The new Link11 European Cyber Report for the first half of 2026 provides a nuanced view: Although the decline in DDoS attacks on the Link11 network for European companies may sound like a reprieve at first, it’s clear that the attacks haven’t become less frequent. Rather, they’ve become more targeted and intense than ever before.
New records for bandwidth, packet rate, and data volume
Although the number of attacks decreased by 42%, record highs were reached in terms of attack intensity in every category. The highest measured bandwidth attack reached 2.3 Tbit/s – 85% higher than the previous peak of 1.2 Tbit/s in the first half of 2025.
The packet rate followed the same pattern, reaching a new peak of 322 million packets per second – up 56% from 207 million packets per second a year earlier. Cumulative traffic also increased, rising from 438 to 705 terabytes over the six-month period – a 61% increase.
Super-botnets drive the records, law enforcement curbs the count
The report attributes these records to super-botnets, such as Aisuru and its successor, Kimwolf, as well as a growing number of hijacked cloud servers. These servers individually push far more bandwidth than a compromised home router or camera ever could. The report credits the drop in raw attack numbers to sustained international law enforcement pressure, including the takedown of pro-Russian group NoName057(16)’s infrastructure in July 2025 during ‘Operation Eastwood.’ In March 2026, another blow followed: Authorities in the U.S., Canada, and Germany shut down the command-and-control servers of four major IoT botnets that collectively controlled more than three million devices.
“These numbers show that the threat isn’t shrinking; it’s shifting from breadth to peak intensity,” said Jens-Philipp Jung, CEO of Link11. “Organisations that size their defences based on last year’s attack count are underestimating how quickly a single incident can escalate today.”
Getting hit once makes it more likely to happen again
Being hit once also makes being hit again more likely: only 44% of targeted customers remained attack-free for 30 days after a wave in the first half of 2026, down from 54% a year earlier.
Noise as cover: the most dangerous attacks aren’t the loudest
Not every dangerous attack is a loud one. In one case documented in the report, attackers used a traffic spike against two domains as cover while quietly running SQL injection and cross-site scripting (XSS) probes behind it – a tactic exposed only because they reused the same IP addresses for both. “The most dangerous attacks we deal with are rarely the loudest ones anymore,” said Jag Bains, VP Solution Engineering, at Link11. “If you’re only watching bandwidth and known signatures, you’ll miss the attacks designed to do the most damage because they’re built to stay unnoticed.”
In short, in 2026, force and concealment determine the risk, not raw attack counts. Defences built around last year’s numbers are aimed at the wrong threat.
There’s plenty of other editorial on our sister site, Electronic Specifier! Or you can always join in the conversation by commenting below or visiting our LinkedIn page.
