Report by ENISA

ENISA Threat Landscape 2025

16 FINDINGSPublished Oct 1, 2025
View Original Report →

Key Findings

Phishing (including malspam, vishing, and malvertising) was the dominant intrusion vector, accounting for approx. 60% of cases..

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropePhishingIntrusion vectorInitial access vector

Top Shares of Recorded Incidents by Sector in the EU: 38.2%: Public Administration, 28.5%: Unknown, 7.5%: Transport (second most targeted sector), 4.8%: Finance, 4.5%: Energy, 2.9%: Education, 2.3%: Health, 2.2%: Digital Infrastructure & Services, 1.7%: Manufacturing, 1.2%: Media & Entertainment.

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropeCyber incident

13.4% of assessed objectives were financially-motivated.

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropeCyber incident motivation

State-aligned operations, often driven by low-impact DDoS campaigns targeting EU Member States’ organisations’ websites, resulted in service disruption in only 2% of incidents.

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropeDDoSState-aligned

79.4% of assessed objectives were ideology driven.

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropeCyber incident motivation

Vulnerability exploitation accounted for 21.3% of initial access vectors.

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropeVulnerability exploitationInitial access vector

7.2% of assessed objectives were cyberespionage.

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropeCyber incident motivation

Public Administration was the most targeted sector in the EU, accounting for just over 38% of incidents.

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropePublic administrationCyber incident

Vulnerability exploitation led to malware deployment as a follow-up activity in 68% of cases.

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropeVulnerability exploitationMalware

Ransomware remained the most impactful cybercrime tool despite a reported decrease of 11% compared to the previous ENISA Threat Landscape (ETL) report.

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropeRansomware

NoName057(16) was responsible for over 60% of claims in the realm of hacktivism, sustained by its DDoSia platform

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropeNoName057(16)Hactivism

Insider threats accounted for 0.8% of initial access vectors.

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropeInsider threatInitial access vector

Botnet accounted for 9.9% of initial access vectors.

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropeBotnetInitial access vector

Essential entities (including public administration, transport, digital infrastructure and services, finance, and manufacturing) represent 53.7% of the total number of recorded incidents in the EU.

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropeEssential entitiesCyber incident

Malicious applications accounted for 8% of initial access vectors.

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropeMalicious applicationInitial access vector

Within Public Administration, incidents were dominated by low-impact DDoS campaigns (94.8%).

ENISAENISA Threat Landscape 2025·Oct 1, 2025
EuropePublic administrationCyber incidentDDoS