EU Faces Rising Cyber Threats in 2025: Ransomware, Hacktivism, and AI-Driven Attacks Surge

September 22, 2026
EU Faces Rising Cyber Threats in 2025: Ransomware, Hacktivism, and AI-Driven Attacks Surge
  • The EU cyber threat landscape in 2025 is dominated by recurrent threats—ransomware, geopolitically influenced activity, and hacktivism—with public administration the most targeted sector.

  • Artificial intelligence is increasingly embedded in attack models to enhance social engineering, phishing, reconnaissance, and content generation, rather than replacing traditional methods.

  • Some campaigns used trusted messaging platforms to guide targets through legitimate authentication, enabling access to compromised devices.

  • Attacks on third-party providers, cloud environments, and software supply chains widened impact, as breaches at one supplier could disrupt many customers through compromised libraries, repositories, and browser extensions.

  • Threat actors are reusing tools while introducing new attack models; supply-chain and third-party attacks remain prominent and impactful.

  • The core message is convergence and scaling of threats, not new threat types, with cybercrime, state activity, hacktivism, and vulnerability exploitation using overlapping tools and dependencies.

  • Geopolitical developments continue to shape cyber activity, driving DDoS campaigns against essential entities and broadening the mix of threat activity.

  • ENISA expects cybercrime, cyberespionage, and hacktivist activity to persist into 2026, with threat actors sharing tools, increasing AI-enabled capabilities, and expanding exposure due to digital dependencies and cloud use.

  • Threat groups reuse tools, adapt attack models, exploit vulnerabilities, and collaborate to target the EU’s digital infrastructure, including supply-chain and third-party attacks.

  • Phishing accounted for 77.8% of social engineering techniques in EU incidents, with growing use of ClickFix and continued exploitation of software vulnerabilities (intrusions in 5.2% of unauthorized-access incidents; 60.4% of that subset involved vulnerability exploitation).

  • Cybercriminal, hacktivist, and state-nexus groups are converging in methods, access vectors, and tools, complicating attribution and tracking, with new groups likely to continue emerging.

  • Threat vectors were diverse, with DDoS (51.3%), unauthorized access (39.5%), phishing (77.8%), and vulnerability exploitation (60.4%) as major intrusion methods; over 48,000 new vulnerabilities were reported, a 22% year-on-year increase.

Summary based on 6 sources


Get a daily email with more Tech stories

More Stories