Monday, March 17, 2025
HomePress ReleaseEuropean Cyber Report 2025: 137% More DDoS Attacks Than Last Year -...

European Cyber Report 2025: 137% More DDoS Attacks Than Last Year – What Companies Need to Know

Published on

SIEM as a Service

Follow Us on Google News

Cyberattacks are no longer an abstract threat – they dominate risk planning for companies worldwide.

The latest Link11 European Cyber Report shows an alarming trend: the number of DDoS attacks has more than doubled, and they are shorter, more targeted, and more technically sophisticated.

Organizations that do not continuously evolve their security strategies face significant financial losses and long-term reputational damage.

The numbers speak for themselves:

  •  137% more DDoS attacks on the Link11 network compared to last year.
  • A new scale has been reached: The largest attack measured to date was 1.4 terabits per second (Tbps).
  • Attacks are shorter and highly effective: Two-thirds of all attacks peaked in just 10 to 60 seconds.
  • Multi-vector attacks are setting new standards: The combination of different attack vectors makes defense more difficult and requires more precise protection.

Why organizations should act now

The Allianz Risk Barometer 2025 highlights that while digital transformation presents new opportunities, it also expands the attack surface for cyber threats.

Cybercriminals are leveraging powerful botnets and increasingly sophisticated attack techniques, accelerating the speed and impact of DDoS attacks.

A recent case demonstrates how these evolving threats are testing the resilience of organizations.

Multi-vector DDoS: When Network Load Meets Application Attacks

A four-day attack combined Layer 3/4 and Layer 7 techniques, putting both infrastructure and web applications under massive pressure.

Link11 recorded a total of 120 million requests, resulting in more than a million WAF logs – a load that quickly overwhelmed conventional defenses.

The attackers’ strategic approach was particularly striking:

  • Layer 3/4 attacks: Massive data streams overwhelm the network infrastructure.
  • Layer 7 attacks: APIs and web applications were deliberately crippled with complex queries.
  • Dynamic attack patterns: Attacks were launched in waves to test the response times of defenses.

Organizations that do not continuously adapt their IT security strategy risk becoming victims of targeted attacks.

Web applications and APIs are particularly targeted by cybercriminals because they often handle sensitive data and control critical business processes.

Modern security architecture is the key to resilience

The incident underscores the growing limitations of traditional DDoS defenses, emphasizing the need for more adaptive mitigation strategies.

Enterprises are increasingly turning to AI-powered systems for real-time threat detection and attack prevention.

Additionally, Web Application and API (WAAP) protection is gaining importance as attackers continue to exploit this critical attack vector.

Combining advanced protection solutions:

  • AI-based attack detection for early detection of suspicious patterns
  • Bot management to block automated attacks
  • Adaptive WAF systems that adapt in real time

A holistic security strategy combines advanced DDoS mitigation, continuous monitoring, and adaptive protection mechanisms.

“The increasing number of DDoS attacks shows that cybercriminals continue to rely on this proven method. However, the shortened attack time does not mean that the threat is decreasing – on the contrary: companies need to react faster and further optimize their defense mechanisms,” said Jens-Philipp Jung, CEO of Link11.

The full European Cyber Report 2025 can be downloaded here.

About Link11

Link11 is a specialized global IT security provider and protects infrastructures and web applications from cyberattacks.

Its cloud-based IT security solutions help companies worldwide to strengthen the cyber resilience of their networks and critical applications and avoid business disruption.

Link11 is a BSI-qualified provider for DDoS protection of critical infrastructure.

With ISO 27001 certification, the company meets the highest standards in data security.

Contact

Corporate Communications
Lisa Froehlich
Link11 GmbH
l.froehlich@link11.com
+49 16098088442

Kaaviya
Kaaviya
Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Latest articles

Kentico Xperience CMS Vulnerability Enables Remote Code Execution

In recent security research, vulnerabilities in the Kentico Xperience CMS have come to light,...

Wazuh SIEM Vulnerability Enables Remote Malicious Code Execution

A critical vulnerability, identified as CVE-2025-24016, has been discovered in the Wazuh Security Information...

Espressif Systems Flaws Allow Hackers to Execute Arbitrary Code

A series of vulnerabilities has been discovered in Espressif Systems' ESP32 devices, specifically affecting...

AI Operator Agents Helping Hackers Generate Malicious Code

Symantec's Threat Hunter Team has demonstrated how AI agents like OpenAI's Operator can now...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

INE Security Alert: Using AI-Driven Cybersecurity Training to Counter Emerging Threats

As Artificial Intelligence (AI)-powered cyber threats surge, INE Security, a global leader in cybersecurity...

Modat Launches Premier Product, Modat Magnify for Cybersecurity Professionals

Founded in 2024, Modat - the European-crafted, research-driven, AI-powered cybersecurity company, has announced the...

CYREBRO’s AI-Native MDR Platform Earns Silver at the 2025 Globee Cybersecurity Awards

CYREBRO, the AI-native Managed Detection and Response (MDR) solution, announced today that it won...