The European Union’s digital infrastructure is under sustained pressure from a growing mix of cyber adversaries, according to the ENISA Threat Landscape 2025 report.
Analysing 4,875 incidents between July 2024 and June 2025, ENISA found that diverse threat groups are increasingly reusing each other’s tools and techniques, blending tactics and even collaborating across ideological and criminal lines. This convergence, the agency warns, is amplifying the scale and impact of attacks on EU organizations.
Distributed Denial of Service (DDoS) attacks dominated the reporting period, accounting for 77% of incidents – the majority carried out by hacktivists. While most such campaigns caused little disruption, they drove a surge in ideology-driven attacks, which made up nearly 80% of all cases. Ransomware, however, was judged the most damaging single threat.
Public administration emerged as the most targeted sector, with 38% of incidents, followed by transport, digital infrastructure, finance and manufacturing. ENISA noted that these align closely with sectors covered under the EU’s NIS2 Directive, underscoring its importance.
Phishing remained the leading entry point for intrusions, representing 60% of observed cases, with criminals increasingly turning to ‘Phishing-as-a-Service’ kits. The report also highlights the growing role of artificial intelligence in both enabling and exposing new attack vectors, with AI-supported phishing accounting for over 80% of global social engineering activity by early 2025.






