Geopolitical Tensions Fuel Surge in DDoS Attacks Against Media Outlets
Media organizations faced a significant increase in DDoS attacks throughout 2026, driven by global conflicts and major sporting events, according to Cloudflare.

Media organizations have become the primary target for Distributed Denial-of-Service (DDoS) attacks in 2026, experiencing a dramatic surge attributed to escalating geopolitical tensions and major global events. Cloudflare's latest data reveals that attacks on the media, production, and publishing sectors accounted for 14.2% of all DDoS attacks launched in the first half of the year. This makes the sector significantly more targeted than the second most-affected industry, gambling and casinos, which saw nearly four times fewer attacks.
According to Cloudflare, the motivations behind these attacks on media outlets differ fundamentally from those targeting other sectors. "For publishers, availability is the deliverable," explained Blake Darché, Head of Cloudforce One and Threat Intelligence at Cloudflare. "While a DDoS attack on an e-commerce site could aim to steal transaction revenue, an attack on a publisher is typically aimed at censorship, information suppression or timing disruption." The effectiveness of such attacks is amplified by the ephemeral nature of news; taking an outlet offline during a breaking story or a critical event can effectively silence it at its peak readership, even if systems recover shortly thereafter.
The ongoing wars in Ukraine and Iran, coupled with the FIFA World Cup, have been identified as key catalysts for this trend. Cloudflare's findings align with reports from other security firms. Following the outbreak of war between the US and Iran in February, Akamai observed a 245% increase in cybercrime, with DDoS attacks rising by 38%. Similarly, Palo Alto Networks noted a clear uptick in pro-Russia hacktivism around the same period, with hacktivist groups often relying on DDoS attacks to achieve their objectives.
These hacktivist groups, frequently organized on social media, coordinate attacks against specific organizations. While often characterized as low-level, their impact can be significant, particularly for critical infrastructure operators where sustained disruption could lead to severe service outages. The war in Iran also contributed to a notable increase in attacks targeting government entities, which rose from the 29th most-targeted sector in Q1 to ninth in Q2. The US and China remained the most targeted regions, with Turkey also seeing a rise in attacks following its hosting of the Ankara NATO summit.
Beyond the specific targeting of media and government, Cloudflare also reported a substantial increase in hyper-volumetric network-layer DDoS attacks. In the second quarter of 2026 alone, the company mitigated 805 attacks exceeding 1 Terabit per second (Tbps), a staggering 519% increase from the previous quarter. These attacks, which target core networking protocols to overwhelm infrastructure, represent a growing threat despite comprising a tiny fraction of overall DDoS activity.
While these hyper-volumetric attacks are rare, their potential impact is immense. They are capable of taking down even the most robust internet infrastructure. In contrast, the vast majority of DDoS attacks remain smaller and shorter in duration, with 96.62% transmitting less than 500 Mbps and 90.6% concluding in under ten minutes. However, even these smaller attacks can be sufficient to knock most networks offline, with a 100 Mbps attack capable of taking down a website and a 1 Gbps attack potentially disrupting an entire data center.
The speed and brevity of these large-scale attacks present a significant challenge for mitigation. Cloudflare noted that by the time a security analyst is alerted, the attack may have already concluded, rendering manual intervention too slow. "Whether an attack lasts half a minute or ten minutes, there is no practical window for human intervention," the report states. Even short bursts can trigger cascading effects, leading to routing instability, application timeouts, and degraded services that can take hours or days to fully resolve.
The evolving landscape of DDoS attacks, driven by geopolitical events and increasingly sophisticated techniques, underscores the need for robust, automated defenses. The rise of hyper-volumetric attacks, coupled with the strategic targeting of information dissemination channels, highlights the critical importance of maintaining resilient digital infrastructure in an increasingly volatile global environment.