria: at least 100 blocked IP addresses and a rate of at least 1,000 requests per second. Multiple attack waves are grouped into a single incident if the time gap between them does not exceed one hour.

As in previous quarters, HTTP flood — application-layer (L7) attacks — remained the most common DDoS attack vector in Q2 2026, accounting for 46.8% of all attacks we recorded. This was slightly below both the 2025 level (56.4%) and the previous quarter (54.1%). UDP flood ranked second, with its share increasing significantly compared to 2025 (22.9% → 29.3%).

The share of TCP flood attacks more than doubled compared to 2025 (4.2% → 8.9%), while SYN flood attacks saw a similar increase (2.8% → 5.6%). By contrast, the share of IP flood attacks continued to decline (13.8% → 5.2%). We also observed an unexpected surge in ICMP flood attacks: they accounted for 4.3% of all attacks in Q2 2026, compared to just 0.1% in 2025.

The share of multi-vector attacks continued to grow in Q2 2026, reaching 11.7% of all recorded incidents. At the same time, the share of multi-vector attacks combining L3-L4 and L7 vectors returned to the previous year’s level, declining from 6.2% of all incidents in Q1 2026 to 3.6% in Q2.

Distribution of DDoS attacks by industry in Q2 2026

The largest share of DDoS attacks during Q2 2026 targeted organizations in the FinTech (31.9%), Information and communication technology (16.8%), and Media (14.0%) segments. Together, these segments accounted for approximately two-thirds of all recorded incidents.

They were followed by the E-commerce (12.0%) and Betting (9.0%) segments. We expect activity in the latter to peak next quarter, as the most significant stage of the FIFA World Cup is taking place in July.

At a more granular level, the microsegments most frequently targeted by DDoS attacks during Q2 2026 were Media, TV, radio, and bloggers (12.7%), Payment systems (10.0%), Banks (9.5%), Betting shops (9.0%), and Trading platforms (7.9%). Together, these five microsegments accounted for nearly half (49.1%) of all recorded incidents.

Duration of DDoS attacks in Q2 2026

The longest DDoS attacks recorded during Q2 2026 targeted the Online retail (79.9 hours), Banks (24.4 hours), Gambling (18.3 hours), Betting shops (12.5 hours), and Systems integrators (12.4 hours) microsegments. The maximum attack duration was more than four times greater than in the previous quarter (19.0 hours), although it still fell well short of the 2025 record (119.2 hours).

The average attack duration decreased slightly in Q2 2026 compared to the previous quarter, from 3,221 to 2,764 seconds. At the same time, the median attack duration increased slightly, from 120 to 150 seconds.

Intensity of L3-L4 DDoS attacks in Q2 2026

The two most intensive DDoS attacks recorded during Q2 2026 targeted organizations in the Betting segment. Their peak bitrates reached 1.64 Tbps and 1.58 Tbps, while packet rates peaked at 553 Mpps and 638 Mpps, respectively. By both metrics, these were the largest DDoS incidents of the quarter.

The larger of the two attacks consisted of three distinct waves, with a combined period of peak activity lasting approximately 20 minutes.

The most intensive attack of Q2 2026

Although the highest bitrates recorded in Q2 2026 were somewhat lower than the peaks observed in Q1 2026 (2.07 Tbps) and in 2025 (3.51 Tbps), the overall trend remains unchanged — DDoS attacks exceeding 1 Tbps have become commonplace. During Q2 alone, we mitigated 12 such incidents, twice as many as throughout 2025.

The five microsegments targeted by the most intensive L3-L4 DDoS attacks in terms of bitrate during Q2 2026 were Betting shops (1,641 Gbps), Marketplaces (1,509 Gbps), Hosting platforms (1,353 Gbps), Game developers (1,172 Gbps), and Payment systems (951 Gbps).

In terms of peak packet rate, the top five microsegments were Betting shops (638.6 Mpps), Game developers (134.1 Mpps), Marketplaces (132.1 Mpps), Hosting platforms (118.4 Mpps), and Banks (114.1 Mpps).

The largest DDoS botnet of Q2 2026

During Q2 2026, the largest botnet we observed while mitigating L7 DDoS attacks decreased in size for the first time in two years, falling from 13.5 million devices in the previous quarter to 2.09 million devices in Q2. One possible reason for this sharp decline was the law enforcement operation carried out by authorities in the United States, Canada, and Germany, which disrupted the infrastructure used by major botnets, including Aisiru and Kimwolf. As the operation took place at the very end of Q1 2026, its impact became most apparent during the second quarter.

The botnet consisted primarily of devices located in Brazil (18.5%), the United States (10.9%), the United Kingdom (5.1%), Saudi Arabia (3.9%), and Argentina (3.1%). Unlike the size of the botnet, the country distribution has changed little since the previous quarter.

Despite the successful law enforcement operation, the fundamental conditions that enable such massive botnets to emerge have not changed. The number of potentially vulnerable devices worldwide continues to grow, while the process of finding and compromising them has become much simpler and faster in recent years with the emergence of new AI-based automation tools used by attackers.

For this reason, we do not expect a long-term shift in the situation. Over time, the largest botnets are likely to start growing again, as their operators will be able to rebuild infrastructure quickly and compensate for the losses incurred.

Geographic distribution of L7 DDoS attack sources in Q2 2026

The law enforcement operation carried out by authorities in the United States, Canada, and Germany, discussed in the previous section, appears to have affected not only the size of the largest botnet but also the overall geographic distribution of L7 DDoS attack sources during Q2 2026. The United States ranked first with 15.9%, followed by Vietnam (9.5%) and Russia (7.2%). Brazil, which had led the ranking for several consecutive quarters, saw its share decline sharply to 6.2%, dropping to fourth place. The Netherlands climbed to fifth with 3.1% after ranking outside the top ten in the previous quarter.

Overall, the Q2 2026 distribution of L7 DDoS attack sources continues to reflect the trend toward greater geographic diversification of the infrastructure used by attack operators. Despite the reshuffling within the top five, their combined share remained virtually unchanged (42.0% → 41.9%), while the share of all other countries outside the top 20 continued to grow (29.0% → 29.8%). As we have noted in previous reports, this diversification reduces the effectiveness of simple geographic blocking as a mitigation measure against large-scale DDoS attacks.

Bad bot protection statistics in Q2 2026 — Qrator.AntiBot

“Bad bots” refer to automated systems that attempt to interact with websites while impersonating real users. Their typical objectives include data scraping, metric manipulation, credential stuffing, and other forms of unwanted activity. However, unlike destructive DDoS bots, bad bots usually do not aim to disrupt website availability.

During Q2 2026, the average monthly number of blocked bad bot requests declined noticeably compared to previous quarters, totaling approximately 1.8 billion.

This is roughly in line with the levels observed in 2024. It should be noted that 2025 saw two distinct seasonal spikes in bad bot traffic during the second and fourth quarters. These spikes were driven by two particularly large-scale attacks, each lasting for about a month. We have not observed bad bot attacks of comparable duration in 2026 so far. As a result, bad bot traffic has been distributed more evenly across the protected resources.

During Q2 2026, the largest share of bad bot attacks was once again directed at the E-commerce segment, accounting for 43.67% of all bad bot activity. Unsurprisingly, the Betting segment ranked second with 17.20%, followed by the Media segment at 16.04%.

Across all protected resources, the share of bad bot traffic in total traffic — referred to here as the “bot index” — averaged 1.56% in Q2 2026. The highest bot index values were recorded in the EdTech (16.92%), Transport&Logistics (7.70%), Betting (3.83%), Media (2.08%), and Healthcare (1.58%) segments.

It should be noted that Qrator.AntiBot allows customers to configure where protection is applied — including specific pages and domains. As a result, our bot index may not account for a significant portion of bot traffic targeting a protected resource.

The distribution of bots by type changed noticeably in Q2 2026 compared to the previous quarter. Simple script-based bots continued to account for the largest share of all bad bots, although their share declined significantly (65.23% → 50.80%). The share of puppeteer bots — those that emulate the environment of a legitimate user while being controlled through external automation — increased from 2.47% to 3.15%. The share of smart bots — those that are aware of anti-bot checks and attempt to bypass them — doubled (0.28% → 0.57%). API bots also saw substantial growth, with their share increasing from 32.02% to 45.48%.

The most intensive attack blocked by Qrator.AntiBot during Q2 2026 targeted an organization in the Media segment. It was a multi-vector DDoS incident that began as an L3-L4 attack before shifting to the application layer (L7). Its peak intensity exceeded 180,000 malicious requests per second.

The most intensive bad bot attack of Q2 2026

BGP incidents in Q2 2026

The number of unique Autonomous Systems (ASes) responsible for route leaks remained at roughly the same level as in 2025, averaging 1,996 ASes per month during Q2 2026.

In contrast, the average monthly number of unique ASes involved in BGP hijacking continued to decline rapidly: it fell from 8,587 in 2025 to 7,619 in Q1 2026 (-11.2%), before dropping further to 6,047 in Q2 2026 (-29.6%).

The decline in the number of BGP hijacking incidents is likely the result of significant progress in the deployment of RPKI ROA — a mechanism that effectively prevents this type of attack. Meanwhile, the technologies designed to mitigate route leaks — RFC 9234 and ASPA — are still at an early stage of deployment, which is why the number of route leak incidents has remained stable.

Adoption of RPKI ROA accelerated significantly during Q2 2026, bringing global coverage to 66% for IPv4 and 73% for IPv6 by the time of writing. ASPA deployment also advanced rapidly in 2026. Although its global adoption remains very limited at just 2.3%, the number of ASPA records increased more than fourfold since the beginning of the year, rising from 556 to 2,269.

As for global BGP incidents, we recorded seven route leaks and no BGP hijacking incidents during Q2 2026.

To identify global BGP incidents, the Qrator.Radar team applies a set of threshold criteria, including the number of affected prefixes and ASes, as well as the extent to which the anomaly propagates across routing tables.


Get your Report

Full name *
Work email *
Job Title *
Company name *

I acknowledge and agree to the terms and conditions set forth in Qrator Labs’ Privacy Policy.

Survey

Share your experience and expectations regarding DDoS protection. Your answers will help us tailor solutions to meet your cybersecurity needs.

Tell us about your company’s infrastructure and critical systems. This will help us understand the scope of protection you require.

Help us learn about how decisions are made in your company. This information will guide us in offering the most relevant solutions.

Let us know what drives your choices when it comes to DDoS protection. Your input will help us focus on what matters most to you.

1/4. Questions about Awareness and Needs Questions about Infrastructure Questions about Decision-Making Questions about Motivation
What is most important to you when choosing an Anti-DDoS solution? (select multiple options)
Who in your company makes decisions about cybersecurity solutions?
What is your company's average internet traffic volume?
Mb
Have you encountered DDoS attacks before?
What key risks do you want to minimize with DDoS protection?
When do you plan to consider a solution for DDoS protection?
Which systems are critical for your business to protect? (select multiple options)
Does your company have a solution to protect against DDoS attacks?
What is your company’s primary type of activity?
What level of DDoS protection do you consider sufficient?
Team size:
Thank you for completing the survey!
Your participation will help us produce better market analytics.
Thank you for staying with us!
If the document does not load, please click the "Download" button. Help us better understand the market and prepare better analytics, take the survey.
Your subscription successfully activated
Type
Name
Email
Phone Number
Write your message