ENISA Warns Digital Dependencies Are Widening Europe’s Cyber Attack Surface
Key Takeaways
- Dependencies Magnify Cyber Risk: ENISA found that supply-chain and third-party attacks can produce large-scale or particularly impactful incidents as compromises spread across interconnected services and infrastructure.
- Ransomware Remains the Most Impactful Threat: Ransomware continued to have the greatest short-term impact, while DDoS attacks accounted for 51% of recorded incidents.
- Public Administration Takes the Most Fire: Public administration accounted for 32% of incidents, with ideology-driven DDoS attacks making up 82% of recorded events against the sector.
- Essential and Important Entities Dominate the Targets: Organizations classified as essential or important under NIS2 represented 73% of targeted organizations.
- AI Is Becoming Both a Tool and a Target: ENISA observed malicious actors using AI to support existing operations while the growing deployment of AI systems creates additional attack surface.
Deep Dive
More than half of the cyber incidents recorded by the European Union’s cybersecurity agency last year were distributed denial-of-service attacks. Most were not especially damaging, but they were, however, remarkably easy to summon. A political statement, an election, a protest or another turn in the war in Ukraine could be enough. Hacktivist groups claimed 4,709 attacks against EU Member States during 2025, according to ENISA’s latest Threat Landscape report, and more than 89% involved DDoS attacks. Public administrations bore much of it.
That helps explain one of the stranger features of Europe’s cyber threat picture. Ransomware remained the most consequential type of incident in the short term, but DDoS attacks accounted for 51% of the incidents ENISA recorded. Ideology, meanwhile, was behind 57% of threats targeting or affecting the EU, while almost 30% were financially motivated.
The figures come from ENISA’s analysis of incidents and events observed between Jan. 1 and Dec. 31, 2025. The agency drew on open sources, anonymized information supplied by EU Member States and information shared through its Cyber Partnership Programme.
Public administration was the most targeted sector, accounting for 32% of recorded incidents. Business services and transport each accounted for 8%, followed by manufacturing at 7% and finance and banking at 6%.
Those numbers need some care. Ideology-driven DDoS attacks accounted for 82% of the events recorded against public administrations, so attack volume alone says relatively little about the severity of what those organizations experienced. Still, there is a reason to pay attention to where the attacks landed. Nearly three-quarters of targeted organizations, 73%, were entities classified as essential or important under NIS2.
ENISA’s 2026 NIS360 assessment had already identified several sectors where cybersecurity maturity was lower than average while criticality was higher. Health, railway, maritime, ICT management services, space, public administration, drinking water and wastewater were among them. The Threat Landscape puts those weaknesses alongside another problem. Organizations rarely stand alone anymore.
ENISA continued to see attackers targeting what it calls cyber dependencies, including supply chains and third parties. These attacks tend to produce large-scale or otherwise significant incidents because compromising one organization can provide a route into others that depend upon it. The security of a company’s own systems is only part of the equation when its operations depend on an expanding collection of software, infrastructure and service providers.
“The analysis highlights how threats become more interconnected and how threat groups spread their impact across the larger map of digital services and infrastructures,” ENISA Executive Director Juhan Lepassaar said.
That interconnectedness is also showing up among the attackers themselves.
ENISA found cybercriminals, hacktivists and state-linked actors repeatedly using similar techniques, infrastructure and access mechanisms despite pursuing different objectives. Threat groups reused tools, exploited vulnerabilities, introduced new attack models and collaborated. The old categories have not disappeared, but the technical distinctions between them have become less tidy.
Cybercrime accounted for 36% of the events ENISA analyzed. Among financially motivated activity, ransomware deployment represented 40%, followed by data breaches at 31% and fraud and impersonation at 19%.
Ransomware operators continued to combine encryption with data theft and extortion. Social engineering remained one of the ordinary ways into an organization, particularly through phishing. ENISA also observed growing use of phishing kits, service-based criminal ecosystems and the ClickFix technique.
Then there are the vulnerabilities.
More than 48,000 new vulnerabilities were assigned Common Vulnerabilities and Exposures identifiers during 2025, a 22% increase from the previous year. ENISA said exploitation of both N-day and zero-day vulnerabilities remained a prevalent intrusion vector.
The agency was able to identify an intrusion vector in only 5% of the unauthorized-access incidents it examined. Within that limited subset, 60% involved exploitation of a vulnerability. It is an important distinction. The figure does not mean vulnerabilities accounted for 60% of unauthorized access overall.
Compromised data and credentials were also feeding fraud. ENISA highlighted so-called Baiting News Sites, websites made to look credible while drawing victims toward promises of easy profits. The European Banking Authority has estimated that online investment fraud alone cost about €4 billion across the European Economic Area in 2024.
State-linked activity followed its own pattern. State-nexus intrusion sets were reported carrying out intrusion operations in 87% of recorded activity and phishing campaigns in 12%.
Artificial intelligence is beginning to cut across these categories too, although ENISA’s findings are less a story of some entirely new class of attack than of existing operations becoming easier to conduct.
In foreign information manipulation and interference activity, the agency observed synthetic audio and video alongside AI-generated text. The technology lowers the cost of producing material and can help actors translate and distribute it at scale. ENISA said such tools have become part of the daily arsenal available to threat actors.
Malicious groups are also using AI to facilitate or enhance cyber operations. At the same time, the spread of AI systems inside organizations creates systems worth attacking in their own right. State-nexus intrusion sets, information manipulation actors and cybercriminals have all shown interest in AI both as a tool and as a target.
None of this displaces the older threats. Phishing still works. Vulnerabilities still get exploited. Ransomware still shuts organizations down. DDoS attacks remain cheap enough and disruptive enough to accompany political events almost as they happen.
What has changed is the environment in which those familiar attacks operate. A vulnerability in one product can become somebody else’s incident. A compromised provider can carry an attacker into organizations that never dealt with the attacker directly. Techniques developed for one kind of campaign can turn up in another.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

