ENISA publishes its 2026 assessment of Europe’s cyber threat landscape
In its review of 2025 incidents, ENISA said public administration accounted for 32% of targeted organisations and low-impact DDoS attacks for 51% of recorded cases.
Event / data period: 2025
Published: · Updated:
ENISA published its European Threat Landscape report on 22 September 2026, reviewing events observed from 1 January through 31 December 2025. The agency said it used open sources, anonymised information shared by EU member states and data from its Cyber Partnership Programme. It described ransomware as the most impactful short-term incident type.
The report said 73% of targeted organisations were essential or important entities under the NIS2 definition, while public administration was the most targeted sector at 32% of cases. Low-impact DDoS attacks made up 51% of recorded incidents. These figures describe ENISA’s 2025 reporting set and are not a forecast.
Data
Security development
Security event or institutional action reported by the source.
- · Occurred
ENISA published its 2026 Threat Landscape
The report assessed events observed during 2025; public administration accounted for 32% of targeted organisations, while 51% of recorded incidents were low-impact DDoS attacks.
Methodology
The event date and description summarise the action reported by the source; no additional measurement or forecast is made.
Updated:
Measure reported by the source
Key quantitative figure stated by the source.
- Share of analysed events classified as cybercrime
- 36 percent
- 2025 · Observed
Methodology
Value is reproduced as stated by the source; a qualifier marks an approximate or bounded figure.
Updated:
Subjects and places
Subject proposals
- Cyber crimeSuggested
- Subject suggested from the title or summary: cyber threatwww.enisa.europa.eu ↗