#034
2026-09-06

Attacks Down 42%, Intensity at Record Highs: DDoS Is Getting Fewer, Stronger, Quieter

📰 Want to see more news?
Browse full news list

Link11's freshly published H1 2026 European Cyber Report contains a striking pair of contradictions: DDoS attack counts dropped 42%, yet every intensity metric set a new record. Peak single-attack bandwidth reached 2.3 Tbit/s (85% higher than the 1.2 Tbit/s peak of H1 2025), packet rate hit 322 million pps (+56%), and half-year cumulative traffic climbed to 705 TB (+61%). The threat didn't disappear — it changed tactics, moving from "spray-and-pray volume" to "precision heavy artillery."

Why fewer attacks, but far more destructive

The report attributes the shift to two forces. First, super-botnets: massive botnets like Aisuru and its successor Kimwolf, plus a growing number of hijacked cloud servers — a single hijacked cloud box can push far more bandwidth than thousands of home routers and cameras. Attackers no longer need huge weak bot swarms; a handful of high-bandwidth cloud zombies is enough to push a single event into Tbit/s territory.

Second, law enforcement actually suppressed the count: the July 2025 "Operation Eastwood" takedown of NoName057(16) infrastructure, and the March 2026 US-Canada-Germany joint shutdown of C2 servers controlling four major IoT botnets managing over three million devices. Volume is down — but what remains is the more professional, better-funded cohort.

The number that should worry you: hit once, hit again

Easily overlooked in the report: only 44% of targeted customers stayed attack-free for 30 days after a wave (down from 54% a year ago). Attackers mark targets they've hit — your IPs, your services, your weaknesses are noted. The first wave is never "over"; it's a probe. The highest-damage attacks tend to come later.

The deadliest attacks are the quietest

One documented case: attackers used a traffic spike against two domains as a smokescreen while quietly running SQL injection and XSS probes from the same IP pool. The only reason it was caught was that the same IP addresses were reused for both — a lazy shortcut, not a detection win.

This is the 2026 reality for defenders: watching bandwidth and matching known signatures will miss the attacks engineered to stay quiet — because their design goal is invisibility, and the damage detonates later.

What this means for your defenses

💡 LAFA Perspective

2026 attack logic is "fewer, stronger, quieter, meaner." Lafa System's military-grade high-defense WAF stops the heavy artillery at the edge, while AI 24/7 automated analysis catches stealth probes at the application layer — the 30-day high-risk window after an attack is exactly when around-the-clock automated defense matters most.