In the first half of 2026, European organizations experienced unprecedented levels of Distributed Denial of Service (DDoS) attack intensity, even as the total number of such incidents declined. Link11, a prominent IT security firm, highlighted these developments in its latest European Cyber Report, released from Frankfurt, Germany.
Surge in Attack Intensity Despite Fewer Incidents
Link11’s report reveals a 42% drop in the number of DDoS attacks on its network. However, this reduction in frequency has been offset by a significant rise in attack intensity. Metrics such as bandwidth, packet rate, and cumulative data volume have hit new peaks, indicating a strategic shift towards more potent, targeted cyber assaults.
The report documents a record-breaking attack in bandwidth, reaching 2.3 Tbit/s, which marks an 85% increase over the previous high of 1.2 Tbit/s recorded in early 2025. Similarly, the packet rate soared to 322 million packets per second, up 56% from last year’s 207 million. Furthermore, cumulative data traffic surged by 61%, escalating from 438 to 705 terabytes within six months.
Role of Super-Botnets and Cloud Servers
These amplified attack intensities are largely attributed to the growing influence of super-botnets, such as Aisuru and Kimwolf, and the exploitation of hijacked cloud servers. The report notes that these servers can deliver greater bandwidth compared to compromised household devices.
Despite the rise in attack potency, the overall drop in attack numbers is credited to global law enforcement efforts. Notable actions include the dismantling of NoName057(16)’s infrastructure in July 2025 and the shutdown of major IoT botnets in March 2026, coordinated by authorities in the U.S., Canada, and Germany.
Changing Nature of Cyber Threats
Jens-Philipp Jung, CEO of Link11, emphasized the evolving nature of cyber threats. “The shift from frequent attacks to high-intensity incidents requires organizations to reassess their defensive strategies,” he explained.
The report further highlights that companies struck by DDoS attacks once are more likely to face subsequent incidents. Only 44% of affected customers remained attack-free for 30 days following an initial wave in 2026, a decrease from 54% the previous year.
Subtle Threats: The Real Danger
According to Jag Bains, VP of Solution Engineering at Link11, the most damaging attacks are not necessarily the most conspicuous. The report cites instances where attackers deployed surges in traffic to obscure more covert operations like SQL injection and cross-site scripting (XSS), revealing the necessity for comprehensive security measures beyond monitoring bandwidth alone.
In conclusion, the year 2026 underscores the importance of adapting cybersecurity defenses to confront increasingly sophisticated threats. As attack strategies evolve, organizations must prioritize resilience against both overt and covert cyber threats.
The complete Link11 report is available for download, offering further insights into these trends.
About Link11: As a leading European IT security provider, Link11 specializes in safeguarding global infrastructures and web applications from cyber threats through advanced cloud-based solutions. The company is recognized for its compliance with high standards such as PCI DSS, SOC 2 Type II, BSI C5, and ISO 27001.
