Publishers were the most attacked industry on the internet in the first half of 2026

Cloudflare mitigated 935 attacks above 1 Tbps in six months, up 519 per cent quarter on quarter. Media, production and publishing took more of it than any other sector.

silver iphone 6 on macbook pro
Illustration · Photo by Nubelson Fernandes on Unsplash

Cloudflare mitigated 23.2 million network-layer denial-of-service attacks in the first six months of 2026 — about 5,343 an hour, or 128,000 a day — according to the company’s half-year threat report.

The figure that stands out is not the total. It is which industry absorbed most of it. Media, production and publishing was the single most attacked sector in both quarters, taking 14.2 per cent of all mitigated HTTP attack traffic.

The very large attacks are multiplying

Cloudflare recorded 935 network-layer attacks exceeding 1 Tbps in the half — a scale that was remarkable when the first one was publicly recorded, and is now happening several times a day. The quarter-on-quarter increase was 519 per cent.

The composition shifted too. DNS-based attacks made up 34.3 per cent of network-layer activity across the half, with DNS floods alone climbing from 25.7 to 40.0 per cent quarter on quarter. CLDAP floods rose 580 per cent to become the third most common vector in the second quarter.

Both of those are amplification techniques: the attacker sends a small request to a misconfigured third-party server that replies with something much larger, aimed at the victim. They persist because the misconfigured servers persist, and neither the attacker nor the victim owns them.

Read the source with the source in mind

This is a vendor report. Cloudflare sells protection against exactly the thing it is measuring, and the data describes traffic crossing Cloudflare’s own network — not the internet as a whole. Sectors and countries that use Cloudflare heavily will be better represented than those that do not.

That does not make the numbers wrong, and Cloudflare’s methodology is more transparent than most. It does mean “media was the most attacked industry” should be read as “media was the most attacked industry among Cloudflare’s customers”, which is a large sample rather than a complete one.

The company publishes much of the underlying data continuously on Cloudflare Radar, which is free and does not require a customer relationship to inspect.

Why publishers

The report notes the government sector jumping from 29th to 9th, and Turkey rising to the third most attacked country around the July NATO summit in Ankara — both consistent with attacks that follow political events rather than commercial incentives.

Publishing fits that pattern. News sites are attacked because someone objects to what they published, because a story is breaking and taking the site down has a window of value, or because they are soft targets with real-time relevance. Unlike a bank, a news site has no funds to steal — the payoff is silence.

That is a different threat model from fraud, and it is one small publishers are poorly placed to handle. Mitigating a terabit-scale attack is not something you do with a plugin.

Denial of service is also only one route in. The other is the unpatched appliance at the edge of the network, which is why CISA’s list of vulnerabilities under active exploitation is worth checking against whatever your hosting sits behind.

What it means for a small site

Most sites will never see anything approaching a terabit. The practical exposure is the ordinary end of the distribution — attacks that a competent CDN absorbs without the owner noticing.

Both the NCSC and CISA publish free guidance, and the useful part of both is the same: know in advance who to call, because the middle of an attack is a bad time to discover your hosting arrangement has no answer.

Sources