research • Help Net Security

ENISA Threat Landscape 2026: Europas teknologiske ryggrad blir primært cybermål

ENISA analyserte 8 257 hendelser i 2025: DDoS dominerer (51,3 %), offentlig forvaltning er hardest rammet (31,8 %), og sårbarhetsutnyttelse utgjør 60,4 % av identifiserte innbruddsmetoder. Svenske kommuner nevnes etter leverandør-ransomware.

ENISA Threat Landscape 2026: Europas teknologiske ryggrad blir primært cybermål

The EU Agency for Cybersecurity, ENISA, published its annual Threat Landscape report on September 24, 2026, mapping 8,257 documented incidents from January 1 through December 31, 2025. The picture is stark: Europe's digital infrastructure — especially public administration, transport, and business services — faces simultaneous pressure from cybercrime, state-linked actors, FIMI (Foreign Information Manipulation and Interference), hacktivism, and mass vulnerability exploitation. Executive Director Juhan Lepassaar warns these are no longer isolated disruptions but interconnected stresses on the continent's technology backbone.

Attack typology is dominated by availability assaults. DDoS accounted for 51.3 percent of all incidents, followed by unauthorized access at 39.5 percent. Within public administration — which alone represented 31.8 percent of reported events — DDoS made up a remarkable 81.8 percent of cases. That explains why citizen services, school portals, and municipal websites often become the first visible casualty even when underlying data theft happens elsewhere.

Sector distribution shows the threat spreading beyond finance and telecom. After public administration come business services (8.5 percent), transport (8.0), manufacturing (6.9), and finance (5.6). Among financially motivated incidents, data breaches comprised 38.4 percent and ransomware claims 36 percent — nearly even, suggesting actors pick methods based on victim payment appetite and backup maturity rather than a single playbook.

Social engineering remains the dominant entry path. Phishing represented 77.8 percent of social attacks, while ClickFix — tricking users into running malicious commands disguised as «troubleshooting» — is rising fast. ENISA also highlights more personal channels: Signal and WhatsApp guide victims through legitimate authentication flows, making fraud harder to distinguish from genuine IT support.

Among unauthorized-access incidents, method could be identified in only 5.2 percent — an important methodological caveat — yet within that subset, vulnerability exploitation accounted for 60.4 percent. That aligns with this week's urgent patching of network products and CMS platforms: attackers prioritize known zero-day and n-day flaws over slow credential guessing.

The report dedicates significant attention to AI: generative tools fuel phishing, fraud, reconnaissance, malware development, and multilingual FIMI content, while AI applications themselves become targets. For Sweden, ENISA cites ransomware against an IT supplier affecting roughly 200 municipalities and regions — especially HR systems — showing how supply-chain risk scales to entire democratic institutions when one subcontractor falls.

Lepassaar concludes that cybersecurity is now cross-border and cross-sector: a DDoS against an agency can mask exfiltration, FIMI can amplify ransomware negotiations, and hacktivism can provide plausible deniability for state actors.

Evidence Rail

  • Confirmed: ENISA Threat Landscape 2026 (8,257 incidents, Jan–Dec 2025); sector and attack-type statistics; Juhan Lepassaar quote.
  • Reported: Swedish IT supplier ransomware ~200 municipalities/regions; ClickFix trend; Signal/WhatsApp personalized fraud.
  • Unconfirmed: Whether 2025 figures capture unreported incidents beyond ENISA sources.

Concrete steps for IT and security leaders

  • Treat DDoS protection as standing capacity for public services, not a project.
  • Prioritize vulnerability management and patch SLAs for external-facing systems — 60.4% of known intrusion methods are exploit-driven.
  • Train staff on ClickFix and messaging-app fraud outside email (Signal/WhatsApp).
  • Map supplier dependencies with the same rigor as internal systems; one HR vendor can halt entire municipalities.
  • Integrate FIMI monitoring into incident processes when events carry political or electoral dimensions.

In Brief

  • 8,257 incidents in 2025: DDoS 51.3%, public sector 31.8% of all events.
  • Phishing 77.8% of social engineering; vulnerability exploit dominates where method is known.
  • Sweden cited via supplier ransomware hitting ~200 municipalities — supply chain in practice.

Kilder og referanser

← Alle nyheter Verktøy