Exploring the evolution of the cyber threat landscape: How dependencies weaken our digital resilience

The 2026 ENISA Threat Landscape confirms that cyber dependencies expand the attack surface and require a new level of vigilance to effectively prevent and mitigate the impact of cyber incidents.

The cyber threat landscape of the European Union is still shaped by a combination of recurrent threats. Key highlights include:

To shape our understanding of the cyber threat landscape and the dynamics at work, ENISA collected and analysed incidents and events observed from 1 January to 31 December 2025 for this new edition of the Threat Landscape. Those events were gathered from open sources, as well as anonymised information shared by EU Member States and through the ENISA Cyber Partnership Programme.

ENISA’s Executive Director Juhan Lepassaar said: “The ENISA threat landscape is more than a list of cybersecurity threats affecting the EU and how they are distributed around sectors and entities. The analysis highlights how threats become more interconnected and how threat groups spread their impact across the larger map of digital services and infrastructures. Being aware of such underlying dynamics is key if we want to implement the right solutions and maintain a high level of resilience across our digital economy.”

The new report identifies and analyses different types of threats classified into main categories. These include cybercrime, state-nexus activities, foreign information manipulation & interference (FIMI), hacktivism and vulnerabilities. Those threats were analysed in relation to the targeted sectors and how they spread geographically as well specific technical behaviours.

Ransomware operators continued to disrupt organisations across multiple sectors, through encryption, data theft, and extortion-based operations.

Social engineering remained a common enabling tactic to abuse trust, particularly through phishing campaigns, increasingly supported by phishing kits, and service-based ecosystems, with an increase in the use of the ClickFix technique.

Exploitation of N-day and 0-day vulnerabilities remains a prevalent intrusion vector. Across incidents of unauthorised access for which ENISA was able to identify an intrusion vector (5%), 60% were seen leveraging a vulnerability.

Fraud is also facilitated thanks to compromised data and credentials. In addition, there are sites designed to attract and deceive individuals promising easy profits. Known as Baiting News Sites (BNS), they look credible and legitimate. The European Banking Authority reported that online investment fraud alone reportedly cost an estimated EUR 4 billion across the European Economic Area (EEA) in 2024.

The analysis also reveals that threat groups are reusing tools and techniques, introducing new attack models, exploiting vulnerabilities and collaborating to target the security and resilience of the EU’s digital infrastructure.

Therefore, we still observed the targeting of cyber dependencies, including supply-chain attacks and third-party attacks. Such attacks usually result in large-scale and / or impactful incidents.

Threats targeting or impacting the EU were mostly ideology-driven for 57% of incidents while almost 30% of them were financially motivated.

The threat landscape remains overall dominated by low-impact DDoS attacks during the reporting period, for 51% of recorded cases. These DDoS attacks were primarily shaped by geopolitical developments and driven by specific events such as political statements.

The distinction between threat categories continued to blur. Similar techniques, infrastructures and access mechanisms appeared repeatedly across cybercrime, hacktivist and state-nexus reporting, despite differences in underlying objectives.

Considering the total number of incidents, 73% of the targeted organisations are essential and important entities as per the NIS2 definition. The most targeted sector remains public administration in 32% of cases. Other targeted sectors included business services (8%), transport (8%), manufacturing (7%) and finance/ banking (6%).

The threat picture for public administrations is largely impacted by ideology-driven DDoS attacks which accounted for 82% of the recorded events.

The new findings also illustrate and confirm the conclusions made in the ENISA’s last NIS360 report. Targeted sectors had a maturity level assessed as lower-than-average, with criticality exceeding that level. Such sectors include health, railway, maritime, ICT management service, space, public administrations, drinking and wastewater.

We still observe an increasing use of AI by malicious cyber threat groups, primarily to facilitate or enhance their activities. The integration of AI systems into business environments also creates an extended attack surface. Threat groups, including state-nexus intrusion sets, Information Manipulation Sets (IMS), and cybercriminals demonstrate consistent interest in AI systems both as tools to facilitate malicious activity and as targets for exploitation.

For press questions

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source