EUROPEAN CYBER REPORT
MIDYEAR 2025
THE DYNAMIC THREAT SITUATION CONTINUES TO ESCALATE — THE DANGER IS INCREASING.
The threat posed by Distributed Denial-of-Service (DDoS) attacks intensified dramatically in the first half of 2025. The Link11 network recorded 225% more attacks than in the same period last year. Not only was there a massive increase in quantity, but also a qualitative development in the methods used to carry out the attacks. Looking at the last few months, the trend seems clear: the danger continues to grow unchecked.
Alarming Increase in Important Figures and Facts
-
143%
The rise of large-scale “ISP killer attacks” 
that threaten the infrastructure of 
providers or data centers.
-
438TB
The cumulative attack volume rose
massively from an initial 110 TB.

-
225%
DDoS attacks registered in the Link11 
network compared to the previous year.

Which trends you should pay particular attention to
-
Attacks are on the rise
The increase in DDoS attacks is the result of several factors, but is continuing to rise particularly due to global tensions. Two trends are driving the figures upward: more large attacks with higher peak values and an increase in many smaller attacks.
-
New type of attack emerges
A new form of Layer 7 attack has emerged in the form of so-called Yo-yo DDoS attacks. Yo-yo DDoS attacks target the auto-scaling functions of cloud infrastructures. Instead of permanently overloading systems, they generate alternating load peaks and quiet periods, causing instability and high costs.
-
Turbo attacks are decreasing
While we measured an increase in turbo attacks in the Link11 network in 2024, long, persistent attacks are playing an increasingly important role. The longest documented attack in the first half of 2025 lasted 12,388 minutes, or around eight days and 14 hours.
-
ISPs in the crosshairs
A worrying trend has been on the rise recently: more than twice as many attacks compared to last year were severe enough to paralyze backbone connections. Potential damage is more widespread and significantly more costly for providers and their customers.
-
Focus on ML and AI
Attackers use Artificial Intelligence and Machine Learning to detect and exploit vulnerabilities more quickly. At the same time, the number of unprotected IoT and smart home devices is growing, serving as an easily exploitable reservoir for automated botnets.
-
Attacks are shifting
The WAAP analysis shows sectoral shifts from H1 2024 to H1 2025: led by finance, the public sector, and retail & e-commerce, followed by defense, telecommunications, and healthcare. Attacks on defense, retail & e-commerce, and logistics & transportation increased particularly sharply.
ORIGIN OF DDOS TRAFFIC: GLOBAL DISTRIBUTION OF THE ATTACK INFRASTRUCTURE 2025
European Cyber Report Midyear 2025
The entire document is available for a free download below