Frankfurt am Essential, Germany, September third, 2026, CyberNewswire
Tremendous-botnets and hijacked cloud servers drive new bandwidth and packet-rate information as worldwide law-enforcement strain pushes assault counts down
Link11 has launched its European Cyber Report for the primary half of 2026, offering an summary of DDoS assault exercise concentrating on European corporations.
Though the variety of DDoS assaults on the Link11 community decreased by 42 p.c, the report information new highs for assault depth throughout bandwidth, packet price and cumulative knowledge quantity, indicating that assaults have turn out to be extra focused and intense.
New Information for Bandwidth, Packet Charge, and Knowledge Quantity
Though the variety of assaults decreased by 42 p.c, document highs had been reached when it comes to assault depth in each class.
The best measured bandwidth assault reached 2.3 Tbit/s—85 p.c greater than the earlier peak of 1.2 Tbit/s within the first half of 2025.
The packet price adopted the identical sample, reaching a brand new peak of 322 million packets per second — up 56 p.c from 207 million packets per second a 12 months earlier.
Cumulative visitors additionally elevated, rising from 438 to 705 terabytes over the six-month interval — a 61 p.c improve.
Tremendous-Botnets Drive the Information, Legislation Enforcement Curbs the Rely
The report attributes these information to super-botnets, similar to Aisuru and its successor, Kimwolf, in addition to a rising variety of hijacked cloud servers.
These servers individually push way more bandwidth than a compromised residence router or digital camera ever may.
The report credit the drop in uncooked assault numbers to sustained worldwide regulation enforcement strain, together with the takedown of pro-Russian group NoName057(16)’s infrastructure in July 2025 throughout “Operation Eastwood.”
In March 2026, one other blow adopted: Authorities within the U.S., Canada, and Germany shut down the command-and-control servers of 4 main IoT botnets that collectively managed greater than three million units.
“These numbers present that the menace isn’t shrinking; it’s shifting from breadth to peak depth,” stated Jens-Philipp Jung, CEO of Link11.
“Organizations that measurement their defenses primarily based on final 12 months’s assault rely are underestimating how shortly a single incident can escalate in the present day.”
Getting Hit As soon as Makes It Extra Prone to Occur Once more
Being hit as soon as additionally makes being hit once more extra probably: solely 44 p.c of focused prospects remained attack-free for 30 days after a wave within the first half of 2026, down from 54 p.c a 12 months earlier.
Noise as Cowl: The Most Harmful Assaults Aren’t the Loudest
Not each harmful assault is a loud one. In a single case documented within the report, attackers used a visitors spike in opposition to two domains as cowl whereas quietly working SQL injection and cross-site scripting (XSS) probes behind it a tactic uncovered solely as a result of they reused the identical IP addresses for each.
“Essentially the most harmful assaults we take care of are not often the loudest ones anymore,” stated Jag Bains, VP Resolution Engineering, at Link11.
“If you happen to’re solely watching bandwidth and recognized signatures, you’ll miss the assaults designed to do essentially the most harm as a result of they’re constructed to remain unnoticed.”
In brief, in 2026, drive and concealment decide the chance, not uncooked assault counts. Defenses constructed round final 12 months’s numbers are aimed on the mistaken menace.
The total report shall be accessible for obtain right here.
About Link11
Link11 is a number one European IT safety supplier that protects world infrastructures and internet functions in opposition to cyberattacks.
Its cloud-based IT safety options assist corporations worldwide strengthen the cyber resilience of their networks and significant functions and keep away from enterprise disruptions.
Link11 is a BSI-qualified supplier for the DDoS safety of crucial infrastructure.
With PCI DSS, SOC 2 Sort II, BSI C5 and ISO 27001, the corporate meets the very best requirements in knowledge safety and compliance.
Lisa Froehlich
Link11 GmbH









