What the EU cyber threat landscape looked like in 2025
Analytics2026-09-24, 10:42
The European Union Agency for Cybersecurity (ENISA) analyzed 8 257 recorded incidents affecting the EU in 2025. One of the most interesting contrasts is that raw attack counts are a poor reflection of their actual impact: large-scale DDoS attacks and hacktivism significantly inflate the number of events, drawing attention away from less frequent financially motivated attacks and cyberespionage with more serious consequences.
• DDoS accounted for 51.3% of all events, while hacktivism accounted for 57.3%, although most DDoS attacks had limited impact. Financially motivated attacks and cyberespionage accounted for just 29.3% and 6.3% of events, respectively, yet ENISA considers the former the primary short-term threat and the latter a significant strategic threat over a longer time horizon.
• The government sector ranked first by number of attacks, at 31.8%. However, 81.8% of events were DDoS attacks, and their consequences were usually limited to temporary disruptions of public services. In other words, the leading position of government organizations largely reflects the intensity of hacktivism rather than the number of incidents with serious consequences.
• Manufacturing ranked only fourth by total number of incidents, with a 6.9% share, but it suffered the highest share of ransomware attacks in the EU (25.2%). Ransomware was present in 82.8% of financially motivated attacks against manufacturing, causing disruptions to core IT systems and production processes.
• The financial sector accounts for only 5.6% of the overall statistics, yet it accounted for 10% of all reviewed incidents with significant impact.
ENISA specifically highlights attacks through suppliers, SaaS, cloud services, and other shared infrastructure. Ransomware attacks are also showing a shift toward data theft: exfiltration over a command-and-control channel occurred in 73.3% of the incidents studied, while encryption occurred in 13.7%.
The report also focuses on hacktivism and information operations:
• Hacktivism. ENISA recorded 4 709 hacktivist claims, with 45.8% of this activity targeting the government sector. More than 89% of the claims involved DDoS attacks, but the actual impact was significantly more limited: when one campaign was analyzed, target unavailability was independently confirmed for only 23.8% of the claimed attacks.
• Information operations (FIMI). The European External Action Service (EEAS) recorded 540 FIMI incidents. They used around 10.5 thousand dissemination channels — from news websites to social media accounts — and approximately 43 thousand individual pieces of content across 19 platforms. 65% of the episodes remained unattributed, 29% were linked to Russia, and 6% to China.
Although the report describes the situation in the EU, its main conclusion applies more broadly: the number of recorded incidents alone is a poor indicator of the actual level of risk. Large-scale and highly visible attacks have a greater effect on the statistics, but the most serious consequences are often associated with less frequent yet deeper and more persistent compromises.