Europe's cybersecurity agency, ENISA, analyzed 8,257 incidents from 2025 to compile its latest Threat Landscape report. Distributed denial-of-service attacks dominated, representing 51.3% of cases, while unauthorized access followed at 39.5%. Hacktivist groups drove much of the DDoS activity, often aimed at government websites during elections, law enforcement operations, and geopolitical tensions.

The report highlights how attacks on shared technology providers can have cascading effects. One ransomware hit on a Swedish IT supplier disrupted services for roughly 200 municipalities. Public administration suffered the most overall at 31.8% of incidents, with business services, transport, manufacturing, and finance trailing behind.

Phishing remained the most common social engineering technique, appearing in 77.8% of identified cases. Attackers also exploited software vulnerabilities and used trusted messaging platforms to trick users. ENISA noted a rise in ClickFix tactics, which trick people into running malicious commands disguised as troubleshooting steps.

Artificial intelligence is now embedded in cybercriminal operations, helping create tailored phishing messages, automate reconnaissance, and produce disinformation content. AI-powered applications themselves are becoming targets, as they often connect to sensitive data and development environments. ENISA's executive director stressed that threats are increasingly interconnected, requiring a broader view of resilience across Europe's digital economy.