Every day, our global infrastructure mitigates massive volumes of malicious traffic, giving us a front-row view of how the DDoS threat landscape is evolving. In this report, we explore the key trends that shaped Q2 2026, including the most common attack patterns, the industries most heavily targeted, and the distribution of DDoS activity across different countries.

You might also want to read our Q1 2026 DDoS report.
Q2 2026 Main Trends
The number of DDoS attacks increased by 108% year over year in Q2 2026. While this is lower than the 168% growth recorded in Q1, it does not indicate that the threat level is subsiding. Instead, it suggests that the pace of growth has slowed by about 36%, while the overall volume of attacks remains exceptionally high.
Geopolitical tensions continued to play a major role in shaping the threat landscape. StormWall estimates that more than 70% of all DDoS attacks during the quarter were attributed to hacktivist groups, with most campaigns targeting organizations connected to the Russia–Ukraine and Middle East conflicts.
At the same time, the majority of attacks remained relatively small in terms of bandwidth. This is not a coincidence: low-bandwidth attacks are inexpensive to launch, easier to scale, and often stay below automated detection thresholds, making them an effective tool for attackers.

Although attacks exceeding 2 Tbit/s represented just 0.3% of all incidents in Q2, this marks a significant increase from approximately 0.085% a year earlier — a 3.5-fold increase. While the percentage may appear small, at today’s attack volumes, it translates into a substantial increase in the number of ultra-high-capacity attacks capable of disrupting even well-protected organizations.
The Rise of AI-Powered Attacks
AI is playing an increasingly important role in modern DDoS campaigns. In Q2 2026, AI-assisted attacks accounted for approximately 34% of all DDoS incidents, up from 22% in Q1, highlighting how quickly attackers are adopting AI-powered tools.
One of the main reasons behind this growth is the rapid expansion of the underground AI ecosystem. Over the past year, mentions of malicious AI tools on dark web forums increased by 219%, while purpose-built services have made sophisticated attacks accessible even to individuals with limited technical expertise.
StormWall has observed a growing number of attacks launched using commercial malicious AI platforms such as WormGPT 4, GhostGPT, and Xanthorox AI, which are widely advertised on Telegram and can cost as little as $50 per month. Open-source alternatives, including KawaiiGPT, are also becoming increasingly popular.
Rather than replacing traditional attack tools, AI acts as an intelligent orchestration layer that continuously adapts attack campaigns in real time. Attackers use it to:
- Shape malicious traffic to resemble legitimate user behavior.
- Rotate traffic sources to reduce the effectiveness of blocking.
- Modify attack parameters on the fly when defensive measures are detected.
As a result, launching adaptive and polymorphic DDoS attacks has become significantly easier. What once required experienced operators can now be automated with minimal effort, contributing to rapid growth of both multi-vector and Layer 7 attacks during Q2 2026.
Multi-Vector Attacks: The Leading Attack Type
Multi-vector DDoS attacks remained the most common attack type observed by StormWall in Q2 2026, increasing by 38% year over year. By combining multiple attack techniques into a single campaign, they place significantly greater pressure on defensive systems than conventional single-vector attacks.
The growing use of AI-powered tools is accelerating this trend. Attackers can now coordinate and adapt multiple attack vectors with minimal effort, making complex campaigns easier to launch, harder to detect, and more difficult to mitigate. As a result, organizations relying on traditional, single-purpose DDoS defenses are finding it increasingly challenging to withstand these evolving threats.
Layer 7 Attacks: One of the Fastest-Growing Vectors
Layer 7 (application-layer) attacks increased by 82% year over year in Q2 2026, making them one of the fastest-growing DDoS attack vectors observed during the quarter.
Unlike network-layer attacks that overwhelm bandwidth, Layer 7 attacks are designed to exhaust application resources by generating large volumes of seemingly legitimate HTTP(S) requests. Because this traffic closely resembles normal user activity, it is far more difficult to distinguish from genuine requests.
Throughout Q2, StormWall observed attack campaigns that increasingly combined automation with large proxy and residential proxy networks:
- Distribute requests across thousands of IP addresses.
- Mimic legitimate browser behavior.
- Continuously vary request patterns to evade detection.
Attackers also focused on high-traffic APIs and other critical application endpoints, generating requests that appeared random and authentic in an effort to blend in with legitimate user traffic. This makes conventional rule-based defenses far less effective.
AI has become a key enabler of these campaigns. By automating traffic generation, behavioral imitation, and real-time adaptation, AI allows attackers to launch sophisticated Layer 7 attacks that previously required experienced operators. Today, many of these capabilities are available through off-the-shelf AI tools, significantly lowering the barrier to entry for complex application-layer attacks.
DDoS Protection for Websites
- Activate protection in 10 minutes
- 24/7 technical support
Botnet Attacks: Growing Stronger
Botnet-powered DDoS attacks increased by 116% year over year in Q2 2026, marking the largest growth among all attack categories tracked by StormWall this quarter.
Despite the disruption of the Aisuru and Kimwolf botnets — operations that would normally reduce global attack activity — overall DDoS volumes remained virtually unchanged. Instead, threat actors quickly shifted to alternative botnet infrastructure, demonstrating just how resilient and decentralized today’s DDoS ecosystem has become.
Among the most active botnets observed during Q2 2026 were:
- Masjesu (also known as XorBot)
- xlabs_v1
- More than 116 active Mirai-derived botnet variants
- RapperBot (also tracked as Eleven11bot)
The growing availability of botnet resources has directly contributed to more powerful attacks. Across several major industries, StormWall recorded a significant increase in the average bandwidth of DDoS campaigns:

This trend is most evident at the highest end of the attack spectrum. The number of DDoS attacks exceeding 2 Tbit/s grew 3.5-fold year over year. While these hyper-volumetric attacks still account for only a small share of overall activity, they are increasing faster than any other attack-size category and pose an escalating threat to organizations with insufficient network capacity or outdated mitigation strategies.
Industry Breakdown: Financial Services Take the Lead
The financial sector became the most targeted industry in Q2 2026, overtaking telecommunications for the first time in StormWall’s reporting history. While telecom providers continued to face a significant share of DDoS activity, attackers increasingly shifted their attention toward financial institutions, reflecting the growing impact of attacks on critical digital services.

Financial services also recorded the strongest year-over-year increase in attack volume, with nearly every major industry experiencing substantial growth.

Compared with Q1 2026, the distribution of attacks shifted noticeably:
- Financial services increased from 18% to 26% of all attacks, representing a rise of approximately 44%.
- Telecommunications declined from 34% to 22%, although it remained the second most targeted sector.
- Government organizations held steady at 14%.
- Entertainment grew from 9% to 12%.
- Retail declined from 12% to 8%.
- Oil & Gas entered StormWall’s list of the ten most targeted industries by attack volume.
The emergence of financial services as the primary target marks one of the most significant shifts observed this quarter. At the same time, the growing focus on the oil and gas sector suggests that attackers are focusing on the industries that operate critical infrastructure,where service disruptions can have far-reaching operational and economic consequences.
Relative DDoS Risk by Industry
While no organization is immune to DDoS attacks, some industries face significantly higher risk than others. Based on the global distribution of attacks observed by StormWall in Q2 2026, the table below illustrates the relative likelihood of organizations in each sector being targeted.

Financial institutions and telecommunications providers remain the most attractive targets, largely because service disruptions in these sectors have immediate financial, operational, and reputational consequences. Organizations operating critical infrastructure or high-traffic online services also continue to face an elevated level of risk.
Note: These figures represent relative risk based on the global distribution of DDoS attacks observed by StormWall. The actual likelihood of an individual organization being targeted depends on factors such as its internet exposure, business profile, security posture, geographic location, and whether it has been specifically selected by threat actors.
Top 3 Most Attacked Sectors: A Closer Look
While DDoS activity increased across nearly every industry in Q2 2026, three sectors stood out as the primary targets. Below is a closer look at the attack trends observed in each sector.
1. Financial Services
Financial services became the most targeted industry in Q2 2026, overtaking telecommunications for the first time in StormWall’s reporting. Much of this activity was driven by pro-Iranian hacktivist groups, which increasingly focused on banks, payment providers, and other financial organizations.
Attack campaigns also became significantly more persistent. Compared with Q2 2025:
- The median duration of network-layer DDoS attacks against financial institutions increased by 452%.
- In the EMEA region, the median attack duration more than doubled, rising from 34 minutes to 72 minutes.
From a technical perspective, attackers increasingly focused on the application layer, particularly APIs that support online banking, payment processing, and customer-facing digital services.

The growing prevalence of API-layer attacks reflects a broader shift toward application-focused DDoS campaigns. Rather than simply overwhelming network bandwidth, attackers are increasingly targeting the services that process transactions and customer requests, where even short disruptions can have an immediate impact on users, revenue, and business operations.
2. Telecommunications
Telecommunications remained the second most targeted industry in Q2 2026. Although its share of overall DDoS attacks declined compared with the previous quarter, telecom operators continued to face relentless attack activity due to their role as critical internet infrastructure providers.
StormWall observed that this sector experienced the highest proportion of botnet-driven attacks of any industry. Large botnets were frequently used to generate sustained, high-bandwidth floods capable of overwhelming network infrastructure and disrupting connectivity for downstream customers.

Unlike the financial sector, where application-layer attacks dominated, telecommunications providers were primarily targeted by large-scale network-layer attacks. TCP, UDP, and ICMP floods accounted for more than 86% of all attacks observed in this sector, highlighting attackers’ continued focus on exhausting network capacity and disrupting connectivity through high-volume traffic generated by large botnets.
3. Government Sector
The government sector remained one of the primary targets for politically motivated DDoS campaigns in Q2 2026. According to StormWall’s observations, nearly half of all attacks mitigated for government organizations were launched by organized hacktivist groups, with many campaigns linked to geopolitical tensions in the Middle East. In Europe, a significant portion of DDoS activity targeting public-sector infrastructure was attributed to state-sponsored threat actors.
Government organizations were most frequently targeted through attacks aimed at disrupting public-facing online services rather than overwhelming network capacity alone.

HTTP floods were by far the most common attack vector, accounting for more than two-fifths of all attacks against government infrastructure. This reflects a broader shift toward application-layer attacks designed to disrupt websites, citizen portals, and digital public services while blending in with legitimate user traffic, making mitigation more challenging than traditional volumetric attacks.
Geographic Breakdown: DDoS Attacks by Country
DDoS activity remained highly concentrated in a relatively small number of countries during Q2 2026. The United States, China, and India continued to be the three most targeted nations, together accounting for 40.4% of all attacks observed by StormWall — up from 33.4% in Q1. This indicates that attackers increasingly focused their efforts on a smaller group of high-value targets.

One of the most notable developments this quarter was the sharp rise in attacks targeting Iran, which became the sixth most attacked country globally with 7.2% of all observed DDoS activity. As geopolitical tensions in the Middle East increasingly centered on Iran, the country’s digital infrastructure became a much more prominent target than in Q1.
At the same time, the exceptional surge in attacks against several other Middle Eastern countries observed during the previous quarter began to moderate in relative terms:
- Israel: 8.7% → 6.4% (approximately 26% lower share)
- United Arab Emirates: 7.1% → 4.8% (approximately 32% lower share)
- Saudi Arabia: 6.8% → 4.2% (approximately 38% lower share)
It is important to note that these figures reflect a decline in relative share, not necessarily a reduction in the absolute number of attacks. In practice, this means that DDoS activity expanded more rapidly in other regions, causing these countries to represent a smaller proportion of global attack volume.
Notable Changes Since Q1 2026
| Country | Q1 2026 | Q2 2026 |
| USA | 12.8% | 17.4% ▲ |
| Iran | Outside top 15 | 7.2% ▲ |
| United Kingdom | 7.4% | 9.7% ▲ |
| China | 11.4% | 12.6% ▲ |
| India | 9.2% | 10.4% ▲ |
| Saudi Arabia | 6.8% | 4.2% ▼ |
| United Arab Emirates | 7.1% | 4.8% ▼ |
| Israel | 8.7% | 6.4% ▼ |
| Singapore | 5.4% | 3.6% ▼ |
| Ukraine | 3.6% | 2.3% ▼ |
Overall, the geographic distribution of attacks in Q2 reflects two parallel trends: an increasing concentration of DDoS activity in the world’s largest digital markets and a continued, though evolving, influence of geopolitical conflicts on attackers’ targeting decisions.
Summary: Q2 2026 in Review
Q2 2026 confirmed that the DDoS threat landscape continues to evolve rapidly. While the pace of growth slowed compared with the previous quarter, attackers became more capable, more adaptive, and increasingly reliant on AI.
Key takeaways from Q2 2026:
- DDoS attacks increased by 108% year over year. Although this is lower than the 168% growth recorded in Q1, overall attack volumes remain exceptionally high.
- AI-assisted attacks continued to surge. StormWall estimates that their share rose from approximately 22% in Q1 to 34% in Q2, driven by the rapid adoption of purpose-built malicious AI tools.
- Attack power reached new levels. Average attack bandwidth increased sharply across major industries — by as much as 5× in telecommunications — while the number of attacks exceeding 2 Tbit/s grew 3.5 times year over year.
- Financial services became the primary target. The sector accounted for 26% of all attacks, followed by telecommunications (22%) and the government sector (14%).
- Geopolitical events continued to shape attacker behavior. The United States (17.4%), China (12.6%), and India (10.4%) remained the most targeted countries, while Iran entered the global top ten with 7.2% of attacks as regional tensions intensified.
The defining story of Q2 was the rapid adoption of AI by threat actors. AI is no longer just making DDoS attacks easier to launch — it is making them smarter. By automating traffic generation, adapting attack behavior in real time, and coordinating complex multi-vector campaigns, AI has significantly lowered the barrier to entry while increasing the sophistication and effectiveness of attacks.
AI has fundamentally changed the economics of DDoS attacks. Capabilities that once required experienced operators are now available through commercial and open-source AI tools, making sophisticated attacks accessible to a much broader range of threat actors.
As a result, organizations should expect DDoS campaigns to become more adaptive, more persistent, and increasingly difficult to distinguish from legitimate traffic. Effective protection now depends on mitigation technologies that can analyze traffic behavior in real time and respond just as quickly as attackers adapt.
“The question is no longer whether AI will reshape the DDoS landscape — it already has. The real question is whether organizations are prepared for this new reality,” said Ramil Khantimirov, CEO and Co-Founder of StormWall.
Author: Yulia Ilyina, Technical Expert at StormWall
Network Protection from DDoS Attacks
- Activate protection within 10 minutes
- 24/7 technical support















