Link11 Report: European DDoS Attacks Fall 42% in Number but Peak at Record 2.3 Tbps

Link11 Report: European DDoS Attacks Fall 42% in Number but Peak at Record 2.3 Tbps

Link11 Report: European DDoS Attacks Fall 42% in Number but Peak at Record 2.3 Tbps

DDoS attackers in Europe are launching fewer campaigns but hitting far harder, according to Link11's European Cyber Report covering the first half of 2026, published September 3. The total number of DDoS attacks across the region fell by 42% compared to previous periods — while the maximum bandwidth of individual campaigns surged by 85%. The most significant event recorded was a 2.3 Tbps volumetric attack, accompanied by a peak packet-forwarding rate of 322 million packets per second.

Fewer Attacks, More Force

That divergence — fewer total attacks but unprecedented peak intensity — points to a strategic shift by threat actors. Instead of continuous, low-sophistication nuisance floods, adversaries are launching targeted, high-impact operations. Analysts attribute the escalation to the weaponization of "super-botnets" and the strategic hijacking of cloud computing environments, which provide the massive egress capacity needed to generate multi-terabit traffic streams. The traditional picture of IoT devices humming quietly in the background is giving way to compromised enterprise-grade cloud servers aggregating serious bandwidth.

The 322 Mpps figure matters as much as the terabit headline. High-packets-per-second attacks are specifically designed to exhaust the CPU and state tables of perimeter firewalls, routers, and load balancers — causing hardware failure even when total bandwidth capacity is never saturated. An attack does not have to fill your pipe to break your edge.

Extortion Economics

The drop in overall attack frequency suggests that DDoS-for-hire services and extortion syndicates are prioritizing quality over quantity: overwhelming "shock-and-awe" attacks that force immediate ransom payments from targeted organizations. For victims, a single well-executed multi-terabit event is more disruptive — and more monetizable — than months of background noise.

What Should You Do?

  1. Assume on-prem mitigation is not enough. On-premises DDoS appliances and standard ISP protections are structurally incapable of absorbing attacks exceeding 2 Tbps. Route traffic through cloud-native scrubbing networks with multi-terabit edge capacity.
  2. Stress-test both failure modes. Run DDoS simulations against volumetric exhaustion (Tbps) and state exhaustion (Mpps), and verify that failover routing and scrubbing activate without creating internal bottlenecks.
  3. Secure your own cloud workloads. Enforce outbound traffic rate limiting (egress filtering) and continuous monitoring across cloud environments so your infrastructure cannot be conscripted into a super-botnet.
  4. Rehearse the extortion conversation. Decide in advance who owns the decision not to pay, and how you communicate during an attack window measured in minutes.

The WAF Angle

Volumetric attacks are stopped upstream, not at the WAF — no application-layer appliance absorbs 2.3 Tbps. But the report's state-exhaustion finding is squarely in WAF territory: connection floods and high-PPS packet storms kill stateful middleboxes, and a WAF that chokes on connection pressure fails exactly when it is needed most. Architectures that separate L3/L4 scrubbing from L7 inspection, keep per-client connection and request limits tight, and behave predictably under state pressure will survive the "fewer but harder" era Link11 describes. The trend also matches what Cloudflare observed globally in the first half of 2026: terabit-class attacks are becoming routine, and planning for one is no longer paranoia.

Sources