TMWTMW Global NetworksTMW Global Networks
Back to attack reports

Attack Reports

TMW Attack Report, July 2026

2026-08-20 · 4 min

817 mitigated events in the latest 30-day Shield window. UDP Flood led with 52% of attacks. Peak intensity reached 55.9 Mpps. Destination addresses are omitted.

  • 817 attacks mitigated in the 30-day window
  • Peak intensity: 55.9 Mpps
  • Leading vector: UDP Flood, 423 events (52%)
  • UDP carried 85% of events; TCP 15%

What Shield handled in 30 days.

Last 30 days · All mitigated

attacks

817

Last 30 days

Leading vector

UDP Flood

423 events, 52% of the window

Dominant transport

UDP

691 events, 85% of the window

Peak intensity

55.9 Mpps

Highest packet rate observed in the window

Attack type

817

attacks

Last 30 days

  • UDP Flood423 · 52%
  • UDP Fragmentation203 · 25%
  • TCP SYN62 · 8%
  • Fragment Flood56 · 7%
  • TCP ACK-PSH Flood25 · 3%
  • Other46 · 6%

Transport

Protocol family share

817 attacks

UDP 85%
TCP 15%
  • UDP691 · 85%
  • TCP125 · 15%
  • ICMP1 · <1%

Top ports

Most targeted service ports

  • 80 HTTP32 attacks
  • 443 HTTPS29 attacks
  • 25565 Minecraft27 attacks
  • 25572 Game service18 attacks
  • 22 SSH18 attacks

Peak packet rate

Highest observed intensity. Destinations omitted.

55.9 Mpps

#1

46.9 Mpps

#2

15.3 Mpps

#3

11.9 Mpps

#4

11.0 Mpps

#5

Target mix

Share of events by destination rank. Addresses are not published.

  1. Rank 1

    428

    52%

  2. Rank 2

    47

    6%

  3. Rank 3

    43

    5%

  4. Rank 4

    31

    4%

  5. Rank 5

    30

    4%

  6. All others

    238

    29%

Executive summary

The latest TMW Shield panel window recorded 817 mitigated events. Most pressure was volumetric UDP: floods and fragmentation together were 77% of attacks.

A single destination accounted for 52% of events. Peak packet rate in the window was 55.9 Mpps, far above what origin firewalls can absorb without edge scrubbing. Customer destination addresses are not published.

Vector and transport mix

UDP Flood 423 (52%), UDP Fragmentation 203 (25%), TCP SYN 62 (8%), Fragment Flood 56 (7%), TCP ACK-PSH Flood 25 (3%), other 46 (6%).

By protocol family: UDP 691 (85%), TCP 125 (15%), ICMP 1 (under 1%).

Ports and intensity

The most targeted service ports were HTTP 80 (32 attacks), HTTPS 443 (29), Minecraft 25565 (27), game port 25572 (18), and SSH 22 (18).

The five highest packet-rate events ranged from 11.0 Mpps to 55.9 Mpps. Destinations for those events are omitted.

Recommendations

Keep always-on Shield on prefixes that host UDP games or voice. UDP floods and fragments were the bulk of this window.

Restrict SSH and admin surfaces. Port 22 was among the five most targeted services.

Do not size origin firewalls for 50 Mpps events. That intensity belongs at the scrubbing edge.

Need help interpreting your own attack telemetry or designing filter policy? Our NOC publishes these reports to help operators prepare before the next flood.

Contact engineering
TMW Global Networks

Carrier-grade DDoS protection, IP transit, and hosting for networks that need direct operational support.

All systems operational

Hosting

  • Dedicated Servers
  • Cloud VPS
  • KVM Server
  • IP-Transit
  • Network
  • BGP Communities
  • Colocation

Services

  • TMW Shield
  • TMW CDN / Proxy
  • On-Prem
  • Filter Profiles
  • Status page

Guides

  • Guides
  • FAQ
  • Attack Reports
  • Case Studies
  • What is a Cloud Server?
  • What is a VPS?
  • What is DDoS Protection?
  • TCP & UDP Ports Explained
  • TCP/IP Explained

Company

  • Solutions
  • About
  • DDoS Frankfurt
  • abuse@t-w.dev
  • noc@t-w.dev
  • Contact
  • Under Attack?

© 2026 TMW Global Networks. All rights reserved.

ImprintPrivacyTermsTMW Shield Terms