Skip to main content
ENISA logo

The European Union Agency for Cybersecurity (ENISA) has published its annual analysis of the cyber threats affecting the European Union. Released in September 2026, the report is based on 8,257 incidents recorded between 1 January and 31 December 2025, drawn from open sources and from anonymised information shared by EU Member States and members of the ENISA Cyber Partnership Programme.

This edition marks a change in reporting period: ENISA has aligned the analysis with the calendar year, which means it overlaps by six months with the previous edition. The agency has also expanded the range of cybercrime activities it tracks, including data breaches and fraud.

What the data show

Denial-of-service attacks accounted for the largest share of recorded activity (51.3%), followed by unauthorised access (39.5%). Social engineering remained the most common enabling tactic, with phishing representing 77.8% of such activity, increasingly supported by phishing kits and service-based ecosystems. Exploitation of vulnerabilities, both N-day and zero-day, was behind 60.4% of unauthorised access cases.

By motivation, ideology-driven operations represented the largest share of observed activity (57.3%), largely through hacktivist denial-of-service campaigns against public-facing services. Financially motivated activity accounted for 29.3% of incidents and, ENISA notes, remained the most impactful in the short term. Cyberespionage by state-linked actors accounted for 5.9%.

Public administration was the most affected sector (31.8%), ahead of business services (8.5%), transport (8%), manufacturing (6.9%) and finance and banking (5.6%).

Trends the report highlights:

  • Convergence of methods. Cybercriminal, hacktivist and state-linked operators increasingly rely on similar access vectors, tooling and operational approaches, which ENISA notes makes attribution and threat analysis more difficult.
  • Supply chain and digital dependencies. Incidents affecting software suppliers, service providers and cloud environments continued to generate large-scale downstream impact.
  • Evolving social engineering. The report documents growing use of the ClickFix technique and of SMS-based phishing (smishing).
  • Artificial intelligence in malicious operations. ENISA assesses that AI will increasingly support malicious activity, and that 2026 is likely to see more phases of the attack chain directly enabled by AI, with possible experimentation on human-out-of-the-loop approaches. The growing availability of frontier models and of specialised dual-use tooling is expected to lower barriers to entry and support automation and scale.

Relevance for cybersecurity skills

The report is not a training resource, but it provides the evidence base that training should be built on. For anyone designing cybersecurity curricula, awareness campaigns or workforce development programmes, it identifies which techniques are actually being used against European organisations, which sectors are most exposed, and where attacker capability is shifting. The prominence of phishing and social engineering in the data, in particular, supports the case for organisation-wide awareness work rather than training confined to specialist security roles.

Structure

The report opens with an overview of trends and a sectoral analysis covering five sectors, then examines four areas in depth (cybercrime, state-nexus activity, foreign information manipulation and interference, and hacktivism) followed by a chapter on vulnerabilities disclosed during the period and a forward-looking conclusion. Two annexes cover law enforcement operations in the EU and the assessment methodology.

Access

The report is available in English and can be downloaded free of charge from the ENISA website. It is published under a Creative Commons Attribution 4.0 licence.

Digital skills resource details

Target audience
Digital skills for ICT professionals and other digital experts.
Digital technology / specialisation
Digital skill level
Geographic scope - Country
Austria
Belgium
Bulgaria
Cyprus
Industry - field of education and training
Database and network design and administration
Target language
English
Geographical sphere
EU institutional initiative
Methodology

The report follows the ENISA Cybersecurity Threat Landscape methodology published in September 2026. Analysts collected and assessed 8,257 incidents recorded between 1 January and 31 December 2025, mainly from open sources and from anonymised information shared by EU Member States and members of the ENISA Cyber Partnership Programme. The reporting period has been aligned with the calendar year, resulting in a six-month overlap with the previous edition. The chapter on foreign information manipulation and interference draws on the European External Action Service's FIMI Threat Landscape 2025. ENISA notes that open-source reporting does not provide a complete picture of the threat landscape and is subject to caveats concerning granularity and timing.

Main document - File for download
Skills resource type
Report
0