GBHackers

Fewer attacks, more force: Link11’s European Cyber Report finds new DDoS records for the first half of 2026


Frankfurt am Main, Germany, September 3rd, 2026, CyberNewswire

Super-botnets and hijacked cloud servers drive new bandwidth and packet-rate records as international law-enforcement pressure pushes attack counts down

Link11 has released its European Cyber Report for the first half of 2026, providing an overview of DDoS attack activity targeting European companies.

Although the number of DDoS attacks on the Link11 network decreased by 42 percent, the report records new highs for attack intensity across bandwidth, packet rate and cumulative data volume, indicating that attacks have become more targeted and intense.

New Records for Bandwidth, Packet Rate, and Data Volume

Although the number of attacks decreased by 42 percent, record highs were reached in terms of attack intensity in every category.

The highest measured bandwidth attack reached 2.3 Tbit/s—85 percent higher than the previous peak of 1.2 Tbit/s in the first half of 2025.

The packet rate followed the same pattern, reaching a new peak of 322 million packets per second — up 56 percent from 207 million packets per second a year earlier.

Cumulative traffic also increased, rising from 438 to 705 terabytes over the six-month period — a 61 percent increase.

Super-Botnets Drive the Records, Law Enforcement Curbs the Count

The report attributes these records to super-botnets, such as Aisuru and its successor, Kimwolf, as well as a growing number of hijacked cloud servers.

These servers individually push far more bandwidth than a compromised home router or camera ever could.

The report credits the drop in raw attack numbers to sustained international law enforcement pressure, including the takedown of pro-Russian group NoName057(16)’s infrastructure in July 2025 during “Operation Eastwood.”

In March 2026, another blow followed: Authorities in the U.S., Canada, and Germany shut down the command-and-control servers of four major IoT botnets that collectively controlled more than three million devices.

“These numbers show that the threat isn’t shrinking; it’s shifting from breadth to peak intensity,” said Jens-Philipp Jung, CEO of Link11.

“Organizations that size their defenses based on last year’s attack count are underestimating how quickly a single incident can escalate today.”

Getting Hit Once Makes It More Likely to Happen Again

Being hit once also makes being hit again more likely: only 44 percent of targeted customers remained attack-free for 30 days after a wave in the first half of 2026, down from 54 percent a year earlier.

Noise as Cover: The Most Dangerous Attacks Aren’t the Loudest

Not every dangerous attack is a loud one. In one case documented in the report, attackers used a traffic spike against two domains as cover while quietly running SQL injection and cross-site scripting (XSS) probes behind it a tactic exposed only because they reused the same IP addresses for both.

“The most dangerous attacks we deal with are rarely the loudest ones anymore,” said Jag Bains, VP Solution Engineering, at Link11.

“If you’re only watching bandwidth and known signatures, you’ll miss the attacks designed to do the most damage because they’re built to stay unnoticed.”

In short, in 2026, force and concealment determine the risk, not raw attack counts. Defenses built around last year’s numbers are aimed at the wrong threat.

The full report will be available for download here. 

About Link11 

Link11 is a leading European IT security provider that protects global infrastructures and web applications against cyberattacks.

Its cloud-based IT security solutions help companies worldwide strengthen the cyber resilience of their networks and critical applications and avoid business disruptions.

Link11 is a BSI-qualified provider for the DDoS protection of critical infrastructure.

With PCI DSS, SOC 2 Type II, BSI C5 and ISO 27001, the company meets the highest standards in data security and compliance. 

Lisa Froehlich

Link11 GmbH

[email protected]



Source link