# ENISA publishes its 2026 assessment of Europe’s cyber threat landscape

> In its review of 2025 incidents, ENISA said public administration accounted for 32% of targeted organisations and low-impact DDoS attacks for 51% of recorded cases.

- Canonical URL: https://newsverum.com/en/news/enisa-threat-landscape-2026-report-september
- Publisher: Newsverum
- Section: Security
- Published: 2026-10-06T08:58:59+00:00
- Updated: 2026-10-07T05:57:25+03:00
- Event / data period: 2025
- Other editions: [Türkçe](https://newsverum.com/tr/news/enisa-threat-landscape-2026-report-september.md), [العربية](https://newsverum.com/ar/news/enisa-threat-landscape-2026-report-september.md), [Français](https://newsverum.com/fr/news/enisa-threat-landscape-2026-report-september.md), [Español](https://newsverum.com/es/news/enisa-threat-landscape-2026-report-september.md), [Deutsch](https://newsverum.com/de/news/enisa-threat-landscape-2026-report-september.md), [Português](https://newsverum.com/pt/news/enisa-threat-landscape-2026-report-september.md)

ENISA published its European Threat Landscape report on 22 September 2026, reviewing events observed from 1 January through 31 December 2025. The agency said it used open sources, anonymised information shared by EU member states and data from its Cyber Partnership Programme. It described ransomware as the most impactful short-term incident type.

The report said 73% of targeted organisations were essential or important entities under the NIS2 definition, while public administration was the most targeted sector at 32% of cases. Low-impact DDoS attacks made up 51% of recorded incidents. These figures describe ENISA’s 2025 reporting set and are not a forecast.

## Data

### Security development

Security event or institutional action reported by the source.

Methodology: The event date and description summarise the action reported by the source; no additional measurement or forecast is made.

| date | label | description | status |
|---|---|---|---|
| 2026-09-22 | ENISA published its 2026 Threat Landscape | The report assessed events observed during 2025; public administration accounted for 32% of targeted organisations, while 51% of recorded incidents were low-impact DDoS attacks. | occurred |

Sources: <https://www.enisa.europa.eu/news/exploring-the-evolution-of-the-cyber-threat-landscape-how-dependencies-weaken-our-digital-resilience> · Download data: [JSON](https://newsverum.com/api/v1/articles/enisa-threat-landscape-2026-report-september/data/security-event?lang=en&format=json) · [CSV](https://newsverum.com/api/v1/articles/enisa-threat-landscape-2026-report-september/data/security-event?lang=en&format=csv)

### Measure reported by the source

Key quantitative figure stated by the source.

Methodology: Value is reproduced as stated by the source; a qualifier marks an approximate or bounded figure.

| label | value | unit | period | basis | value_qualifier |
|---|---|---|---|---|---|
| Share of analysed events classified as cybercrime | 36 | percent | 2025 | observed | exact |

Sources: <https://www.enisa.europa.eu/news/exploring-the-evolution-of-the-cyber-threat-landscape-how-dependencies-weaken-our-digital-resilience> · Download data: [JSON](https://newsverum.com/api/v1/articles/enisa-threat-landscape-2026-report-september/data/security-figures?lang=en&format=json) · [CSV](https://newsverum.com/api/v1/articles/enisa-threat-landscape-2026-report-september/data/security-figures?lang=en&format=csv)

## Sources

- [European Union Agency for Cybersecurity (ENISA)](<https://www.enisa.europa.eu/news/exploring-the-evolution-of-the-cyber-threat-landscape-how-dependencies-weaken-our-digital-resilience>) (Source checked: 2026-10-06; Published: 2026-09-22)

## Correction history

- 2026-10-07T00:50:40+03:00: German and Portuguese editions and translations of the data and correction explanations have been added to this article.
- 2026-10-07T05:57:25+03:00: Data classification added: each figure now carries a measure identifier with its unit, geography, frequency and type. No figure, unit or date changed.

---

Cite the canonical URL above. [Editorial standards and corrections](https://newsverum.com/en/editorial)
