Europe’s Tech Infrastructure Faces Rising Cyber Threats

▼ Summary
– ENISA’s Threat Landscape 2026 report highlights increasing cybersecurity risks in Europe driven by financially motivated cybercrime and state-linked activities.
– Analysis of 8,257 incidents from 2025 reveals that DDoS attacks and unauthorized access are the most frequent incident types affecting the region.
– Public administration is the most targeted sector, accounting for over 31% of incidents, with DDoS attacks representing the majority of these cases.
– Cybercriminals increasingly exploit shared technology providers and software supply chains, causing widespread disruption to multiple organizations through third-party compromises.
– A notable example includes a ransomware attack on a Swedish IT supplier that disrupted services for approximately 200 municipalities and regional authorities.
Europe’s digital infrastructure is grappling with a surge in sophisticated cyber threats, ranging from financially motivated crime to state-sponsored espionage. According to the ENISA Threat Landscape 2026, the security environment is defined by interconnected risks that allow disruptions to cascade across organizations through shared technology providers and complex digital supply chains. The report identifies cybercrime, state-linked activity, foreign information manipulation, hacktivism, and vulnerability exploitation as the primary drivers of this escalating danger.
The European Union Agency for Cybersecurity analyzed 8,257 incidents recorded throughout 2025. This data was gathered from open sources, anonymized reports from EU member states, and contributions from the ENISA Cyber Partnership Programme. The findings reveal how threat actors leverage geopolitical tensions and digital interdependence to maximize their impact.
> “The ENISA threat landscape is more than a list of cybersecurity threats affecting the EU and how they are distributed around sectors and entities. The analysis highlights how threats become more interconnected and how threat groups spread their impact across the larger map of digital services and infrastructures. Being aware of such underlying dynamics is key if we want to implement the right solutions and maintain a high level of resilience across our digital economy,” said ENISA’s Executive Director Juhan Lepassaar.
Dominance of DDoS and Unauthorized Access
The breakdown of incident types shows a clear preference for disruptive tactics. Distributed Denial of Service (DDoS) attacks accounted for 51.3% of all recorded incidents, while unauthorized access represented 39.5%. Hacktivist groups were heavily involved in DDoS campaigns targeting government websites and online public services. Meanwhile, ransomware continued to serve as a major source of operational disruption across various sectors.
A significant trend is the widening impact of attacks on shared technology services. Cybercriminals increasingly target third-party providers, cloud environments, and software supply chains. When an organization relies on an affected supplier, it becomes vulnerable even if its own internal systems remain uncompromised. Incidents included compromised software repositories, browser extensions, and widely used libraries. Because technology providers connect to multiple customers, an intrusion at one point can interrupt services or grant attackers access to broader parts of the digital ecosystem.
For example, ENISA highlighted a ransomware attack on a Swedish IT supplier that impacted approximately 200 municipalities and regional authorities. The breach disrupted human resources reporting systems, illustrating how a single company’s failure can ripple out to affect numerous dependent clients.
Public Administration Under Siege
Public administration emerged as the most targeted sector, accounting for 31.8% of all incidents. This was followed by business services at 8.5%, transport at 8%, manufacturing at 6.9%, and finance and banking at 5.6%.
Government entities faced a disproportionate share of DDoS attacks, which made up 81.8% of incidents in this sector. Attackers frequently targeted government websites and portals during elections, law enforcement operations, and periods of heightened geopolitical tension, including Russia’s war against Ukraine and conflicts in the Middle East. Among financially motivated attacks on public administration, data breaches accounted for 38.4%, while ransomware claims represented 36%, primarily hitting local municipalities.
State-linked groups also maintained a focus on cyberespionage, targeting ministries, diplomatic organizations, and other government institutions. Their operations extended beyond immediate targets to include strategic intelligence collection and potential intellectual property theft across the EU.
Business services, the second-most affected sector, saw unauthorized access account for 56.7% of incidents, followed by DDoS attacks at 38%. Within this sector, ransomware deployments comprised 54% of unauthorized-access incidents, and data breaches represented 26.5%.
Social Engineering and Vulnerability Exploitation
Attackers continue to rely on human error and software flaws as common entry points. Phishing remained the dominant social engineering technique, appearing in 77.8% of identified incidents. ENISA also noted an increase in the use of ClickFix, a method that deceives users into executing malicious commands under the guise of troubleshooting instructions.
Vulnerability exploitation played a critical role in system intrusions. In 5.2% of unauthorized-access incidents, attackers exploited specific vulnerabilities. Of those cases, 60.4% involved direct exploitation of known flaws. Other campaigns utilized trusted messaging platforms like Signal and WhatsApp to initiate personalized contact. Targets were guided through legitimate authentication processes, allowing attackers to gain full control over compromised devices.
The Role of Artificial Intelligence
The integration of Artificial Intelligence (AI) into cyber operations is accelerating the speed and sophistication of attacks. Both cybercriminals and state-linked groups are using AI to enhance phishing, fraud, reconnaissance, malicious code development, and post-exploitation activities. These tools help operators create tailored messages, write scripts, and increase the velocity of existing techniques.
Groups engaged in foreign information manipulation and interference are leveraging AI-generated text, audio, and video to produce content, translate it into multiple languages, and distribute it to wider audiences. Simultaneously, AI applications themselves have become attractive targets due to their connections to sensitive files, credentials, browser sessions, and development environments. A compromised AI application could provide a direct route into trusted systems. Furthermore, AI-linked development tools and software supply chains offer additional opportunities for attackers seeking access to organizations and their customers.
ENISA anticipates that advanced AI models will enable more stages of the attack process. Increased automation could expand the scale of cyber activity and make malicious operations harder to detect. Threat groups may also experiment with systems capable of performing parts of an attack with limited human involvement, raising the stakes for future digital resilience efforts.
(Source: Help Net Security)



