ENISA’s 2026 report identifies ransomware, vulnerability exploitation and AI-enabled attacks as leading EU cyber threats

ENISA’s 2026 threat landscape finds that ransomware, vulnerability exploitation and the growing use of AI are reshaping the European cyber threat environment, with existing threats increasingly converging.

ENISA’s 2026 report identifies ransomware, vulnerability exploitation and AI-enabled attacks as leading EU cyber threats

The European Union Agency for Cybersecurity (ENISA) has published its Threat Landscape 2026, analysing cyber incidents and events recorded between January and December 2025. The report finds that the European cyber threat environment is increasingly characterised by the convergence and scaling of existing threats rather than the emergence of entirely new forms of attack.

Cybercrime, state-linked activity, hacktivism and vulnerability exploitation are increasingly drawing on overlapping tools, techniques and digital dependencies. ENISA’s assessment highlights ransomware, vulnerability exploitation and the growing use of artificial intelligence by threat actors as key features of the current threat landscape.

Ransomware remains a major short-term threat. It accounted for 40% of analysed financially motivated cybercrime events, while cybercrime overall represented 36% of recorded events in the report’s classification. Ransomware operations continue to combine data theft, encryption and extortion, supported by an established ecosystem involving access brokers, stolen credentials and specialised services.

Vulnerability exploitation is another major entry point for attacks. Among incidents where the initial intrusion vector could be identified, 60% involved exploitation of a vulnerability. ENISA notes that both known and zero-day vulnerabilities remain relevant, making the period between the discovery of a vulnerability and its exploitation particularly important for defenders.

The report links this risk to growing digital interdependence. Vulnerabilities affecting a product, software component or service provider can expose multiple organisations, while supply-chain attacks and third-party compromises can extend the impact of an individual weakness across sectors.

Artificial intelligence is increasingly being incorporated into existing attack methods. ENISA identifies its use in activities including social engineering, phishing, reconnaissance and content generation. Rather than necessarily creating entirely new attack models, AI can reinforce established techniques by increasing their scale and speed. The report also points to increasingly service-based phishing ecosystems and the growing use of techniques such as ClickFix.

Geopolitical developments are also reflected in the threat landscape. Distributed denial-of-service (DDoS) attacks accounted for 51% of recorded incidents, with many linked to geopolitical events or political statements. Public administration was the most targeted sector, representing 32% of targeted organisations, while 73% of targeted organisations were classified as essential or important entities under the NIS2 framework.

ENISA points to increasingly blurred boundaries between different categories of threat actors. Cybercriminals, hacktivists and state-linked actors may reuse similar infrastructure, tools and access mechanisms, making the European cyber environment more interconnected and difficult to assess through individual threat categories alone.

Go to Top