As civic space faces pressure in various parts of the world, the digital environment has become the main battlefield for ensuring transparency and fundamental rights.
Through Project Galileo โ a Cloudflare initiative that freely protects over 3,400 civic organizations in 120 countries โ the company published its 2026 Report on Cyberattacks Against Civil Society, mapping data collected between February 2025 and January 2026.
One of the main findings of the survey is the change in the dynamics of Distributed Denial of Service (DDoS) attacks at the application layer, which accounted for 81.7% of all malicious traffic recorded.
Below, we analyze the anatomy of these attacks and the impact of digital asymmetry on non-profit organizations.
- THE ANATOMY OF PROLONGED DDOS ATTACKS
Unlike the behavior observed in commercial companies โ where about 75% of DDoS attacks end in less than 10 minutes โ attacks against civil society are characterized by their extensive duration, extending for days or weeks:
Burst Strategy (Chunked Structure): Attackers send ostensible traffic in short intervals followed by deliberate pauses. This tactic causes dynamic system mitigation rules to expire during silent periods, forcing the defense infrastructure to re-analyze the threat from scratch with each new wave.
Rate Limit Reverse Engineering: Strategic pauses allow cybercriminals to identify which blocking rules have been activated and adjust malicious traffic signatures to operate just below the detection threshold.
- CASES OF GLOBAL IMPACT
The report highlights massive attacks targeting organizations with a critical role in ensuring rights:
Tech4Peace (Iraq): The digital rights organization suffered a DDoS attack that lasted eight continuous days in May 2025, accounting for 2.6 billion malicious requests. The attack occurred shortly after the publication of a fact-check debunking a politically charged AI-generated image.
Wahana Visi Indonesia: The humanitarian NGO faced a three-day offensive distributed across 13 traffic peaks, totaling 4.9 billion malicious requests and reaching a peak of 366,666 requests per second (rps).
Refugee Council (United Kingdom): The refugee support institution suffered an attack that extended for seven days and 15 hours, keeping the infrastructure under constant pressure.
CONCLUSION: THE IMPACT OF CONTINUOUS THREATS
The deliberate extension of DDoS attacks demonstrates a clear attempt to exhaust the operational resources and technical defenses of entities providing essential services to the population.
Neutralizing these threats requires the presence of global reverse networks capable of absorbing and filtering continuous bursts of traffic without taking down the original platforms.
Official sources and references:
- Official Report "2026 Cloudflare Report on Cyberattacks Against Civil Society" โ Project Galileo & Cloudflare Research.
- Traffic Mitigation Data and Case Studies (Tech4Peace, Wahana Visi) โ Cloudflare Radar.
This article was supported by artificial intelligence through Gemini (Google) in the development of its editorial structure.
