Starting from Q2 2025, we changed our methodology for analyzing DDoS attacks. Previously, we considered network- and transport-layer attacks (L3-L4 DDoS) and application-layer attacks (L7 DDoS) separately. We now use a unified approach based on incidents, which may consist of multiple attacks across different vectors.
We filter out L3-L4 DDoS attacks with an intensity below 1 Gbps, considering them background noise. For L7 DDoS attacks, we also apply threshold criteria: at least 100 blocked IP addresses and a rate of at least 1,000 requests per second. Multiple attack waves are grouped into a single incident if the time gap between them does not exceed one hour.
As in previous quarters, HTTP flood — application-layer (L7) attacks — remained the most common DDoS attack vector in Q2 2026, accounting for 46.8% of all attacks we recorded. This was slightly below both the 2025 level (56.4%) and the previous quarter (54.1%). UDP flood ranked second, with its share increasing significantly compared to 2025 (22.9% → 29.3%).
The share of TCP flood attacks more than doubled compared to 2025 (4.2% → 8.9%), while SYN flood attacks saw a similar increase (2.8% → 5.6%). By contrast, the share of IP flood attacks continued to decline (13.8% → 5.2%). We also observed an unexpected surge in ICMP flood attacks: they accounted for 4.3% of all attacks in Q2 2026, compared to just 0.1% in 2025.
The share of multi-vector attacks continued to grow in Q2 2026, reaching 11.7% of all recorded incidents. At the same time, the share of multi-vector attacks combining L3-L4 and L7 vectors returned to the previous year’s level, declining from 6.2% of all incidents in Q1 2026 to 3.6% in Q2.
The largest share of DDoS attacks during Q2 2026 targeted organizations in the FinTech (31.9%), Information and communication technology (16.8%), and Media (14.0%) segments. Together, these segments accounted for approximately two-thirds of all recorded incidents.
They were followed by the E-commerce (12.0%) and Betting (9.0%) segments. We expect activity in the latter to peak next quarter, as the most significant stage of the FIFA World Cup is taking place in July.
At a more granular level, the microsegments most frequently targeted by DDoS attacks during Q2 2026 were Media, TV, radio, and bloggers (12.7%), Payment systems (10.0%), Banks (9.5%), Betting shops (9.0%), and Trading platforms (7.9%). Together, these five microsegments accounted for nearly half (49.1%) of all recorded incidents.
The longest DDoS attacks recorded during Q2 2026 targeted the Online retail (79.9 hours), Banks (24.4 hours), Gambling (18.3 hours), Betting shops (12.5 hours), and Systems integrators (12.4 hours) microsegments. The maximum attack duration was more than four times greater than in the previous quarter (19.0 hours), although it still fell well short of the 2025 record (119.2 hours).
The average attack duration decreased slightly in Q2 2026 compared to the previous quarter, from 3,221 to 2,764 seconds. At the same time, the median attack duration increased slightly, from 120 to 150 seconds.
The two most intensive DDoS attacks recorded during Q2 2026 targeted organizations in the Betting segment. Their peak bitrates reached 1.64 Tbps and 1.58 Tbps, while packet rates peaked at 553 Mpps and 638 Mpps, respectively. By both metrics, these were the largest DDoS incidents of the quarter.
The larger of the two attacks consisted of three distinct waves, with a combined period of peak activity lasting approximately 20 minutes.
Although the highest bitrates recorded in Q2 2026 were somewhat lower than the peaks observed in Q1 2026 (2.07 Tbps) and in 2025 (3.51 Tbps), the overall trend remains unchanged — DDoS attacks exceeding 1 Tbps have become commonplace. During Q2 alone, we mitigated 12 such incidents, twice as many as throughout 2025.
The five microsegments targeted by the most intensive L3-L4 DDoS attacks in terms of bitrate during Q2 2026 were Betting shops (1,641 Gbps), Marketplaces (1,509 Gbps), Hosting platforms (1,353 Gbps), Game developers (1,172 Gbps), and Payment systems (951 Gbps).
In terms of peak packet rate, the top five microsegments were Betting shops (638.6 Mpps), Game developers (134.1 Mpps), Marketplaces (132.1 Mpps), Hosting platforms (118.4 Mpps), and Banks (114.1 Mpps).
During Q2 2026, the largest botnet we observed while mitigating L7 DDoS attacks decreased in size for the first time in two years, falling from 13.5 million devices in the previous quarter to 2.09 million devices in Q2. One possible reason for this sharp decline was the law enforcement operation carried out by authorities in the United States, Canada, and Germany, which disrupted the infrastructure used by major botnets, including Aisiru and Kimwolf. As the operation took place at the very end of Q1 2026, its impact became most apparent during the second quarter.
The botnet consisted primarily of devices located in Brazil (18.5%), the United States (10.9%), the United Kingdom (5.1%), Saudi Arabia (3.9%), and Argentina (3.1%). Unlike the size of the botnet, the country distribution has changed little since the previous quarter.
Despite the successful law enforcement operation, the fundamental conditions that enable such massive botnets to emerge have not changed. The number of potentially vulnerable devices worldwide continues to grow, while the process of finding and compromising them has become much simpler and faster in recent years with the emergence of new AI-based automation tools used by attackers.
For this reason, we do not expect a long-term shift in the situation. Over time, the largest botnets are likely to start growing again, as their operators will be able to rebuild infrastructure quickly and compensate for the losses incurred.
The law enforcement operation carried out by authorities in the United States, Canada, and Germany, discussed in the previous section, appears to have affected not only the size of the largest botnet but also the overall geographic distribution of L7 DDoS attack sources during Q2 2026. The United States ranked first with 15.9%, followed by Vietnam (9.5%) and Russia (7.2%). Brazil, which had led the ranking for several consecutive quarters, saw its share decline sharply to 6.2%, dropping to fourth place. The Netherlands climbed to fifth with 3.1% after ranking outside the top ten in the previous quarter.
Overall, the Q2 2026 distribution of L7 DDoS attack sources continues to reflect the trend toward greater geographic diversification of the infrastructure used by attack operators. Despite the reshuffling within the top five, their combined share remained virtually unchanged (42.0% → 41.9%), while the share of all other countries outside the top 20 continued to grow (29.0% → 29.8%). As we have noted in previous reports, this diversification reduces the effectiveness of simple geographic blocking as a mitigation measure against large-scale DDoS attacks.
“Bad bots” refer to automated systems that attempt to interact with websites while impersonating real users. Their typical objectives include data scraping, metric manipulation, credential stuffing, and other forms of unwanted activity. However, unlike destructive DDoS bots, bad bots usually do not aim to disrupt website availability.
During Q2 2026, the average monthly number of blocked bad bot requests declined noticeably compared to previous quarters, totaling approximately 1.8 billion.
This is roughly in line with the levels observed in 2024. It should be noted that 2025 saw two distinct seasonal spikes in bad bot traffic during the second and fourth quarters. These spikes were driven by two particularly large-scale attacks, each lasting for about a month. We have not observed bad bot attacks of comparable duration in 2026 so far. As a result, bad bot traffic has been distributed more evenly across the protected resources.
During Q2 2026, the largest share of bad bot attacks was once again directed at the E-commerce segment, accounting for 43.67% of all bad bot activity. Unsurprisingly, the Betting segment ranked second with 17.20%, followed by the Media segment at 16.04%.
Across all protected resources, the share of bad bot traffic in total traffic — referred to here as the “bot index” — averaged 1.56% in Q2 2026. The highest bot index values were recorded in the EdTech (16.92%), Transport&Logistics (7.70%), Betting (3.83%), Media (2.08%), and Healthcare (1.58%) segments.
It should be noted that Qrator.AntiBot allows customers to configure where protection is applied — including specific pages and domains. As a result, our bot index may not account for a significant portion of bot traffic targeting a protected resource.
The distribution of bots by type changed noticeably in Q2 2026 compared to the previous quarter. Simple script-based bots continued to account for the largest share of all bad bots, although their share declined significantly (65.23% → 50.80%). The share of puppeteer bots — those that emulate the environment of a legitimate user while being controlled through external automation — increased from 2.47% to 3.15%. The share of smart bots — those that are aware of anti-bot checks and attempt to bypass them — doubled (0.28% → 0.57%). API bots also saw substantial growth, with their share increasing from 32.02% to 45.48%.
The most intensive attack blocked by Qrator.AntiBot during Q2 2026 targeted an organization in the Media segment. It was a multi-vector DDoS incident that began as an L3-L4 attack before shifting to the application layer (L7). Its peak intensity exceeded 180,000 malicious requests per second.
The number of unique Autonomous Systems (ASes) responsible for route leaks remained at roughly the same level as in 2025, averaging 1,996 ASes per month during Q2 2026.
In contrast, the average monthly number of unique ASes involved in BGP hijacking continued to decline rapidly: it fell from 8,587 in 2025 to 7,619 in Q1 2026 (-11.2%), before dropping further to 6,047 in Q2 2026 (-29.6%).
The decline in the number of BGP hijacking incidents is likely the result of significant progress in the deployment of RPKI ROA — a mechanism that effectively prevents this type of attack. Meanwhile, the technologies designed to mitigate route leaks — RFC 9234 and ASPA — are still at an early stage of deployment, which is why the number of route leak incidents has remained stable.
Adoption of RPKI ROA accelerated significantly during Q2 2026, bringing global coverage to 66% for IPv4 and 73% for IPv6 by the time of writing. ASPA deployment also advanced rapidly in 2026. Although its global adoption remains very limited at just 2.3%, the number of ASPA records increased more than fourfold since the beginning of the year, rising from 556 to 2,269.
As for global BGP incidents, we recorded seven route leaks and no BGP hijacking incidents during Q2 2026.
To identify global BGP incidents, the Qrator.Radar team applies a set of threshold criteria, including the number of affected prefixes and ASes, as well as the extent to which the anomaly propagates across routing tables.
Share your experience and expectations regarding DDoS protection. Your answers will help us tailor solutions to meet your cybersecurity needs.
Tell us about your company’s infrastructure and critical systems. This will help us understand the scope of protection you require.
Help us learn about how decisions are made in your company. This information will guide us in offering the most relevant solutions.
Let us know what drives your choices when it comes to DDoS protection. Your input will help us focus on what matters most to you.