Illustration comparing EU and US cyber threats with maps, network connections and security shields

Cyber Threat Report: How EU Attacks Compare With the US

DDoS attacks were the most common cyberattack in the European Union last year, but the EU’s own cybersecurity agency says they were mostly noise. The attacks that did the damage came from ransomware and data-theft crews.

That’s the core finding of the ENISA Threat Landscape 2026, released Tuesday. The agency analyzed 8,257 incidents recorded during calendar year 2025. DDoS attacks made up 51.3 percent of them, and unauthorized access came second at 39.5 percent.

US data tells the same story from the other side of the Atlantic. Verizon’s 2026 Data Breach Investigations Report found that exploiting software flaws overtook stolen credentials as the top way into breached networks for the first time in the report’s 19-year history, and that breaches involving a third party jumped 60 percent to account for 48 percent of the total.

Beyond the Break weekly cybersecurity newsletter — Subscribe

The FBI, meanwhile, tallied nearly $21 billion in reported US cybercrime losses in 2025, driven mainly by investment fraud. The three reports use different datasets but reach the same conclusion: the attacks that make the most noise are not the ones that cost the most.

For a side-by-side look at where the EU and U.S. data agree, and where they part ways, see our comparison chart below.

The security bod was quick to put that top number in context.

“The distribution of incident types remains dominated by low-impact DDoS attacks, which make up 51.3% of all recorded incidents, primarily shaped by geopolitical developments and political statements,” the report reads.

Most of those attacks came from hacktivists. Ideology-driven activity accounted for 57.3 percent of all incidents, much of it from pro-Russia groups such as NoName057. Their favorite target was government. Public administration drew 31.8 percent of all incidents, and DDoS made up 81.8 percent of the attacks against it. The typical payoff was a website knocked offline for a while.

ENISA said that “despite representing most incidents, ideology-driven claims did not result in large-scale or significant impact.”

Low impact doesn’t mean low volume. Cloudflare says the DDoS attacks it detected more than doubled in 2025, to 47.1 million.

The agency’s own survey backs that up. In ENISA’s NIS investments report, “DDoS are characterized as ‘noise’ by representatives of EU organisations operating in NIS sectors of high criticality, while ransomware dominate organisational concerns.”

The damage came from criminals. Financially motivated activity accounted for just over 29 percent of incidents, and ransomware made up 47 percent of those financially motivated claims.

ENISA said “financially motivated activities remain the most impactful threat to EU organisations in the short-term and cyberespionage represents a significant strategic threat in the mid to longer-term.”

One case shows the gap between loud and damaging. In September 2025, a ransomware attack on Collins Aerospace’s passenger-processing software knocked out automated check-in at several EU airports, including Brussels and Berlin. It caused delays and cancellations and sent staff back to manual check-in.

The ransomware playbook is also shifting. In ENISA’s analysis of techniques used by the top ransomware operators, exfiltration over command-and-control channels was the most frequently observed at 73.3 percent. Encrypting data for impact came in at 13.7 percent. ENISA reads that as a move away from locking files and toward stealing them for extortion.

Getting in still often starts with a lure. Phishing accounted for 77.8 percent of the social engineering techniques ENISA identified, with malicious spam a distant second at 13 percent. Verizon found attackers shifting to phones, with fake texts and voice calls succeeding 40 percent more often than traditional email phishing.

ENISA flagged ClickFix as a growing piece of that picture. In a ClickFix attack, the victim is shown a fake error or verification prompt and told to paste and run a command. The malicious PowerShell has already been copied to their clipboard. Qilin ransomware operators used the tactic as a primary initial access vector, the report said.

“An increasing use of the ClickFix technique, abusing victim into ‘fixing’ an issue, ultimately leading to the execution of malicious code, was prevalent in 2025,” the EU security authority said in its report.

“ENISA also observed the popularisation of phishing kits and Phishing-as-a-Service (PhaaS) platforms to further enable financially motivated cyber activities.”

For attackers breaking into networks, the most common identifiable route was a software flaw. Of the unauthorized-access incidents where ENISA could pin down an entry point, 60.4 percent involved exploiting a vulnerability and 20.7 percent involved misconfiguration or accidental exposure. The caveat is that an entry point was identifiable in only 5.2 percent of those incidents.

Supply-chain attacks make the same point from the other direction. ENISA doesn’t put a number on them, but says third-party and supply-chain compromises kept producing large-scale, impactful incidents throughout 2025. Verizon’s 48 percent figure suggests the problem is at least as big in its global dataset.

“Cybercriminals increasingly targeted third-party providers, such as digital services, highly likely as an opportunity to optimise the efficiency of their attacks,” the report reads. “Adversaries were also seen exploiting the digital supply chain, notably by compromising software, repositories or browser extensions.”

Of particular concern was the increase in compromises of popular libraries or npm packages, as seen with the Shai-Hulud campaign, according to the report.

On AI, the report cuts against both the hype and the dismissal. ENISA found that in 2025, “attackers primarily use consumer-grade AI tools to augment existing skills and adapt attack vectors rather than to achieve breakthrough capabilities.” The agency also assessed that this is highly likely to change, and that 2026 will likely see more stages of the attack chain directly enabled by AI.

ENISA also cautions against reading its tallies as a scoreboard. DDoS and ransomware are claimed loudly and immediately, while espionage campaigns can take six months to more than four years to surface in public reporting. It notes that “increased reporting of a specific threat does not necessarily reflect an increased tempo of activity.”

Same threats, different scoreboards

How Europe’s 2025 threat data compares with U.S. reporting, and where the two part ways.

MeasureEU: ENISA Threat Landscape 2026U.S. & global: FBI IC3, Verizon DBIRVerdict
Most common by count 51.3%DDoS share of all recorded incidents, mostly hacktivist-driven PhishingAmong the most frequently reported complaint types Diverge
Top way in 60.4%Vulnerability exploitation, among intrusions with an identified entry point 31%Of breaches began with a software flaw, now ahead of stolen credentials Agree
Supply chain RisingThird-party and software supply-chain attacks caused large-scale incidents 48%Of breaches involved a third party, up 60% Agree
Social engineering 77.8%Phishing’s share of social engineering techniques; ClickFix and smishing up +40%Higher success rate for text and voice lures than email phishing Agree
Where the damage is RansomwareFinancially motivated attacks rated the most impactful short-term threat $20.9BReported losses; investment fraud the top driver of scam losses Diverge

Sources: ENISA Threat Landscape 2026 (EU incidents, calendar 2025); FBI IC3 2025 report (U.S. complaints, calendar 2025); Verizon 2026 DBIR (global breaches, Nov. 2024 to Oct. 2025). The reports measure different things; figures are not directly comparable.

Total
0
Shares
Previous Article
Logo grid of the Blueprint Alliance's 12 founding members — Okta, AWS, CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler — around the alliance's own logo

Okta, 11 Rivals Launch AI Agent ‘Blueprint Alliance’

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading