Scudo digitale sopra una mappa dell'Europa attraversata da una rete di nodi interconnessi

Immagine creata con IAAI-generated image

Cyber threats in the European Union: the ENISA Threat Landscape 2026 report

On 22 September 2026 the European Union Agency for Cybersecurity (ENISA) published the 2026 edition of its annual report on the cyber threat landscape, the ENISA Threat Landscape. The document describes the threats that affected the European Union during 2025 and identifies the growing interdependence of digital services and infrastructures as a recurring feature.

The report and the observation period

The 2026 edition analyses incidents and events observed from 1 January to 31 December 2025. The data come from open sources, from anonymised information shared by the Member States and from the ENISA Cyber Partnership Programme. Compared with the previous edition, published on 1 October 2025 and covering 4,875 incidents recorded between 1 July 2024 and 30 June 2025, the reference period now coincides with the calendar year. The figures of the 2025 edition are also referred to in the analysis NIS 2, DORA and the Cyber Resilience Act: how to find your way when perimeters overlap.

The report classifies threats into five main categories: cybercrime, state-nexus activities, foreign information manipulation and interference (FIMI), politically motivated hacking (hacktivism) and vulnerabilities. Each category is examined in relation to the targeted sectors, the geographical distribution and the technical behaviours observed.

The main threat categories

According to ENISA, 57% of the incidents targeting or affecting the Union were ideology-driven and almost 30% were financially motivated. DDoS attacks (Distributed Denial of Service, attacks that make a service unavailable by overloading it with requests), mostly of low impact, account for 51% of recorded cases. The campaigns were largely linked to political events such as elections, protests, geopolitical tensions and Member States’ support to Ukraine: hacktivism accounts for 4,709 claims against Member States, more than 89% of which involved DDoS attacks.

Cybercrime covers 36% of all events. Among financially motivated activities, ransomware (malicious software that encrypts the victim’s data in order to extort a ransom) accounts for 40% of analysed events, data breaches for 31% and fraud and impersonation for 19%. The report identifies ransomware as the type of incident with the greatest short-term impact. Social engineering remains a common technique, particularly through phishing campaigns supported by ready-made kits and service-based ecosystems, with increased use of the technique known as ClickFix. ENISA also refers to the estimate of the European Banking Authority (EBA) that online investment fraud alone cost around EUR 4 billion across the European Economic Area in 2024.

State-nexus activities consist of intrusion operations in 87% of cases and phishing campaigns in 12%. As regards vulnerabilities, more than 48,000 new vulnerabilities with a CVE (Common Vulnerabilities and Exposures) identifier were published in 2025, a 22% increase on the previous year. Among incidents of unauthorised access for which the intrusion vector could be identified, equal to 5% of cases, 60% leveraged a vulnerability.

The report notes that the boundaries between categories continue to blur: similar techniques, infrastructures and access mechanisms recur across criminal, hacktivist and state-nexus activity, despite different underlying objectives. Supply-chain and third-party attacks remain frequent and usually result in large-scale or high-impact incidents.

The most targeted sectors and the link with the NIS 2 Directive

73% of the targeted organisations are essential or important entities as defined by Directive (EU) 2022/2555 (the NIS 2 Directive). Public administration remains the most targeted sector, with 32% of cases, followed by business services (8%), transport (8%), manufacturing (7%) and finance and banking (6%). For public administration, ideology-driven DDoS attacks account for 82% of recorded events. On the supervision arrangements for NIS 2 entities in Italy, see the contribution on the guidance of the National Cybersecurity Agency (ACN).

ENISA links these figures to the NIS360 report published on 28 May 2026, which assesses the maturity and criticality of the sectors of high criticality listed in Annex I to the NIS 2 Directive. NIS360 identifies a “risk zone” made up of sectors with lower-than-average maturity and criticality exceeding their maturity: health, railway, maritime, ICT service management, space, public administration, drinking water and waste water. According to the Agency, the sectors targeted by the threats described in the Threat Landscape partly coincide with those placed in the risk zone. For the health sector, the European measures being implemented are described in the contribution on the cybersecurity of hospitals in Europe.

The dual role of artificial intelligence

The report records an increasing use of artificial intelligence by malicious groups, mainly to facilitate or enhance existing activities. In the field of information manipulation, ENISA points to the spread of synthetic audio and video content and of text generated by artificial intelligence systems, low-cost tools that allow content to be distributed and translated at scale. At the same time, the integration of artificial intelligence systems into business environments extends the attack surface: criminal groups, state-nexus intrusion sets and information manipulation sets show interest in these systems both as tools and as targets.

Outlook

According to ENISA, organisations across the Union are likely to continue facing a combination of cybercrime, cyberespionage and hacktivism driven by geopolitical developments, while emerging artificial intelligence models are expected to be increasingly used to support malicious operations. Implementation of the regulatory framework continues: since 11 September 2026 the reporting obligations of the Cyber Resilience Act apply, requiring manufacturers to notify actively exploited vulnerabilities and severe incidents through the single reporting platform run by ENISA, while the main obligations will apply from 11 December 2027. The Agency has announced a summary booklet of the report, not yet available, and a webinar on the Threat Landscape on 29 September 2026.

In dialogue with the 2030 Agenda

Goal 9. Industry, innovation and infrastructure: the report documents threats to digital infrastructure and to sectors of high criticality, including transport, water services and space, and the growing weight of supply-chain attacks.

Goal 16. Peace, justice and strong institutions: public administration is the most targeted sector, and information manipulation campaigns affect the functioning of institutions and electoral processes.

Goal 17. Partnerships for the goals: the report relies on information sharing between Member States, Union institutions and private entities through the ENISA Cyber Partnership Programme.

Sources


AI AnthropoCosmic In evidenzaAI AnthropoCosmicUn progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo, che mette al centro la dignità della persona nella progettazione dei sistemi. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicAn international project for an AI at the service of humanity, the environment and the cosmos, placing human dignity at the centre of system design. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article
Intervista Radio Radio IntervistaLegge e colossi del digitaleIl patteggiamento di Meta sui minori non è una condanna. Stati Uniti ed Europa seguono strade opposte, e sugli agenti di IA resta aperta la domanda su chi risponde.Un Giorno Speciale su Radio Radio, con Alessio De Paolis · audio dal minuto 2:26:00Ascolta l’intervistaGuarda il videoLeggi l’articolo
Digital Omnibus ContributoIl Digital Omnibus cambia l’AI ActNuove scadenze per i sistemi ad alto rischio e un chiarimento sull’obbligo di AI literacy: più tempo per adeguarsi, nessuno sconto sulla preparazione di persone e processi.Articolo scritto per il blog di SkillaLeggi su Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo tra i relatori del festival dedicato a protezione dei dati, archivi digitali e regole del futuro. Interviene sul tema «Le regole dell’IA: nuove leggi o principi del diritto?».Venerdì 6 novembre 2026, ore 16:30, Ex Convitto Palmieri, LecceL’interventoLa scheda relatriceIl festival
AI AnthropoCosmic 2026Moderatrice e relatriceAI AnthropoCosmic 2026Valentina Grazia Sapuppo nel progetto dell’Università Pontificia Salesiana su Persona, Ambiente e Cosmo: moderazione della sessione mattutina del Convegno finale e intervento negli AI Laboratori del Domani su commercio elettronico e IA.14 novembre 2026, online · 28 novembre 2026, Università Pontificia Salesiana, RomaIl convegnoL’incontroIl contributoLa relatriceIl progetto
Interview Radio Radio InterviewLaw and the digital giantsThe Meta settlement on minors is not a conviction. The United States and Europe take opposite paths, and on AI agents the question of who answers remains open.Un Giorno Speciale on Radio Radio, with Alessio De Paolis · audio from 2:26:00 · in ItalianListen to the interviewWatch the videoRead the article
Digital Omnibus ContributionThe Digital Omnibus reshapes the AI ActNew deadlines for high-risk systems and a clarification on the AI literacy duty: more time to comply, no discount on preparing people and processes.Article written for the Skilla blog, in ItalianRead on Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo among the speakers of the festival on data protection, digital archives and the rules of the future. She takes part in the panel «The rules of AI: new laws or principles of law?».Friday 6 November 2026, 16:30, Ex Convitto Palmieri, LecceThe panelSpeaker profileThe festival
AI AnthropoCosmic 2026Moderator and speakerAI AnthropoCosmic 2026Valentina Grazia Sapuppo in the project of the Università Pontificia Salesiana on Person, Environment and Cosmos: moderator of the morning session of the closing conference and speaker at the AI Laboratori del Domani on e-commerce and AI.14 November 2026, online · 28 November 2026, Università Pontificia Salesiana, Rome · sessions held in ItalianThe conferenceThe sessionThe contributionSpeakerThe project