Link11 Releases European Cyber Report 2026: DDoS Attacks Become a Constant Threat
Frankfurt am Main, Germany, Mon, Mar 2, 2026
Frankfurt am Main, Germany, Mon, Mar 2, 2026
12,388 minutes of continuous attacks – more than eight days straight 509 terabytes of cumulative attack volume 70% of companies targeted in an initial attack are hit again
Link11 has published its European Cyber Report 2026 , highlighting that DDoS attacks reached unprecedented levels in 2025, presenting a constant challenge to digital infrastructures.
The report notes a 75% increase in documented attacks in the Link11 network for 2025, following a previous surge of 137%. This trend establishes DDoS attacks as a persistent issue for businesses and critical infrastructures in Europe.
DDoS attacks have increasingly become more severe, with multiple incidents surpassing 1 Tbit/s in 2025. The peak attack measured 1.33 Tbit/s, with over 120 million packets per second. A coordinated series of attacks amassed 509 terabytes of data, equivalent to the daily data traffic of a medium-sized city.
The report notes a 75% increase in documented attacks in the Link11 network for 2025, following a previous surge of 137%.
The duration of attacks is increasing, with the longest attack recorded lasting 12,388 minutes, equivalent to over eight days. In 2025, active DDoS attacks were documented 88% of the time, translating to 322 days of targeted attacks on Link11's network. The probability of follow-up attacks after an initial incident exceeds 70%, with an average of 2.8 subsequent attacks, marking an 80% increase from the previous year.
New Attack Tactics: A Hybrid of Volume, Endurance, and Precision
Attackers are employing a strategic combination of high-volume attacks and long-lasting scenarios, testing protective mechanisms, varying patterns, and shifting focus to the application level. Modern DDoS campaigns now combine extensive bandwidth with tactical patience, increasing their danger.
Rethinking Resilience: Combining Infrastructure and Application Levels
DDoS attacks now affect revenue, reputation, SLA commitments, and regulatory compliance. Beyond robust DDoS protection, securing web applications and APIs is critical. Modern attacks target Layer 7, mimicking legitimate traffic to degrade performance gradually without triggering alarms.
Web Application & API Protection (WAAP) is recommended for maintaining stable digital business processes, requiring a combination of network protection, behavior analysis, and AI-supported bot detection. Companies should integrate DDoS scenarios into business continuity plans to ensure digital availability and competitiveness.
Always-on DDoS protection WAAP solutions for web applications and APIs Automated, AI-powered detection and mitigation
Link11 is a European IT security provider offering protection against cyberattacks for global infrastructures and web applications. Its cloud-based solutions enhance network and application resilience, minimizing business interruptions. Link11 is a BSI-qualified provider of DDoS protection for critical infrastructure and holds PCI-DSS, SOC2 Type 2, C5, and ISO-27001 certifications.
Based on reporting by Cyber Security News.
