BRUSSELS — The European Union Agency for Cybersecurity (ENISA) released its landmark ENISA Threat Landscape 2026 report, painting a complex, dual-natured picture of the European digital ecosystem. Analyzing 8,257 security incidents recorded throughout the 2025 calendar year, the agency’s exhaustive 101-page evaluation reveals a stark operational dichotomy: while low-impact, high-volume disruptions like Distributed Denial-of-Service (DDoS) attacks dominate raw incident counts, financially motivated operations—principally ransomware and strategic data exfiltration—remain the most acutely damaging threats to organizations in the short term.

The findings carry profound implications for cybersecurity practitioners, information governance specialists, and eDiscovery professionals across the continent. By separating the high-frequency "noise" of political hacktivism from the calculated, revenue-driven "signals" of sophisticated threat actors, ENISA’s latest assessment underscores an evolving digital battleground where modern supply chains, interconnected cloud ecosystems, and expanding digital dependencies drastically widen the continental attack surface.


Main Facts

The ENISA Threat Landscape 2026 report is built upon a foundation of 8,257 cyber incidents cataloged between January 1 and December 31, 2025. Drawing primarily from open-source intelligence, anonymized reports from EU member states, and contributions through the agency’s Cyber Partnership Programme, the comprehensive assessment provides a macro-level snapshot of contemporary cyber risk.

Key findings from the analysis include:

  • The Volume vs. Impact Divide: Ideology-driven activities accounted for a staggering 57.3% of total incidents analyzed, yet produced virtually no large-scale operational disruption. Conversely, financially motivated activities represented 29.3% of incidents, yet generated the vast majority of severe financial losses, data loss, and regulatory exposure.
  • DDoS Dominance in Volume: Distributed Denial-of-Service attacks led all incident types at 51.3% of the total dataset, overwhelmingly driven by pro-Russian hacktivist groups targeting public administration and critical infrastructure.
  • The Shift Toward Data Exfiltration: In the realm of financially motivated cybercrime, ransomware operators accounted for 47.3% of claims. Critically, technique-level analysis revealed that data exfiltration over command-and-control channels constituted 73.3% of observed operations, dwarfing traditional file encryption (which accounted for just 13.7%).
  • Targeting the Public Sector: Public administration remained the single most targeted sector, absorbing 31.8% of recorded events, with ideology-driven DDoS attacks comprising 81.8% of those specific incidents.
  • The Supply Chain Multiplier: Third-party providers, software repositories, and cloud environments served as primary vectors for large-scale disruptions, proving that adversaries increasingly favor indirect, highly efficient pathways into enterprise networks.

Chronology

To fully understand the data presented in the 2026 report, security analysts must examine the evolutionary shift in ENISA’s reporting methodology and the temporal timeline of significant events throughout 2025 and early 2026.

  • Transition to Calendar-Year Reporting: Historically, ENISA’s threat landscape reports operated on mismatched rolling periods. The ENISA Threat Landscape 2025 edition analyzed 4,875 incidents spanning July 2024 through June 2025. The 2026 edition shifts to a strict calendar-year model (January to December 2025), creating an intentional six-month overlap between consecutive publications and expanding tracking parameters to include data breaches and broader cybercrime metrics.
  • September 2025 — Supply Chain Disruption: A ransomware incident striking U.S.-based Collins Aerospace’s passenger-processing software cascaded across Europe, severely crippling automated check-in systems at major hubs including Brussels and Berlin airports. Simultaneously, a parallel ransomware strike paralyzed IT infrastructure across roughly 200 Swedish municipalities and regional authorities.
  • November 2025 — ENISA Secures CVE Root Status: ENISA officially became a root authority within the Common Vulnerabilities and Exposures (CVE) program, empowering the agency to directly assign identifiers to newly discovered security flaws as vulnerability volumes surged 22% year-over-year to exceed 48,000 new CVEs.
  • September 22, 2026 — Official Publication: ENISA formally publishes the ENISA Threat Landscape 2026, accompanied by leadership warnings regarding systemic cyber dependencies and the urgent need for a new standard of organizational vigilance.
  • September 11, 2026 — Implementation of the Cyber Resilience Act: A critical regulatory milestone takes effect, requiring hardware and software manufacturers across the European Union to report actively exploited vulnerabilities and severe security incidents directly to national CSIRTs via a centralized EU platform, with simultaneous notification flowing to ENISA.

Supporting Data

A granular review of ENISA’s metrics illustrates how threat actors distributed their efforts across sectors, techniques, and geopolitical objectives during the 2025 evaluation period:

Incident Classifications and Objectives

  • Ideology-Driven Activity: 57.3% of total assessed objectives. Within this category, pro-Russian hacktivist collective NoName057(16) alone accounted for 48% of all ideology-driven activity, directing 89% of its campaigns toward DDoS strikes against EU member states. However, ENISA independent verification checks on claims made by NoName057(16) between July and November 2025 revealed that only 23.8% held up against third-party availability audits, indicating that a substantial portion of hacktivist claims serve psychological and influence operations rather than true operational disruption.
  • Financially Motivated Activity: 29.3% of total objectives. Within this high-impact vertical, ransomware led at 47.3% of claims, followed by data breaches at 36%, and fraud/impersonation at 13.3%.
  • Cyberespionage: 5.9% of total objectives. ENISA notes that while espionage claims appear smaller in volume, their long-term strategic damage to intellectual property and state security is profound, noting that espionage campaigns routinely take anywhere from six months to over four years to be publicly uncovered.

Geographic and Sectoral Distribution

  • Targeted Sectors: Public administration absorbed 31.8% of recorded events. Overall, essential and important entities governed under the EU’s NIS2 Directive represented 73% of total recorded events, validating the regulatory focus of the directive, though discrepancies remain between ENISA’s open-source dataset and formal member-state reports submitted under NIS2 frameworks.
  • Ransomware Geographics: Germany led EU member states in receiving ransomware claims at 26.5%, while the manufacturing sector absorbed the heaviest industry share at 25.2%. The most active ransomware and extortion gangs operating within the EU theater included Qilin, SafePay, Akira, INC Ransom, and Hunters International.

Official Responses

Reacting to the release of the threat landscape report, executive leadership at ENISA emphasized that Europe’s security posture must adapt to an era of hyper-interconnected digital infrastructure.

"The analysis highlights how threats become more interconnected and how threat groups spread their impact across the larger map of digital services and infrastructures," stated ENISA Executive Director Juhan Lepassaar during the launch.

Lepassaar underscored that modern cyber defense can no longer rely on perimeter-based security or reactive compliance checklists. Instead, organizations must acknowledge that their operational resilience is inextricably bound to the security practices of third-party software vendors, cloud service providers, and outsourced IT suppliers.

The European Commission echoed these sentiments in statements surrounding the enforcement of the Cyber Resilience Act, stressing that automated, centralized vulnerability reporting is no longer optional if the EU is to stem the tide of supply chain exploitation.


Implications

For CISOs, information governance professionals, legal counsel, and eDiscovery practitioners, the ENISA Threat Landscape 2026 report serves as both a warning and a strategic roadmap. The data demands several immediate operational shifts:

1. Modernizing Incident Planning for Data Exfiltration over Encryption

Because 73.3% of financially motivated operations now prioritize data exfiltration over command-and-control channels rather than outright file encryption (13.7%), traditional disaster recovery backups are no longer an adequate defense against extortion. Organizations can no longer rely solely on immutable backups to restore operations. Instead, data maps, robust retention schedules, and rigorous data minimization must be integrated directly into incident response plans. Every unmapped file share, dark data repository, and over-retained mailbox represents a latent breach notification liability under the GDPR.

2. Verification Before Panic: Navigating Unverified Breach Claims

ENISA’s findings highlight a growing trend of opportunistic extortion, where criminal forums (such as darkforums.st, which accounted for 58% of forum-based breach listings evaluated) list unverified or recycled corporate data. Legal and privacy teams must establish formal verification protocols to confirm whether claimed data actually left corporate environments before initiating costly legal holds, public disclosures, or notification campaigns driven purely by criminal forum noise.

3. Supply Chain Governance and Vendor Risk Audits

With malicious actors increasingly weaponizing software repositories, browser extensions, and third-party integrations (exemplified by the npm package risks and the Collins Aerospace passenger-processing disruption), enterprise vendor risk management must mature. Legal teams must embed strict, enforceable notification timelines into vendor contracts, while technical teams must continuously audit OAuth tokens, standing administrative privileges, and integrations between SaaS platforms like Salesforce, Microsoft 365, SharePoint, and Google BigQuery.

4. Preparing for the AI-Driven Threat Horizon

While ENISA observed that cybercriminals in 2025 primarily utilized off-the-shelf consumer artificial intelligence tools to optimize existing workflows rather than invent novel attack vectors, the agency warns that 2026 will likely usher in human-out-of-the-loop, AI-native attack chains. Concurrently, internal AI deployments are becoming prime targets for adversaries seeking to harvest credentials, access developer environments, and compromise sensitive browser sessions. Security leaders must proactively secure their enterprise AI pipelines with the same rigor applied to core database infrastructure.

Ultimately, ENISA’s 2026 assessment forces a sobering question for corporate governance boards across Europe: When a trusted supplier is compromised, do you know which vendor will pick up the phone to warn you first—and does your organization have the data visibility to verify the damage before the headlines break?