Friday, September 25, 2026



TECH




ENISA: DDoS attacks accounted for more than half of the incidents recorded in Europe last year

In total, DDoS attacks represented 51.3% of the incidents recorded last year, according to the latest edition of the ENISA report on the threat landscape in the European Union. Meanwhile, unauthorized access to systems accounted for 39.5% of the total.

The 2026 ENISA Threat Landscape confirms that cyber dependencies expand the attack surface and require a new level of vigilance to effectively prevent and mitigate the impact of cyber incidents.

The cyber threat landscape of the European Union is still shaped by a combination of recurrent threats. 

Key highlights include:
-Ransomware remains the most short-term impactful type of incident. 
-Geopolitical developments still influence cyber activity affecting the EU with hacktivist-led DDoS campaigns targeting essential entities. 
-Public administration continues to be is the most targeted sector. 
-Organisations across the EU are likely to continue facing a combination of cybercrime, cyberespionage and hacktivist activity driven by geopolitical developments. 
-Emerging AI models are expected to be increasingly used to support malicious operations.

To shape our understanding of the cyber threat landscape and the dynamics at work, ENISA collected and analysed incidents and events observed from 1 January to 31 December 2025 for this new edition of the Threat Landscape. Those events were gathered from open sources, as well as anonymised information shared by EU Member States and through the ENISA Cyber Partnership Programme.

Public administration emerged as the most affected sector, accounting for 31.8% of incidents, and 73% of the affected organizations were entities classified as "essential" or "important" under the NIS2 directive.
According to ENISA, financially motivated attacks accounted for 29.3% of all recorded incidents, with ransomware standing out in this category. Ransomware attacks also feature on the list of threats affecting a wide range of sectors during the period under review—a list that includes data breaches, phishing, and fraud.
Regarding social engineering, phishing was present in 77.8% of incidents where this technique was identified, with attackers increasingly relying on "phishing kits" and specialized services to carry out campaigns.

ENISA also highlights the rise of threats such as ClickFix and tactics like smishing, as fraud schemes continue to exploit compromised credentials and identity theft, alongside other social engineering techniques.

Digital infrastructures in attackers' crosshairs...According to the report, attackers are increasingly exploiting organizations' digital infrastructures—including software vendors, third-party services, and cloud platforms—meaning a single incident can have consequences for a broader range of entities. Attacks on supply chains, third-party vendors, and other digital infrastructures continued to cause large-scale, high-impact incidents throughout 2025, the agency reports.

Alongside public administration, business services were also among the most affected sectors, accounting for 8.5% of the incidents recorded by ENISA. These were followed by transportation (8%), manufacturing (6.9%), and the finance and banking sector (5.6%). However, attack patterns and the impact of threats vary by sector. For instance, in the public administration sector, 82% of recorded incidents were ideologically motivated DDoS attacks, making the sector a primary target for campaigns linked to political and geopolitical events.

Geopolitical developments—including the ongoing war between Russia and Ukraine and the escalating conflict in the Middle East—also significantly impacted the threat landscape in 2025. Ideologically motivated operations accounted for 57.3% of observed incidents.

As detailed in the report, hacktivism cases were linked to campaigns involving DDoS attacks against public services, essential entities, and organizations connected to political events or the support of specific countries involved in conflicts.

During the period under review, 4,709 claims of hacktivist attacks against EU Member States were recorded. More than 89% of these involved DDoS attacks.

State-aligned threat actor groups also continued to conduct cyber-espionage operations, which accounted for 5.9% of observed incidents. On one hand, groups linked to Russia focused primarily on central government and diplomatic entities, while groups associated with China showed greater interest in the transport sector.

Vulnerabilities and AI-powered tools...Exploiting vulnerabilities remained a primary method for gaining unauthorized access to systems in 2025. Over the past year, more than 48,000 new vulnerabilities were recorded—a 22% increase compared to the previous year.

ENISA reports that these security flaws were the root cause of 60.4% of unauthorized access incidents where the attackers' entry method could be identified. These include both newly discovered vulnerabilities and known flaws that persist in systems that have not yet been updated.

AI is also gaining ground in cybercriminal operations, enabling faster, automated, and easier-to-execute attacks. The agency expects this trend to intensify, with the technology being used in an increasing number of attack stages and lowering the barrier to entry for attackers.

Looking ahead, ENISA anticipates that the major threats identified in 2025 will continue to impact European organizations. The realms of cybercrime, cyber-espionage, and hacktivism are expected to remain influenced by geopolitical developments. Cybercrime is projected to persist as a leading source of attacks and disruptions.

The agency also warns of two factors that could increase risks for organizations: growing reliance on external suppliers, services, and infrastructure, and the increasing use of AI.

mundophone

No comments:

Post a Comment

TECH A $20 multimeter might reveal your CPU's overclocking potential Can you predict how well your CPU will overclock by probing it wit...