Superbotnet and hijacked cloud servers set new records for bandwidth and packet rates as attack countdown continues under pressure from international law enforcement agencies
link 11 has released its European Cyber Report for the first half of 2026, offering insights into DDoS attack activity targeting European businesses. Despite a 42% decrease in DDoS attacks against Link11 networks, the report highlights a trend towards more targeted and intensified attacks, reaching new peaks in terms of bandwidth, packet rate, and cumulative data volume.
New records for bandwidth, packet rate, and data volume
Although the number of attacks has dropped by 42%, their intensity has reached unprecedented levels in all categories. The highest recorded bandwidth attack hit 2.3 Tbit/s, marking an 85% increase from the previous peak of 1.2 Tbit/s in early 2025.
Packet rates also soared to a new high of 322 million packets per second, up by 56% from 207 million packets per second a year ago. Cumulative traffic witnessed a 61% rise from 438 terabytes to 705 terabytes in six months.
Superbots set new records, law enforcement cracks down
The report attributes these records to superbotnets like Aisuru and Kimwolf, along with a rising number of hijacked cloud servers that individually generate more bandwidth than compromised home devices. The decrease in attacks is credited to ongoing international law enforcement efforts, including operations like NoName057 (16) during Operation Eastwood in July 2025. Further strikes in March 2026 led to the takedown of command and control servers for four major IoT botnets, overseeing over 3 million devices collectively.
“These figures demonstrate that the threat is not fading but rather intensifying to its maximum level,” stated Link11 CEO Jens Philipp Jung. “Organizations that base their defenses on last year’s attack numbers are underestimating how rapidly a single incident can escalate today.”
Once targeted, expect repeated attacks
Furthermore, being targeted once increases the likelihood of future attacks. Following the surge in the first half of 2026, only 44% of targeted customers remained attack-free for 30 days, down from 54% in the previous year.
Noisy attacks are not necessarily the most dangerous
Deadly attacks are not always the loudest. The report outlines a scenario where attackers used a traffic spike to two domains to silently execute SQL injection and cross-site scripting (XSS) probing. This strategy was identified due to both domains sharing the same IP address.
“We’re thrilled to collaborate with Link11,” remarked Jag Bains, VP of Solutions Engineering at Link11. “The most dangerous attacks we face are no longer the most audible ones. Focusing solely on bandwidth and known signatures may overlook destructive attacks designed to evade detection.”
This implies that in 2026, the combination of force and stealth will determine risk, not just the number of direct attacks. Defenses must be tailored to the evolving threat, not past statistics.
The complete report can be downloaded here.
About Link11
link 11 is a prominent European IT security provider safeguarding global infrastructure and web applications against cyber-attacks. Their cloud-based solutions enhance cyber resilience for networks and critical applications worldwide, preventing disruptions. Link11 is a BSI-certified DDoS protection provider for critical infrastructure, meeting top standards for data security and compliance with certifications like PCI DSS, SOC 2 Type II, BSI C5, and ISO 27001.
contact
Lisa Froehlich
Link11 GmbH
l.froehlich@link11.com
Source: www.nextbigfuture.com






