Selectel reports a fourfold increase in peak DDoS volume
Selectel reports growth in DDoS count, duration and power. We examine the methodology and practical resilience measures for digital services.

Selectel published its DDoS report for the first half of 2026 on 15 July. The provider says its protection systems mitigated 88,618 attacks, 45% more than during the same period in 2025.
Reported figures
Combined attack duration reached 22,101 hours, close to the 22,743 hours recorded during the whole of 2025. Peak attack volume reached 870 Gbit/s and peak packet rate reached 369 million packets per second.
One customer experienced up to 10,522 incidents in a month, while the maximum combined exposure for one customer exceeded 795 hours in a calendar month. TCP SYN Flood and TCP PSH/ACK Flood together represented 58% of incidents, down from 76%, indicating a broader mixture of techniques.
What the methodology covers
The data comes from protection operating on Selectel’s own data-centre network for its cloud, platform services and dedicated servers. It describes what one provider observed in its environment, not every attack across Russia.
The useful signal is the simultaneous growth of count, duration, bandwidth and packet rate. Capacity planning must cover links, routers, state tables, load balancers and application resources.
A layered resilience model
An additional link alone is insufficient. A resilient design combines upstream L3/L4 scrubbing, boundary controls, application-layer protection, caching and queues, scalable critical components and a degraded mode that preserves essential operations.
Failover also needs to be rehearsed. Both paths require protection, while DNS, certificates and control-plane access must not become new single points of failure.
Track detection time, mitigation activation time, false blocks, remaining channel headroom, P95/P99 latency and successful business operations. Connect these measures to an SLO rather than keeping them only in a network report.
Our guide to SLIs, SLOs and error budgets explains that connection. Prolonged unavailability should also be covered by a tested disaster recovery plan.
Conclusion
Selectel’s data indicates growth across several DDoS dimensions at once. An organisation may have a different traffic profile, but readiness still needs to be tested end to end—from the external link to the customer operation—before an incident.
Source: Selectel’s report dated 15 July 2026.
Primary source: Selectel: H1 2026 DDoS report


