Editor’s Note: Ransomware and supplier compromises, not the DDoS attacks that make up most of the count, are where the ENISA Threat Landscape 2026 places the short-term impact, while cyberespionage remains the agency’s longer-term concern. The EU cybersecurity agency analyzed 8,257 incidents from 2025 and found financially motivated attacks remained the most impactful threat in the short term, and its review of ransomware techniques likely confirms a tilt toward data theft and extortion.

For cybersecurity, data privacy, regulatory compliance and eDiscovery professionals, that shift makes data maps, retention schedules and vendor contracts part of incident response, and ENISA’s caution that forum breach listings could not be verified bears directly on notification decisions. The report also arrives as Cyber Resilience Act reporting of actively exploited vulnerabilities takes hold. One practical point: several figures in ENISA’s Sept. 22 press release differ from the report, so the report is the version to cite.

Watch for whether ENISA’s expectation that AI will likely enable more stages of attacks in 2026 shows up in incident data.


Content Assessment: ENISA Threat Landscape 2026 finds DDoS leads incident counts while ransomware stays most impactful in the short term

Information - 94%
Insight - 93%
Relevance - 94%
Objectivity - 92%
Authority - 94%

93%

Excellent

A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "ENISA Threat Landscape 2026 finds DDoS leads incident counts while ransomware stays most impactful in the short term."


News Analysis – Cybersecurity Beat

ENISA Threat Landscape 2026 finds DDoS leads incident counts while ransomware stays most impactful in the short term

ComplexDiscovery OÜ Staff

Distributed denial-of-service attacks made up just over half of the 8,257 incidents the EU cybersecurity agency ENISA analyzed for 2025, but its newest threat report says the activity with the most impact came from elsewhere.

Financially motivated attacks, ransomware above all, remained the most impactful threat to organizations in the short term, the European Union Agency for Cybersecurity said in the ENISA Threat Landscape 2026, published Sept. 22. The agency’s announcement led with a related warning: cyber dependencies “expand the attack surface,” it said, and require “a new level of vigilance.” The report ties those dependencies to supply chains, third-party providers and cloud environments, whose compromise kept producing large-scale, impactful incidents during 2025.

That pairing matters for cybersecurity, information governance and eDiscovery practitioners, because it separates the activity that fills the charts from the activity ENISA ties to disruption and data loss. ENISA describes most of that volume as low-impact and short-lived. The exposure that reaches breach notices and legal holds tends to sit in the smaller financially motivated categories, the ones ENISA ranks as most impactful in the short term. Before anyone repeats the report’s totals, though, its own caveats deserve a close read.



What 8,257 incidents can and cannot tell you

ENISA built the 101-page report from incidents recorded between Jan. 1 and Dec. 31, 2025, drawing mainly on open sources plus anonymized data from EU member states and from participants in the agency’s Cyber Partnership Programme. This edition moved to a calendar year, so its period overlaps the previous edition by six months. ENISA also widened the cybercrime activity it tracks, including data breaches and fraud, and said that change affected the numbers without substantially changing the trends or rankings.

Those design choices matter for anyone tempted to compare totals across years. The 2025 edition analyzed 4,875 incidents from July 2024 through June 2025, according to ENISA’s publication listing. Because collection expanded between editions, the rise to 8,257 is not a like-for-like measure of more attacks. ENISA calls the report a snapshot of prevailing trends, and it warns that espionage campaigns typically come to light six months to over four years after they occur. Heavier reporting on a threat, the agency added, can reflect audience interest rather than a faster tempo of activity.

Noise at volume, impact elsewhere

Those caveats shape how the headline split should be read. By ENISA’s classification of assessed objectives, ideology-driven activity accounted for 57.3 percent of incidents, financially motivated activity for 29.3 percent and cyberespionage for 5.9 percent. DDoS led incident types at 51.3 percent, followed by unauthorized access at 39.5 percent. ENISA said the ideology-driven claims, though the most numerous, produced no large-scale impact, and its methodology section calls cyberespionage “a more impactful threat in the long term.”

The agency counted 4,709 claims by hacktivists against EU member states, and over 89 percent of them involved DDoS. The pro-Russia group NoName057(16) alone accounted for 48 percent of ideology-driven activity. ENISA’s own analysis tempers those totals. When the agency examined NoName057(16) activity from July through November 2025, only 23.8 percent of the claims it assessed held up against independent third-party availability checks. ENISA said the gap suggests some claims “may have served an influence objective by inflating perceptions of operational impact.”

Public administration remained the most targeted sector at 31.8 percent of recorded events, and ideology-driven DDoS made up 81.8 percent of incidents in that sector. Essential and important entities under the NIS2 Directive represented 73 percent of recorded events, which ENISA, an agency that publishes NIS2 implementation guidance, said confirms the relevance of the directive’s approach. Member-state reporting under NIS2 paints a somewhat different picture. Of the 1,954 events member states had reported under the directive as of July 14, 2026, the top five sectors for 2025 included health and digital infrastructure, a gap ENISA traced to differences in scope, thresholds and reporting conditions.

Claimed attacks on operational technology deserve the same skepticism. Such claims rose from 37 in the third quarter to 124 in the fourth, yet most named neither the techniques used nor the affected entities. ENISA assesses that these claims will likely keep rising while confirmed incidents with operational impact will likely remain stable.

Why ENISA sees ransomware tilting toward data theft

The short-term impact, by ENISA’s account, sits in those financially motivated categories. Ransomware made up 47.3 percent of financially motivated claims, data breaches 36 percent and fraud and impersonation 13.3 percent. Manufacturing absorbed the largest share of ransomware claims at 25.2 percent, and Germany led member states in ransomware claims at 26.5 percent. Qilin, SafePay, Akira, INC Ransom and Hunters International were the most active operators in the EU.

The technique data is where information governance teams should look hardest. In ENISA’s analysis of publicly reported techniques used by the most active operators, exfiltration over command-and-control channels represented 73.3 percent, while data encryption for impact represented 13.7 percent. ENISA said the split likely confirms a wider move away from encryption and toward data exfiltration and extortion. When an attack steals before it locks, every unmapped file share and over-retained mailbox becomes potential notification exposure, so data maps and retention schedules belong in incident planning rather than only in compliance binders.

The report also describes Qilin adding a “call lawyer” feature that mimics legal escalation to pressure victims. ENISA said the tactic carries extra weight in the EU, where incident-reporting rules and General Data Protection Regulation (GDPR) duties likely push victims toward paying to protect their reputations. Thirty-three EU organizations were identified as targets of repeat victimization, with ransomware accounting for 44 percent of that activity and data breaches for 40 percent. ENISA judged it likely that some of that activity was operationally linked, and that a lack of restoration practices after incident response enabled the repeated targeting.

Breach claims need verification before they drive decisions. ENISA’s data breach analysis rests on listings offering stolen data on criminal forums, and the agency said it could not verify whether those listings were authentic or current. The forum darkforums.st alone accounted for 58 percent of those claims. Legal and privacy teams weighing notification obligations after a forum listing should confirm what data, if any, actually left their environment before treating the listing as fact.

When the supplier becomes the way in

That verification burden grows when the breach happens at someone else’s company. Cybercriminals went after third-party providers more often, ENISA said, highly likely as a way to make their attacks more efficient, and adversaries compromised software, repositories and browser extensions. The report flags a rise in compromised libraries and npm packages, citing the Shai-Hulud campaign, and notes that ENISA issued a technical advisory on using package managers securely in March 2026.

The examples are concrete. In September 2025, according to the report, a ransomware incident affecting U.S.-based Collins Aerospace’s passenger-processing software disrupted automated check-in at several airports in the EU, among them Brussels and Berlin. A ransomware attack on a Swedish IT supplier affected about 200 municipalities and regional authorities. The report traces the data-theft group ShinyHunters across the full attack chain. It typically got in by phoning staff while posing as IT support to collect single sign-on credentials and multifactor codes, and its activity reached Salesforce, Microsoft 365, SharePoint, Slack and Google BigQuery environments.

For legal and compliance teams, that pattern argues for an inventory of which vendors hold which data and under what access, plus contract terms that require prompt notice when a supplier is compromised. Revoking stale OAuth tokens and limiting standing access between software-as-a-service platforms costs little next to an exfiltration that runs through a trusted integration.

Where ENISA expects AI to go next

Attackers in 2025 relied mostly on off-the-shelf consumer AI tools to sharpen skills they already had, according to the report, not to gain breakthrough capabilities. ENISA expects that to change. The agency assessed it is likely that 2026 will bring more stages of the attack chain enabled directly by AI, possibly including experiments with human-out-of-the-loop proofs of concept. It also warned that AI applications are becoming targets themselves, particularly those that can reach files, credentials, browser sessions or development environments.

AI use is already measurable in information manipulation. The European External Action Service, whose data ENISA used for its foreign information manipulation chapter, detected 540 incidents in 2025, and 27 percent involved AI-related techniques, with such cases rising from 41 in 2024 to 147.

Read the release with the report open

Practitioners who cite ENISA’s figures should take them from the report rather than the announcement. In its analysis by threat categories, the Sept. 22 release says cybercrime covered 36 percent of total events and lists ransomware deployment at 40 percent “of all analysed events,” followed by data breaches at 31 percent and fraud and impersonation at 19 percent. The report’s cybercrime chapter and its charts put cybercrime at 29.3 percent of events and give ransomware, data breaches and fraud as 47.3, 36 and 13.3 percent of financially motivated claims. The release also says state-nexus groups mostly carried out intrusion operations, at 87 percent, where the report’s corresponding sentence gives unauthorized access at 81.7 percent. The release does not explain the differences, and elsewhere it says almost 30 percent of incidents were financially motivated, consistent with the report.

Other headline figures line up. Over 48,000 new vulnerabilities received Common Vulnerabilities and Exposures (CVE) identifiers in 2025, a 22 percent increase from the year before, and in November 2025 ENISA became a root within the CVE program, the system that assigns those identifiers. In unauthorized-access incidents where ENISA could identify an intrusion vector, 60.4 percent involved exploiting a vulnerability. That figure rests on a narrow base. The report puts the incidents with an identifiable vector at 5.2 percent, so the share describes the cases ENISA could see into rather than all unauthorized access.

The vulnerability numbers arrive as a new reporting duty takes hold. Since Sept. 11, 2026, manufacturers have been required under the Cyber Resilience Act to report actively exploited vulnerabilities and severe incidents affecting the security of their products. Those notifications go through a single reporting platform to the computer security incident response team in the member state where the manufacturer has its main establishment. The information reaches ENISA at the same time unless particularly exceptional circumstances apply, according to the European Commission.

“The analysis highlights how threats become more interconnected and how threat groups spread their impact across the larger map of digital services and infrastructures,” ENISA Executive Director Juhan Lepassaar said in the release.

If ENISA is right that the chances to reach many victims through a single supplier compromise are likely to grow, how many legal and governance teams could say today which of their vendors would be first to tell them?



News sources



Assisted by GAI and LLM Technologies

Additional reading

Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more understandable for practitioners, policymakers, and business leaders.

 

Have a Request?

If you have information or offering requests that you would like to ask us about, please let us know, and we will make our response to you a priority.

ComplexDiscovery OÜ is an independent digital publication and research organization based in Tallinn, Estonia. ComplexDiscovery covers cybersecurity, data privacy, regulatory compliance, and eDiscovery, with reporting that connects legal and business technology developments—including high-growth startup trends—to international business, policy, and global security dynamics. Focusing on technology and risk issues shaped by cross-border regulation and geopolitical complexity, ComplexDiscovery delivers editorial coverage, original analysis, and curated briefings for a global audience of legal, compliance, security, and technology professionals. Learn more at ComplexDiscovery.com.

 

Generative Artificial Intelligence and Large Language Model Use

ComplexDiscovery OÜ recognizes the value of GAI and LLM tools in streamlining content creation processes and enhancing the overall quality of its research, writing, and editing efforts. To this end, ComplexDiscovery OÜ regularly employs GAI tools, including ChatGPT, Claude, Gemini, Grammarly, Midjourney, and Perplexity, to assist, augment, and accelerate the development and publication of both new and revised content in posts and pages published (initiated in late 2022).