Summary
- Link11 says DDoS attack numbers across its own network fell 42% in the first half of 2026.
- Its largest measured attack reached 2.3 Tbit/s, while peak packet rates reached 322 million packets per second.
- The findings describe Link11 telemetry rather than the entire European threat landscape and should be read as a vendor dataset.
Distributed denial-of-service activity recorded by Link11 fell sharply during the first half of 2026, but the attacks that remained reached substantially higher peaks in bandwidth, packet rate, and cumulative traffic.
The German security provider’s latest European Cyber Report says the number of DDoS attacks observed on its network dropped by 42% compared with the previous period. At the same time, its largest measured attack reached 2.3 Tbit/s, up from a peak of 1.2 Tbit/s in the first half of 2025.
Peak packet rates rose from 207 million packets per second to 322 million, while cumulative attack traffic across the six-month period increased from 438 terabytes to 705 terabytes.
The figures point to a change in the shape of the activity visible to Link11 rather than evidence that DDoS risk across Europe has risen or fallen by the same proportions. The dataset covers traffic handled by the company’s own infrastructure and customers, making it useful operational telemetry but not a census of all attacks against European organisations.
That distinction becomes important when interpreting the 42% reduction in attack numbers. Link11 attributes part of the decline to international law-enforcement action against botnet and hacktivist infrastructure, while linking the higher peaks to large botnets and compromised cloud servers capable of generating considerably more traffic than individual consumer devices.
Cloud infrastructure changes the economics of volumetric attacks because a relatively small number of compromised or abused high-capacity systems can contribute more traffic than much larger collections of low-bandwidth devices. The result is a resilience problem that cannot be understood solely by counting incidents.
The peak bandwidth figure is only one dimension. Packet-per-second attacks can exhaust processing capacity in network equipment even when raw bandwidth is not saturated, while sustained or repeated attacks create a different operational burden from a brief traffic spike. Infrastructure planning therefore has to account for several resource constraints rather than a single headline throughput number.
Link11 also documented a case in which a traffic spike against two domains coincided with SQL injection and cross-site scripting probes from the same source addresses. The finding is based on the company’s own observations and does not establish that such mixed activity is widespread, but it illustrates why a DDoS event can complicate monitoring beyond availability alone.
The report comes amid continued law-enforcement activity against botnet infrastructure. Disruptions can reduce the resources available to specific operators without removing the underlying market for compromised devices, rented infrastructure, and attack services. Large botnets can also be rebuilt or replaced, while cloud capacity can create new sources of attack traffic.
For operators of customer-facing platforms, communications infrastructure, and other availability-sensitive services, the most consequential change is therefore the increasing spread between attack frequency and potential peak load. A quieter six months in incident count does not necessarily justify reducing capacity assumptions if individual attacks can impose significantly greater pressure.
Link11’s figures should remain framed as one provider’s telemetry. They nonetheless show why resilience planning based only on the number of attacks recorded in the previous year can miss changes in the resources attackers are able to mobilise and the load a single event can impose.





