On 22 September 2026 the European Union Agency for Cybersecurity (ENISA) published the 2026 edition of its annual report on the cyber threat landscape, the ENISA Threat Landscape. The document describes the threats that affected the European Union during 2025 and identifies the growing interdependence of digital services and infrastructures as a recurring feature.
The report and the observation period
The 2026 edition analyses incidents and events observed from 1 January to 31 December 2025. The data come from open sources, from anonymised information shared by the Member States and from the ENISA Cyber Partnership Programme. Compared with the previous edition, published on 1 October 2025 and covering 4,875 incidents recorded between 1 July 2024 and 30 June 2025, the reference period now coincides with the calendar year. The figures of the 2025 edition are also referred to in the analysis NIS 2, DORA and the Cyber Resilience Act: how to find your way when perimeters overlap.
The report classifies threats into five main categories: cybercrime, state-nexus activities, foreign information manipulation and interference (FIMI), politically motivated hacking (hacktivism) and vulnerabilities. Each category is examined in relation to the targeted sectors, the geographical distribution and the technical behaviours observed.
The main threat categories
According to ENISA, 57% of the incidents targeting or affecting the Union were ideology-driven and almost 30% were financially motivated. DDoS attacks (Distributed Denial of Service, attacks that make a service unavailable by overloading it with requests), mostly of low impact, account for 51% of recorded cases. The campaigns were largely linked to political events such as elections, protests, geopolitical tensions and Member States’ support to Ukraine: hacktivism accounts for 4,709 claims against Member States, more than 89% of which involved DDoS attacks.
Cybercrime covers 36% of all events. Among financially motivated activities, ransomware (malicious software that encrypts the victim’s data in order to extort a ransom) accounts for 40% of analysed events, data breaches for 31% and fraud and impersonation for 19%. The report identifies ransomware as the type of incident with the greatest short-term impact. Social engineering remains a common technique, particularly through phishing campaigns supported by ready-made kits and service-based ecosystems, with increased use of the technique known as ClickFix. ENISA also refers to the estimate of the European Banking Authority (EBA) that online investment fraud alone cost around EUR 4 billion across the European Economic Area in 2024.
State-nexus activities consist of intrusion operations in 87% of cases and phishing campaigns in 12%. As regards vulnerabilities, more than 48,000 new vulnerabilities with a CVE (Common Vulnerabilities and Exposures) identifier were published in 2025, a 22% increase on the previous year. Among incidents of unauthorised access for which the intrusion vector could be identified, equal to 5% of cases, 60% leveraged a vulnerability.
The report notes that the boundaries between categories continue to blur: similar techniques, infrastructures and access mechanisms recur across criminal, hacktivist and state-nexus activity, despite different underlying objectives. Supply-chain and third-party attacks remain frequent and usually result in large-scale or high-impact incidents.
The most targeted sectors and the link with the NIS 2 Directive
73% of the targeted organisations are essential or important entities as defined by Directive (EU) 2022/2555 (the NIS 2 Directive). Public administration remains the most targeted sector, with 32% of cases, followed by business services (8%), transport (8%), manufacturing (7%) and finance and banking (6%). For public administration, ideology-driven DDoS attacks account for 82% of recorded events. On the supervision arrangements for NIS 2 entities in Italy, see the contribution on the guidance of the National Cybersecurity Agency (ACN).
ENISA links these figures to the NIS360 report published on 28 May 2026, which assesses the maturity and criticality of the sectors of high criticality listed in Annex I to the NIS 2 Directive. NIS360 identifies a “risk zone” made up of sectors with lower-than-average maturity and criticality exceeding their maturity: health, railway, maritime, ICT service management, space, public administration, drinking water and waste water. According to the Agency, the sectors targeted by the threats described in the Threat Landscape partly coincide with those placed in the risk zone. For the health sector, the European measures being implemented are described in the contribution on the cybersecurity of hospitals in Europe.
The dual role of artificial intelligence
The report records an increasing use of artificial intelligence by malicious groups, mainly to facilitate or enhance existing activities. In the field of information manipulation, ENISA points to the spread of synthetic audio and video content and of text generated by artificial intelligence systems, low-cost tools that allow content to be distributed and translated at scale. At the same time, the integration of artificial intelligence systems into business environments extends the attack surface: criminal groups, state-nexus intrusion sets and information manipulation sets show interest in these systems both as tools and as targets.
Outlook
According to ENISA, organisations across the Union are likely to continue facing a combination of cybercrime, cyberespionage and hacktivism driven by geopolitical developments, while emerging artificial intelligence models are expected to be increasingly used to support malicious operations. Implementation of the regulatory framework continues: since 11 September 2026 the reporting obligations of the Cyber Resilience Act apply, requiring manufacturers to notify actively exploited vulnerabilities and severe incidents through the single reporting platform run by ENISA, while the main obligations will apply from 11 December 2027. The Agency has announced a summary booklet of the report, not yet available, and a webinar on the Threat Landscape on 29 September 2026.
In dialogue with the 2030 Agenda
Goal 9. Industry, innovation and infrastructure: the report documents threats to digital infrastructure and to sectors of high criticality, including transport, water services and space, and the growing weight of supply-chain attacks.
Goal 16. Peace, justice and strong institutions: public administration is the most targeted sector, and information manipulation campaigns affect the functioning of institutions and electoral processes.
Goal 17. Partnerships for the goals: the report relies on information sharing between Member States, Union institutions and private entities through the ENISA Cyber Partnership Programme.
Sources
- ENISA, ENISA Threat Landscape 2026, 22 September 2026
- ENISA, Exploring the evolution of the cyber threat landscape: How dependencies weaken our digital resilience, press release of 22 September 2026
- ENISA, ENISA Threat Landscape 2025, 1 October 2025
- ENISA, NIS360: The bigger picture on maturity and criticality of NIS critical sectors, 28 May 2026
- European Commission, Safer and more secure digital products, 11 September 2026
- EUR-Lex, Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS 2 Directive)








