The ENISA Threat Landscape 2026 Report is out, offering a good look into the cyber threats across the EU.
This year's findings show a landscape that, as expected, was impacted by geopolitics, AI, and the increased exploitation of supply chains & digital dependencies. What is worrisome: Critical sectors remain by far the most exposed and the most underprepared.
Some key points from the report:
🔷 Geopolitical developments drive a large number of operations within the EU. Ideology-driven attacks accounted for a 57.3% of recorded incidents, largely via massive DDoS campaigns. Critical entities are bearing the brunt of this activity.
🔷 Public administration not only remains (by far) the most targeted sector, it also remains in the higher ends of the cyber risk zone, where criticality exceeds observed cybersecurity maturity.
🔷 Adversaries are heavily targeting cyber dependencies, including third-party IT management providers and (digital) supply chains with several examples of large-scale and/or impactful incidents throughout the year.
🔷 Financially motivated attacks and particularly ransomware remain the most significant short-term threat. Ransomware operators increasingly reliy on data exposure and sophisticated extortion tactics via Data Leak Sites (DLS) and dark web forums, followed by social engineering techniques targeting credentials.
🔷 Social engineering acts as a primary enabler for major breaches, with phishing campaigns accounting for 77.8% of these tactics. (Personal note: phishing as a term goes far beyond emails and includes smishing, QR-phishing, etc.) Frequent evasion techniques found in the report included ClickFix and smishing campaigns.
🔷 AI in malicious operations keeps expanding actively and is accelerating the Kill Chain. ENISA expects to see an increased number of the kill chain’s phases being directly enabled by AI, with possible experimentation of Human-out-of-the loop proof of concepts in the coming year.
All in all, the lines between cybercrime, state-nexus activities, and hacktivism keep blurring. Threat groups are increasingly relying on similar access vectors, vulnerabilities, and techniques, making attribution harder and defense more complex.
The threat landscape developments further support the idea that reactive defense is a losing strategy, and should belong to the past. It is time to double down on a strategy oriented towards prevention and organizational resilience, and to align security planning with NIS2.
May the odds be ever in our favor. The report:
https://www.enisa.europa.eu/publications/enisa-threat-landscape-2026