‘Attackers are steering their botnets with greater precision and control’: DDoS attack numbers might be dwindling, but they’re intensifying
While law enforcement efforts have had their effect, the rise in super-botnets and hijacked cloud servers has increased the intensity of attacks
While the number of distributed denial of service (DDoS) attacks on European organizations is falling, attacks have become more targeted and intense.
Findings from Link11's European Cyber Report for the first half of 2026 show that the number of attacks was down by 42%, but revealed new highs for attack intensity across bandwidth, packet rate, and cumulative data volume.
The highest measured bandwidth attack reached 2.3 Tbit/s – 85% higher than the previous peak of 1.2 Tbit/s in the first half of 2025.
The packet rate followed the same pattern, reaching a new peak of 322 million packets per second — up 56% from 207 million packets per second a year earlier.
Cumulative traffic also increased, rising from 438 to 705 terabytes over the six-month period — a 61% increase.
“Attacks are shorter, but the total volume that we had to mitigate is higher than ever," said Karsten Desler, Link11 CTO. "Attackers are steering their botnets with greater precision and control, generating more traffic in less time.”
Law enforcement takedowns are working
The drop in the number of attacks is down to sustained pressure from international law enforcement, including the takedown of pro-Russian group NoName057(16)'s infrastructure in July 2025.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Similarly, the takedown in March of the command-and-control servers of four major IoT botnets has played a key role. These controlled more than three million devices between them.
Despite positive gains by law enforcement, a rise in super-botnets such as Aisuru and its successor, Kimwolf, as well as a growing number of hijacked cloud servers, has increased the intensity of attacks.
Unlike a private IoT camera with just a few Mbit/s of upload bandwidth, a compromised server in a data center has a connection in the Gbit/s range - meaning that just a few thousand hacked cloud instances can easily eclipse the attack potential of an IoT botnet with millions of end devices.
“These numbers show that the threat isn't shrinking; it's shifting from breadth to peak intensity,” said Jens-Philipp Jung, CEO of Link11. “Organizations that size their defenses based on last year's attack count are underestimating how quickly a single incident can escalate today.”
No reprieve for victims
Notably, the report found that getting hit once makes it more likely that you'll get hit again: 56% fell victim to a second attack within 30 days of the first, compared with 46% a year earlier.
Link11 said the most dangerous attacks aren't always the most visible ones. In one case, attackers used a traffic spike against two domains as cover while quietly running SQL injection and cross-site scripting (XSS) probes behind it.
The attack was only spotted because the attackers used the same IP addresses for both.
"The most dangerous attacks we deal with are rarely the loudest ones anymore,” said Jag Bains, VP solution engineering, at Link11. “If you're only watching bandwidth and known signatures, you'll miss the attacks designed to do the most damage, because they're built to stay unnoticed.”
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Oracle expands HPE Juniper Networking deal to support AI infrastructure build-outNews The deal is aimed at supporting scale, performance, and availability as Oracle expands its AI superclusters
-
Yesterday’s triple AI outage should be a wake-up call for enterprisesNews Greater vendor transparency is needed in the wake of outages at OpenAI, Anthropic, and xAI
-
NCSC names and shames pro-Russia hacktivist group amid escalating DDoS attacks on UK public servicesNews Russia-linked hacktivists are increasingly trying to cause chaos for UK organizations
-
Cyber experts have been warning about AI-powered DDoS attacks – now they’re becoming a realityNews DDoS attackers are flocking to AI tools and solutions to power increasingly devastating attacks
-
Critical networks face unprecedented threat as DDoS attacks are getting shorter and more intensenews Attackers have stepped up their intrusions into core networks, according to Nokia's 11th annual Threat Intelligence Report
-
US authorities just took down 'one of the most powerful DDoS botnets to ever exist’ with help from AWSNews The Rapper Bot botnet was responsible for a series of large-scale DDoS attacks on government agencies and tech companies. Now it's gone.
-
Think DDoS attacks are bad now? Wait until hackers start using AI assistants to coordinate attacks, researchers warnNews The use of AI in DDoS attacks would change the game for hackers and force security teams to overhaul existing defenses
-
Application layer DDoS attacks are skyrocketing – here's whyNews The industry is seen as a prime target thanks to a reliance on online services and real-time transactions
-
DDoS attackers are pouncing on unpatched vulnerabilitiesNews Who needs a new attack vector when you can exploit old, public, and well-documented vulnerabilities?
-
Europol just took down 27 DDoS-for-hire sitesNews The festive period period usually sees a big bump in DDoS attacks - but this year may be a little safer