ENISA published its Threat Landscape 2026 on 22 September, covering 8,257 incidents that hit organisations in the European Union during 2025. Just over half (51.3%) were denial-of-service attacks, mostly claimed by ideologically motivated hacktivist groups. That skews the report's headline figures, not least the ones that will be quoted most in the coming weeks.
Public administration tops the list of targeted sectors with 31.8% of cases, yet 81.8% of that is DDoS. When the report attributes 72.9% of recorded incidents to essential entities under NIS2, the count works the same way: a municipal website knocked offline for an afternoon weighs as much as an intrusion that ends in data theft.
For a town hall coping with intermittent outages, those numbers fit. For a manufacturer or a services firm wondering where its next ransomware incident will come from, they are close to useless. The material that reader needs is tucked into the sections on intrusion, extortion and dependencies.
What is left of the report once DDoS is set aside?
The split by motive tells the same story. According to the full report, 57.3% of recorded activity was ideologically driven, 29.2% financially motivated and 6.3% espionage. ENISA nonetheless judges profit-driven activity to be the most damaging short-term threat to European organisations.
Intrusions: 39.5% of incidents
Unauthorised access is the second-largest category, and it is where ransomware, data theft and espionage sit: the incidents that end in a breach notification, a NIS2 incident report or a production line standing idle.
Six in ten intrusions with a known entry point began with a vulnerability
ENISA could establish the attacker's entry point for 5.2% of unauthorised-access incidents. Within that subset, 60.4% exploited a vulnerability and 20.7% took advantage of a misconfiguration or an accidental exposure. That is four in five documented intrusions, through weaknesses that were, in principle, within a defender's reach.
The 5.2% matters more than the 60.4%. The report leans mainly on open sources and on anonymised information shared by member states, and ENISA acknowledges that this falls short of a complete picture. For every other intrusion those sources never revealed the way in, the same blank found in many breach notices that leave out the root cause. The 60.4% is a fair account of the documented cases and says nothing reliable about the rest.
In reported ransomware, exfiltration outweighs encryption
When ENISA breaks down the techniques attributed to ransomware operators, data exfiltration over the command-and-control channel (T1041 in MITRE ATT&CK) turns up in 73.3% of cases, while data encryption (T1486) appears in 13.7%. Qilin, SafePay, Akira, INC Ransom and Hunters International rank among the most active operators in the EU.
The ratio reflects how attacks get written up in public, not how often something was actually encrypted. Still, it matches what incident responders have been reporting for a while: the harm increasingly happens when data leaves the network, and less when servers stop booting.
One supplier, two hundred public bodies
A section on what ENISA calls cyber dependencies carries the report's clearest supply chain example: a ransomware attack on a Swedish IT supplier that reached around 200 municipalities and regional authorities and disrupted the systems they relied on for HR. The agency also points to tampering with popular libraries and npm packages, Shai-Hulud among them, and to criminal groups increasingly going after third-party providers, most likely to get more out of each attack.
The pattern holds beyond Europe. Verizon puts third-party involvement at 48% of the breaches it examined, up 60% on the previous year. At that level, supplier risk deserves to be handled as an attack route in its own right, and not just as a section of the procurement questionnaire.
AI speeds attackers up but has not changed how they work
The report is more measured on artificial intelligence than much of the commentary. Groups are folding it into their operations, ENISA says, but mainly through consumer-grade tools that extend skills they already had, with no leap in capability. One AI-assisted cloud intrusion is reported to have reached administrator rights within eight minutes.
For defenders, the lesson comes down to timing. When an intruder can escalate in minutes, every hour it takes to notice the initial foothold costs the victim more.
How does it differ from last year's edition?
The previous edition covered July 2024 to June 2025 and gathered 4,875 incidents. DDoS made up 76.7% of them and intrusions 17.8%. Among observed entry vectors, phishing accounted for roughly 60% and vulnerability exploitation for 21.3%.
Reading that as exploitation tripling in a year would be a mistake. The two periods overlap by six months, this edition widens its tracking of cybercrime, and the bases differ: the 2026 figure of 60.4% covers only intrusions with an identified vector, while phishing now appears as 77.8% of social engineering techniques, a different denominator altogether. ENISA adds that the wider scope did not substantially change trends or rankings. The rankings do hold, even though the shares have shifted considerably: DDoS still comes first and intrusion second.
One conclusion does survive scrutiny, because a second source with its own method backs it. Verizon's 2026 Data Breach Investigations Report, drawn from more than 22,000 confirmed breaches worldwide, ranks vulnerability exploitation as the leading initial access route for the first time, at 31% of breaches against 13% for credential abuse, as SecurityWeek and Help Net Security report. A European dataset assembled from open sources and a global one assembled from breach investigations put the same route on top. That agreement is the firmest result the report offers.
How should defensive architecture change?
When the best-documented way in is a known flaw, what matters is how long an organisation takes to close the vulnerabilities being exploited, not how many it has. The DBIR supplies the benchmark: median remediation time went from 32 to 43 days, and only 26% of the vulnerabilities in CISA's KEV catalogue were fully fixed.
Three practical consequences follow:
- Rank patching by observed exploitation. The KEV catalogue, EPSS scores and a decision tree such as SSVC produce a better order than CVSS alone, as we set out when explaining how to combine KEV, EPSS and SSVC.
- Look at the edge first. VPNs, firewalls and remote access gateways face the internet and do not run an endpoint agent, which is why network devices that EDR cannot see need telemetry of their own.
- Handle configuration as a vulnerability in its own right. Misconfigurations and accidental exposures (20.7%) carry no CVE and no patch; they only come to light through continuous review of the attack surface and of cloud security settings.
Theft-based extortion also changes where detection should look. If the harm is done as data leaves, outbound telemetry is what counts: unusual volumes from servers that seldom talk to the internet, sustained sessions to unsanctioned storage services, sync tools that turn up with no approved change behind them. Well-segmented networks also limit how far an intruder gets before starting to move data out.
Dependencies, finally, push the question beyond an organisation's own perimeter. Nothing prevents the Swedish case recurring with a different supplier: a platform shared by hundreds of customers turns one intrusion into a sector-wide incident. Third-party risk management needs more than an annual questionnaire; it has to know what data each supplier holds, what access it keeps and how quickly it will raise the alarm.
Do the usual controls still hold?
The report gives reasons to keep three. The first is phishing-resistant multi-factor authentication, since phishing remains the most cited social engineering technique (77.8%). The second is immutable backup, because encryption has not gone away, even if it features less prominently. The third is DDoS protection for exposed services, which for a public body is still the most frequent risk in the count.
Three habits no longer stand up. One is treating backups as the ransomware plan when extortion increasingly rests on what was stolen. Another is measuring vulnerability management by the number of patches applied rather than by the time exploited flaws stay open. The last is reading a sector ranking from an aggregate report as if it were one's own risk profile: public administration's 31.8% tells a component manufacturer very little.
What the report cannot know, and what each organisation can
ENISA itself warns that espionage campaigns tend to surface anywhere from six months to more than four years after the fact, and that more reporting on a threat does not mean more activity. The 2026 edition describes 2025 through whatever came to light, and later editions will revise some of what looks settled now.
An entity within the scope of NIS2 cannot afford the same uncertainty about its own incidents. Article 23(4) of the NIS2 Directive requires a final report that identifies the type of threat or the likely root cause. An organisation that has not kept the right logs in its SIEM, or has not prepared its incident response for a forensic investigation, will reach that report unable to answer the question the Directive puts to it.
Mandatory NIS2 notifications are starting to build up root-cause data that no open source can match. If ENISA folds them into its analysis, the 2027 edition could be the first to describe attackers' entry routes into European organisations on the strength of more than a small minority of documented cases. If it does not, the count will keep growing while the issue that matters most to defenders is answered from one intrusion in twenty.
This analysis draws on the ENISA Threat Landscape 2026 and the Verizon DBIR 2026 as published on 26 September 2026. The percentages come from those sources and rest on different bases, so they are not comparable with one another without the context given in each case. Applying them to any single organisation means testing them against its own telemetry and incident history.
Frequently asked questions
Why does public administration come out as the most targeted sector?
▾
Because the count weighs volume, not impact. Most of what public bodies receive is ideologically driven denial-of-service activity, which is plentiful and easy to claim. Comparing yourself with another sector through that ranking gets you little; the intrusion category, and the kind of actor that dominates it, is a far better guide.
Does the 60.4% figure mean most attacks start with a vulnerability?
▾
It means that is what happened in the cases where the entry point is known, which is one in twenty unauthorised-access incidents in the report. Extending it to the whole set is not safe. What gives it weight is that Verizon's 2026 DBIR, using a different method and a different pool of breaches, also puts exploitation ahead of credential abuse.
Can the 2026 figures be compared with the 2025 Threat Landscape?
▾
The relative positions, yes; the percentages, no. When presenting the trend to a board, the safe line is that DDoS still dominates the count, intrusion remains second and, where the entry point is known, vulnerability exploitation stands out, which the DBIR confirms independently. Any claim along the lines of 'it has tripled' mixes bases that ENISA does not calculate the same way.
How should an incident response plan change if exfiltration outweighs encryption?
▾
Restoring systems no longer closes the incident. The team has to establish what data left, weigh the notifications required under GDPR and NIS2, and decide how to handle the extortion demand. That calls for the ability to review outbound traffic from the preceding days, an inventory of where sensitive data sits, and criteria agreed in advance for telling customers and regulators.
Does the report matter to a company that is neither an essential nor an important entity?
▾
Yes, through its customers. NIS2 requires in-scope entities to manage security across their supply chain, so a supplier to an essential entity will face questions and contractual demands about patching, detection and incident notification. The Swedish ransomware case, with some 200 public bodies hit through a single supplier, is exactly what prompts those questions.
What does NIS2 require on the root cause of a significant incident?
▾
Article 23(4) calls for a final report no later than one month after the incident notification, with a detailed description, the type of threat or root cause likely to have triggered it, the mitigation measures applied and under way and, where relevant, its cross-border impact. The clock runs from the notification, so reconstruction work has to be able to start on day one, with the logs already at hand.
How should a risk committee use the ENISA Threat Landscape?
▾
As an outside benchmark rather than a risk profile of its own. Three simple exercises help: compare the report's categories with the incidents and near misses the organisation actually had during the year; check whether the actual time to fix exploited vulnerabilities beats the 43-day median in the DBIR; and ask critical suppliers how they would spot someone pulling data out of their platform.