Cloudflare reported a record DDoS attack of 31.4 Tbps for 2026. But the real change is elsewhere - 94% of login attempts come from bots, and 63% of those carry passwords already stolen.
- Cloudflare's 2026 threat report: a record DDoS attack of 31.4 Tbps, but the real change is in the tactics (March 3).
- 94% of login attempts come from bots; 63% use passwords already compromised elsewhere.
- The takeaway: attackers stopped breaking in and started unlocking - efficiency instead of elaborate exploits.
31.4 Tbps. That's the record DDoS attack in Cloudflare's new threat report for 2026 - a measure of internet traffic speed, high enough to sound like a headline. But the more important number sits quietly further down the page. Attackers stopped breaking down the door. They started unlocking it.
That's the single most important line in the whole report. The attack of the future isn't a brilliant hack. It's your old password, leaked somewhere else and tried automatically everywhere. Cheap, massive, effective.
Defense stopped being just a tall wall. Assume passwords leak, and build as if they've already leaked: unique passwords for every place, 2FA (two-factor login verification), zero trust toward the 'right' login up front. The perimeter doesn't guard alone. What matters is what you let in after it falls.