The 2026 ENISA Threat Landscape confirms that cyber dependencies expand the attack surface and require a new level of vigilance to effectively prevent and mitigate the impact of cyber incidents.
The cyber threat landscape of the European Union is still shaped by a combination of recurrent threats. Key highlights include:
- Ransomware remains the most short-term impactful type of incident.
- Geopolitical developments still influence cyber activity affecting the EU with hacktivist-led DDoS campaigns targeting essential entities.
- Public administration continues to be is the most targeted sector.
- Organisations across the EU are likely to continue facing a combination of cybercrime, cyberespionage and hacktivist activity driven by geopolitical developments.
- Emerging AI models are expected to be increasingly used to support malicious operations.
To shape our understanding of the cyber threat landscape and the dynamics at work, ENISA collected and analysed incidents and events observed from 1 January to 31 December 2025 for this new edition of the Threat Landscape. Those events were gathered from open sources, as well as anonymised information shared by EU Member States and through the ENISA Cyber Partnership Programme.
ENISA’s Executive Director Juhan Lepassaar said: “The ENISA threat landscape is more than a list of cybersecurity threats affecting the EU and how they are distributed around sectors and entities. The analysis highlights how threats become more interconnected and how threat groups spread their impact across the larger map of digital services and infrastructures. Being aware of such underlying dynamics is key if we want to implement the right solutions and maintain a high level of resilience across our digital economy.”
So, what do we learn from the events ENISA analysed?
The new report identifies and analyses different types of threats classified into main categories. These include cybercrime, state-nexus activities, foreign information manipulation & interference (FIMI), hacktivism and vulnerabilities. Those threats were analysed in relation to the targeted sectors and how they spread geographically as well specific technical behaviours.
Ransomware operators continued to disrupt organisations across multiple sectors, through encryption, data theft, and extortion-based operations.
Social engineering remained a common enabling tactic to abuse trust, particularly through phishing campaigns, increasingly supported by phishing kits, and service-based ecosystems, with an increase in the use of the ClickFix technique.
Exploitation of N-day and 0-day vulnerabilities remains a prevalent intrusion vector. Across incidents of unauthorised access for which ENISA was able to identify an intrusion vector (5%), 60% were seen leveraging a vulnerability.
Fraud is also facilitated thanks to compromised data and credentials. In addition, there are sites designed to attract and deceive individuals promising easy profits. Known as Baiting News Sites (BNS), they look credible and legitimate. The European Banking Authority reported that online investment fraud alone reportedly cost an estimated EUR 4 billion across the European Economic Area (EEA) in 2024.
The analysis also reveals that threat groups are reusing tools and techniques, introducing new attack models, exploiting vulnerabilities and collaborating to target the security and resilience of the EU’s digital infrastructure.
Therefore, we still observed the targeting of cyber dependencies, including supply-chain attacks and third-party attacks. Such attacks usually result in large-scale and / or impactful incidents.
Threats targeting or impacting the EU were mostly ideology-driven for 57% of incidents while almost 30% of them were financially motivated.
The threat landscape remains overall dominated by low-impact DDoS attacks during the reporting period, for 51% of recorded cases. These DDoS attacks were primarily shaped by geopolitical developments and driven by specific events such as political statements.
The distinction between threat categories continued to blur. Similar techniques, infrastructures and access mechanisms appeared repeatedly across cybercrime, hacktivist and state-nexus reporting, despite differences in underlying objectives.
What are most targeted sectors?
Considering the total number of incidents, 73% of the targeted organisations are essential and important entities as per the NIS2 definition. The most targeted sector remains public administration in 32% of cases. Other targeted sectors included business services (8%), transport (8%), manufacturing (7%) and finance/ banking (6%).
The threat picture for public administrations is largely impacted by ideology-driven DDoS attacks which accounted for 82% of the recorded events.
How does the ETL align with the 2026 NIS360 findings?
The new findings also illustrate and confirm the conclusions made in the ENISA’s last NIS360 report. Targeted sectors had a maturity level assessed as lower-than-average, with criticality exceeding that level. Such sectors include health, railway, maritime, ICT management service, space, public administrations, drinking and wastewater.
Analysis by threat categories
- Cybercrime: Cybercrime remained a main threat across the EU and globally during the reporting period, covering 36% of total events. In 2025, the most recorded financially motivated activities included ransomware deployment for 40% of all analysed events, followed by data breaches for 31% of events and fraud and impersonation making the third largest category with 19%.
- State-aligned activities: State-nexus intrusion sets were mostly reported carrying out intrusion operations (87%), as well as phishing campaigns (12%).
- FIMI: The evolution we observe aligns with technological developments such as AI. The trend is made visible by contents deployed such as synthetic audio and video and AI-generated text. These cost-effective tools have become part of the daily arsenal of threat actors. AI also enables mass distribution of content and translation thus significantly expanding reach and potential impact.
- Hacktivism: with a total of 4709 claims against EU Member States during the reporting period, more than 89% involved DDoS attacks. Most campaigns were aligned with political developments such as elections, protests and geopolitical tensions and Member States support to Ukraine. Across the year, hacktivist incidents remained concentrated against public administration, transport, and business services.
- Vulnerabilities: 2025 saw the publication of more than 48000 new vulnerabilities which were assigned Common Vulnerability and Exposure (CVE) Identifiers, translating into a 22% increase from the previous year.
Watching out for the dual role of AI
We still observe an increasing use of AI by malicious cyber threat groups, primarily to facilitate or enhance their activities. The integration of AI systems into business environments also creates an extended attack surface. Threat groups, including state-nexus intrusion sets, Information Manipulation Sets (IMS), and cybercriminals demonstrate consistent interest in AI systems both as tools to facilitate malicious activity and as targets for exploitation.
- ENISA Threat Landscape 2026
- ENISA ON AIR – Episode 2 on Threat Landscape 2026
- ENISA video on Threat Landscape 2026 (coming soon)
- ENISA Threat Landscape 2026 Booklet (coming soon)
- NIS360: The bigger picture on maturity and criticality of NIS critical sectors
- Cyber Threats
- ENISA Cybersecurity Threat Landscape Methodology | ENISA
- 2025 Annual Review: NIS2 Cybersecurity Incident Reporting