Threat Landscape

The ENISA Threat Landscape (ETL) report is the annual report of the European Union Agency for Cybersecurity, ENISA, on the state of the cybersecurity threat landscape.

The ENISA Threat Landscape (ETL) report is the annual report of the European Union Agency for Cybersecurity, ENISA, on the state of the cybersecurity threat landscape. ENISA just released the 2026 ETL covering a reporting period from January 2025 to December 2025.

The 2026 ENISA Threat Landscape confirms that cyber dependencies expand the attack surface and require a new level of vigilance to effectively prevent and mitigate the impact of cyber incidents.

The cyber threat landscape of the European Union is still shaped by a combination of recurrent threats. 

Key highlights of the 2026 ENISA Threat Landscape

  • Ransomware remains the most short-term impactful type of incident. 
  • Geopolitical developments still influence cyber activity affecting the EU with hacktivist-led DDoS campaigns targeting essential entities. 
  • Public administration continues to be is the most targeted sector. 
  • Organisations across the EU are likely to continue facing a combination of cybercrime, cyberespionage and hacktivist activity driven by geopolitical developments. 
  • Emerging AI models are expected to be increasingly used to support malicious operations.

Most targeted sectors 

  • Considering the total number of incidents, 73% of the targeted organisations are essential and important entities as per the NIS2 definition. The most targeted sector remains public administration in 32% of cases. Other targeted sectors included business services (8%), transport (8%), manufacturing (7%) and finance/ banking (6%). 

  • The threat picture for public administrations is largely impacted by ideology-driven DDoS attacks which accounted for 82% of the recorded events.