DDoS Attacks Intensify Despite Volume Drop, Link11 Report Reveals
Link11's H1 2026 European Cyber Report indicates a 42% decrease in DDoS attack volume, but new records in intensity driven by super-botnets and compromised cloud servers.

Link11's latest European Cyber Report for the first half of 2026 highlights a significant shift in Distributed Denial of Service (DDoS) attack trends. While the overall volume of attacks decreased by 42 percent compared to the previous year, the intensity of these attacks reached unprecedented levels. This indicates a strategic move by threat actors from broad-based assaults to more targeted and potent strikes.
The report details new records in key attack metrics. The highest measured bandwidth attack surged to 2.3 Tbit/s, an 85 percent increase over the previous H1 2025 peak. Similarly, the packet rate peaked at 322 million packets per second, a 56 percent jump from the prior year's 207 million packets per second. Cumulative data volume also saw a substantial rise, increasing by 61 percent from 438 to 705 terabytes over the six-month period.
These record-breaking intensities are largely attributed to the increasing sophistication and power of "super-botnets." The report specifically names Aisuru and its successor, Kimwolf, as major contributors. Furthermore, a growing number of compromised cloud servers are being leveraged, as these can individually push far more bandwidth than traditional compromised devices like home routers or IoT cameras.
Despite the rise in attack intensity, the reduction in raw attack counts is credited to sustained international law enforcement efforts. Notable operations mentioned include "Operation Eastwood," which targeted the infrastructure of the pro-Russian group NoName057(16) in July 2025, and a March 2026 crackdown by authorities in the U.S., Canada, and Germany that dismantled the command-and-control servers of four major IoT botnets, collectively controlling over three million devices.
Link11 CEO Jens-Philipp Jung emphasized this evolving threat landscape, stating, "Organizations that size their defenses based on last year's attack count are underestimating how quickly a single incident can escalate today." The report also notes a concerning trend: customers who have been attacked once are more likely to be targeted again. In H1 2026, only 44 percent of targeted customers remained attack-free for 30 days post-attack, a decrease from 54 percent a year earlier.
Beyond the sheer volume and bandwidth, the report warns that the most dangerous attacks are not always the loudest. Attackers are increasingly using traffic spikes as cover for more insidious activities, such as SQL injection and cross-site scripting (XSS) probes. This tactic was identified when attackers reused the same IP addresses for both the disruptive traffic and the covert probes, highlighting the need for defenses that look beyond simple bandwidth monitoring.
"The most dangerous attacks we deal with are rarely the loudest ones anymore," commented Jag Bains, VP Solution Engineering at Link11. "If you're only watching bandwidth and known signatures, you'll miss the attacks designed to do the most damage because they're built to stay unnoticed." This underscores a critical shift in attacker methodology, prioritizing stealth and precision over brute-force disruption.
In conclusion, the Link11 report signals a new era of DDoS threats where force and concealment, rather than raw attack volume, define the risk. Organizations must adapt their defenses to account for these more sophisticated, intense, and stealthy attacks, moving beyond metrics based on historical attack counts.