Frankfurt am Main, Germany, September 3rd, 2026, CyberNewswire
In a significant development concerning cyber threats in Europe, Link11 has published its European Cyber Report for the first half of 2026. This report sheds light on the shifting dynamics of DDoS (Distributed Denial of Service) attacks targeting European enterprises. While it highlights a dramatic 42 percent drop in the number of attacks on Link11’s network, it simultaneously records unprecedented highs in attack intensity, particularly in terms of bandwidth, packet rates, and cumulative data volume. This juxtaposition illustrates a worrisome evolution in the sophistication and targeting of cyber-attacks.
New Records for Bandwidth, Packet Rate, and Data Volume
Despite the notable decline in attack frequency, the metrics of intensity reached staggering new heights across various parameters. The report indicates that the most intense attack measured during this period achieved a bandwidth of 2.3 Tbit/s. This figure represents a remarkable 85 percent increase from the previous high of 1.2 Tbit/s recorded in the first half of 2025. This substantial rise in bandwidth emphasizes a troubling shift towards more aggressive and powerful cyber-attacks.
In addition to bandwidth, the report noted a corresponding increase in packet rates, which surged to a new record of 322 million packets per second—an increase of 56 percent compared to the 207 million packets per second observed just a year ago. Furthermore, cumulative data traffic skyrocketed from 438 terabytes to 705 terabytes over the six-month period, marking a staggering 61 percent surge.
Super-Botnets Drive the Records, Law Enforcement Curbs the Count
The surge in intensity has been attributed to the rise of super-botnets—specifically, botnets such as Aisuru and its successor, Kimwolf. The report underscores the growing reliance on hijacked cloud servers, which are capable of delivering significantly higher bandwidth than compromised home routers or cameras, which have traditionally been exploited in such attacks.
Link11 attributes the decrease in raw attack numbers to sustained efforts from international law enforcement agencies. Notably, the dismantling of the pro-Russian group NoName057(16)’s infrastructure in July 2025 during “Operation Eastwood” played a pivotal role in disrupting cybercriminal activities. Additionally, in March 2026, a coordinated effort among U.S., Canadian, and German authorities led to the shutdown of command-and-control servers belonging to four significant IoT botnets, which collectively managed over three million devices.
Jens-Philipp Jung, CEO of Link11, articulated the evolving nature of the threat landscape, remarking, “These numbers show that the threat isn’t shrinking; it’s shifting from breadth to peak intensity.” He cautioned organizations against relying solely on previous year’s attack counts for their defenses, warning that the rapid escalation of attacks can catch unprepared entities off guard.
Getting Hit Once Makes It More Likely to Happen Again
Link11’s findings also revealed a disheartening trend in vulnerability. Only 44 percent of targeted customers managed to remain attack-free for 30 days following an initial wave of attacks in the first half of 2026, a decline from 54 percent the previous year. This statistic underscores the increased likelihood of repeat incidents and highlights the need for enhanced vigilance among organizations.
Noise as Cover: The Most Dangerous Attacks Aren’t the Loudest
The report further cautioned that not all threats are easily detectable. In one documented case, attackers employed a traffic spike against two domains as a distraction, while simultaneously conducting silent SQL injection and cross-site scripting (XSS) attempts. This tactic was exposed only because the attackers reused the same IP addresses for both the loud and covert operations.
Jag Bains, Vice President of Solution Engineering at Link11, observed, “The most dangerous attacks we deal with are rarely the loudest ones anymore.” He emphasized the importance of comprehensive threat monitoring, cautioning that focusing solely on bandwidth and recognized attack signatures could result in missing these cleverly concealed threats.
A Shift in Strategic Focus
In summary, the 2026 landscape of cyber threats reveals a transformation where force and subterfuge define risk levels more than raw attack counts ever could. Organizations must adapt their defenses accordingly or risk being caught unaware. The findings of Link11’s report reflect a harsh reality—cyber defenses rooted in outdated metrics are ill-equipped to handle the modern landscape of rapidly intensifying cyber threats.
The full report is available for download here.
About Link11
Link11 stands as a prominent European IT security provider, safeguarding global infrastructures and web applications against cyberattacks. Its cloud-based security solutions empower companies to bolster the cyber resilience of their networks while mitigating disruptions. Link11 is recognized as a BSI-qualified provider for DDoS protection of essential infrastructure, adhering to the highest standards of data security and compliance, including PCI DSS, SOC 2 Type II, BSI C5, and ISO 27001.
For additional inquiries, stakeholders may contact Lisa Froehlich at Link11 GmbH at [email protected].
.webp)