European DDoS Attacks Reach Record Intensity as Superbotnets and Hijacked Cloud Servers Drive New Bandwidth Peaks
Link11 has published its European Cyber Report for the first half of 2026, highlighting the latest trends in distributed denial-of-service (DDoS) attacks targeting European organizations. While the total number of DDoS attacks against Link11-protected networks fell by 42%, the attacks that did occur were more targeted, sophisticated, and powerful.
Attack intensity reached record levels across bandwidth, packet rate, and total traffic volume, demonstrating that organizations must prepare for fewer but significantly more disruptive cyberattacks.
DDoS attack bandwidth, packet rates, and data volumes reach new records
Despite the 42% decline in the overall number of attacks, DDoS attack intensity reached an all-time high across every major measurement category. The largest recorded bandwidth attack peaked at 2.3 Tbit/s—85% higher than the previous record of 1.2 Tbit/s, recorded in early 2025.
Packet rates also reached a new high of 322 million packets per second, representing a 56% increase from 207 million packets per second during the same period last year. Total attack traffic rose from 438 terabytes to 705 terabytes in six months, an increase of 61%.
Superbotnets and compromised cloud servers fuel larger DDoS attacks
According to the report, the record-breaking attacks were driven by superbotnets such as Aisuru and its successor, Kimwolf, along with a growing number of hijacked cloud servers. Compared with compromised home routers and internet-connected cameras, cloud servers can generate significantly greater bandwidth and packet volumes individually.
Link11 attributes the decline in the overall number of attacks to sustained international law enforcement efforts. These include the disruption of infrastructure operated by the pro-Russian group NoName057 (16) during Operation Eastwood in July 2025. Further action followed in March 2026, when authorities in the United States, Canada, and Germany took down command-and-control servers linked to four major IoT botnets. Together, the botnets were reported to have controlled more than 3 million devices.
“These numbers show that the threat is not diminishing, but rather that it is moving from widespread to maximum intensity,” said Link11 CEO Jens Philipp Jung. “Organizations that size their defenses based on last year’s number of attacks underestimate how quickly a single incident can escalate today.”
Organizations targeted by DDoS attacks face a higher risk of repeat attacks
Organizations that experience a DDoS attack are also more likely to be targeted again. Following the attack activity recorded during the first half of 2026, only 44% of affected customers remained attack-free for 30 days. This compares with 54% during the same period last year.
The most dangerous cyberattacks are not always the loudest
High-volume attacks can also be used to conceal more targeted and damaging activity. In one case described in the report, attackers generated a traffic spike against two domains while quietly conducting SQL injection and cross-site scripting (XSS) reconnaissance. The activity was identified only because both attacks reused the same IP address.
“We’re excited to partner with Link11,” said Jag Bains, VP of Solutions Engineering at Link11. “The most dangerous attacks we deal with are no longer the loudest ones. If you only monitor bandwidth and known signatures, you will miss attacks designed to cause the most damage while remaining undetected.”
The findings show that, in 2026, the scale and stealth of an attack are more important indicators of risk than the total number of incidents. Cybersecurity strategies based solely on last year’s attack volumes may leave organizations unprepared for today’s high-intensity DDoS attacks and concealed application-layer threats.
The full Link11 European Cyber Report for the first half of 2026 is available for download here.
About Link11
Link11 is a leading European IT security provider that protects infrastructure, networks, and web applications from cyberattacks worldwide. Its cloud-based cybersecurity solutions help organizations improve cyber resilience, protect critical applications, and reduce the risk of business interruptions.
Link11 is a BSI-certified provider of DDoS protection for critical infrastructure. With PCI DSS, SOC 2 Type II, BSI C5, and ISO 27001 certifications, the company meets rigorous international standards for data security, compliance, and operational resilience.
Contact
Lisa Froehlich
Link11 GmbH
[email protected]
Source: www.nextbigfuture.com


