Radware H1 2026 Report Shows Web DDoS Attacks Surge 110.6%
Radware, a global leader in AI and application security and delivery solutions for multi-cloud environments, announced its H1 2026 Global Threat Analysis Report, revealing a sharp escalation in cyberattack activity across network and application layers during the first six months of the year.
The new report analyzes data from Radware’s cloud and managed security services and research from its threat intelligence team, highlighting the increasing speed and scale of DDoS attacks, vulnerability exploitation and AI-driven threats facing organizations worldwide.
In the H1 2026 report:
Web DDoS Attack Activity Skyrockets
Web DDoS attacks surged 110.6% compared with H1 2025 and rose 36.3% compared with the second half of 2025. In just the first six months of 2026, Web DDoS mitigations reached nearly 83% of the total volume recorded throughout all of 2025.
Attack Volume: If attack volumes continue at the same pace, based on a straight-line extrapolation of H1 2026 data, Web DDoS attacks could increase by approximately 166% year over year in 2026.
Geographic Targets: Based on H1 2026 trends, North America is estimated to see the highest projected growth in Web DDoS attacks in 2026 at approximately 190%, compared with an estimated 60% in EMEA, 39% in Central and Latin America (CALA), and 27% in APAC, assuming current-pace conditions continue through year-end.
Network DDoS Attacks Intensify
Network-layer DDoS attacks reached an average of 110 attacks per customer per day during H1 2026, a 36.6% increase over the 2025 baseline, as attackers shifted away from traditional reflection and amplification techniques toward direct-path volumetric floods.
Attack Vectors: Direct-path User Datagram Protocol (UDP) floods, which overwhelm targets with traffic, accounted for 73% of total mitigated packets and more than 80% when combined with fragmented UDP traffic.
Industry Targets: The technology sector accounted for 59.4% of all network DDoS attacks, averaging 509 attacks per customer per day. Financial services followed, accounting for 20.8% of network attacks.
Geographic Targets: North America absorbed the largest share of network DDoS attacks at 43.1%, while the Middle East recorded the highest attack frequency, averaging 520 attacks per customer per day.
Application and API Attacks Double
Malicious web application and API transactions increased 104% over 2025 levels, exceeding 14,000 malicious transactions per application per day in H1 2026.
Vulnerability Exploitation: Vulnerability exploitation accounted for 62.1% of all recorded web application and API attacks.
Geographic Targets: North America accounted for 79.5% of all global malicious web application and API transactions.
Vulnerability Exploitation Outpaces Defenders
The window between vulnerability disclosure and active exploitation has narrowed dramatically. The mean time from official Common Vulnerabilities and Exposures (CVE) announcement to the first detected attack in the wild dropped to below zero compared with a mean of 21.5 days post-disclosure in 2025 and 53 days in 2024, based on Radware’s threat intelligence data.
Zero-Day Exploitation: The zero-day rate surpassed 80%, meaning more than four out of five vulnerabilities were exploited before their official CVE announcement.
AI Accelerates Cybersecurity Risks
Autonomous AI systems are creating new attack vectors and accelerating vulnerability discovery. Local AI agents that operate continuously on user devices can access systems, execute tasks, call APIs and autonomously download software dependencies, creating risks ranging from prompt injection to software supply chain attacks.
Advanced AI models are also accelerating attack execution. The report highlights how frontier models can use semantic reasoning and vulnerability chaining to identify flaws that have escaped years of human review and traditional security testing. At the same time, increasingly capable open-weight models are making advanced offensive capabilities more broadly accessible.
AI Agent Adoption: According to Radware’s survey research, 77% of organizations are actively deploying or implementing AI agents and autonomous workflows, yet only 17.2% report full visibility into the AI agents operating in their environments.
API Development: According to Radware’s survey research, more than 70% of organizations increased their use of internally developed APIs over the past year, and 81.2% now push production API updates at least weekly.
API Visibility: Despite the rapid pace of development, Radware’s survey research found that only 6.9% of organizations fully document their internal APIs, while 43% document less than 70% of them.
Bad Bot Activity Continues to Rise
Bad bot activity remained elevated in H1 2026, reaching nearly 60% of the total volume recorded throughout 2025.
Geographic Targets: North America accounted for 50.1% of global bad bot activity, followed by APAC at 23.2%.
Hacktivism Tracks Geopolitical Conflict
Geopolitical conflict continued to dictate hacktivist DDoS activity during the first half of 2026. While overall public attack claims entered a multi-quarter contraction after peaking in Q2 2025, activity surged in direct response to military events, including a 103% month-over-month increase in March 2026 that corresponded with reported military events in the Middle East.
Regional Concentration: Europe remained the primary target, accounting for 48% of all hacktivist DDoS attack claims.
Nation and Industry Targets: Israel was the most targeted country, accounting for 16.9% of claimed attacks, followed by Ukraine (8.4%) and the United States (7.7%). Government remained the most targeted industry at 37.2% of all claims.
Most Active Threat Actor: Pro-Russian threat collectives continued to dominate hacktivist activity. NoName057(16) alone generated 40.5% of all recorded claims in H1 2026.
Radware’s complete H1 2026 Global Threat Analysis Report can be downloaded here.
Radware Webinar on H1 2026 Global Threat Analysis Report
Radware will host a webinar on October 1, 2026, at 11:00am EDT on The Automated Tipping Point: AI Agents, Zero-Day Exploitation and the H1 2026 Threat Landscape, where Pascal Geenens, vice president of threat intelligence at Radware, will discuss the report and the network, application, AI and hacktivist threat trends shaping the first half of 2026.
Security leaders and researchers are invited to attend and explore the report and its data on cyberattack activity during H1 2026.
Pascal Geenens, vice president of threat intelligence at Radware
Attackers are increasingly operating at machine speed — launching direct-path DDoS attacks, exploiting vulnerabilities and using agentic AI to automate and speed up their attacks. At the same time, organizations are rapidly deploying AI agents and APIs without complete visibility into their expanding attack surfaces. The growing gap between the speed of attacks and the ability of organizations to detect and respond to them is fundamentally changing the threat landscape.