Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • AI

Link11 Report: DDoS Attacks Surge 75% in 2025


Link11 Report: DDoS Attacks Surge 75% in 2025
  • by: Source Logo
  • |
  • March 3, 2026

Link11 has published its European Cyber Report 2026, documenting a dramatic escalation in DDoS attacks throughout 2025. The report reveals that DDoS has shifted from occasional disruptive incidents to a persistent structural burden on companies and critical infrastructures across Europe, with attack volumes, durations, and sophistication reaching new highs.

Quick Intel

  • Documented DDoS attacks in the Link11 network increased 75% in 2025, following a 137% surge the previous year.
  • Terabit-scale attacks became routine, with three exceeding 1 Tbit/s (peak at 1.33 Tbit/s and over 120 million packets per second).
  • A coordinated attack series transmitted 509 terabytes—equivalent to a medium-sized city's daily data traffic or 170,000 hours of HD video streaming.
  • Active attacks occurred 88% of the time (322 days per year), with the longest single attack lasting over eight days (12,388 minutes).
  • After an initial attack, there is over 70% probability of follow-ups, averaging 2.8 additional incidents—up 80% year-over-year.
  • Attackers increasingly combine high-volume floods with long-lasting low-and-slow tactics and application-layer (Layer 7) precision.
  • Modern DDoS campaigns require always-on protection, Web Application & API Protection (WAAP), AI-driven detection, and integration into business continuity planning.

The report highlights a paradigm shift: DDoS is no longer viewed as isolated events but as a continuous strategic pressure on digital business models. Attackers now test defenses systematically, adapt patterns in real time, and target application layers to mimic legitimate traffic, causing gradual degradation rather than immediate outages.

Explosive Growth in Volume and Scale 2025 marked the normalization of terabit attacks. While a single 1.4 Tbit/s incident stood out in 2024, multiple such events occurred in 2025, with the strongest reaching 1.33 Tbit/s and generating massive packet rates. Coordinated campaigns delivered unprecedented data volumes, underscoring the resources now available to attackers and the strain placed on even robust infrastructures.

From Short Bursts to Continuous Pressure Attack duration has become a defining characteristic. Systems in the Link11 network faced active DDoS activity for nearly the entire year, transforming emergency response into a default operational state. Follow-up attacks after an initial incident rose sharply, indicating coordinated, persistent campaigns designed to exhaust defenses over time.

Hybrid Tactics Demand New Defenses Attackers blend extreme bandwidth with endurance and precision, shifting focus to application-level vectors that evade traditional volumetric filters. This evolution requires layered protection: always-on network-level DDoS mitigation combined with behavior-based WAAP for APIs and web applications, plus AI-supported bot detection to identify subtle anomalies.

"We are experiencing a clear paradigm shift. DDoS is no longer a disruptive one-off event but rather a permanent strategic burden on digital business models," said Jens-Philipp Jung, founder and CEO of Link11. "Those who only react when an attack occurs have already lost. Resilience must be permanent, automated, and architecturally anchored."

"It's not just the size of an attack that matters anymore, but also its endurance and adaptability," Jung continued. "Modern DDoS campaigns combine extreme bandwidth with tactical patience. That is exactly what makes them so dangerous."

Strategic Recommendations for Cyber Resilience The report calls for a holistic security architecture that integrates:

  • Always-on DDoS protection rather than reactive measures
  • WAAP solutions to safeguard web applications and APIs
  • Automated, AI-powered detection and mitigation
  • Incorporation of DDoS scenarios into business continuity and crisis plans

"Digital availability is a competitive factor today," Jung emphasized. "Cyber resilience determines whether business models can withstand constant technological, operational, and geopolitical attacks."

 

About Link11 

Link11 is a specialized European IT security provider that protects global infrastructures and web applications from cyberattacks. Its cloud-based IT security solutions help companies worldwide strengthen the cyber resilience of their networks and critical applications and avoid business interruptions. Link11 is a BSI-qualified provider of DDoS protection for critical infrastructure. With PCI-DSS, SOC2 Type 2, C5, and ISO-27001 certifications, the company meets the highest standards in data security.

  • Cyber SecurityCyber Resilience
News Disclaimer
  • Share