Threats

Europe sees financially motivated cyber attacks double as phishing attacks grow

September 28, 2026
10 min read

Key Insights:

  • The latest ENISA Threat Landscape report analyses 8,257 cyber incidents recorded during the 2025 calendar year
  • Cybercrime attacks more than doubled, reaching 29% of recorded incidents against 13% in the previous annual report
  • Employees remain a major attack surface with social engineering growing through increasing use of phishing kits, PhaaS, ClickFix, smishing and device-code attacks
  • Ransomware remained the most impactful short-term cyber threat accounting for 47% of financially motivated attacks
  • New CVEs recorded in 2025 were up 22% year-on-year, a figure that pales in comparison with our lived experience in 2026 as AI-enabled discovery accelerated vulnerability exploitation
  • Cybersecurity is no longer about protecting computers, it's about protecting the ability of your business to operate during digital disruption

Security incident reporting just published in the EU shows that cybersecurity is becoming harder for one fundamental reason - businesses are becoming more and more interconnected and attackers are learning how to exploit these critical links.

The latest ENISA Threat Landscape 2026 from the European Union Agency for Cybersecurity provides key insights into how that threat is evolving.

Analysing 8,257 cyber incidents recorded during 2025, the EU agency examines the major threats affecting organisations across Europe but undoubtedly replicated by threat actors targeting operations across the wider world.

The agency's TL;DR? Cyber security is not about protecting your systems and data. It's about protecting the ability of your business to operate when an incident takes place.

Digital dependencies are dangerous

Businesses now often rely on multiple outsourced providers. Anything from cloud platforms, software developers, managed service providers, payment gateways, SaaS applications and a growing number of key technologies from a common top ten list of vendors.

Whilst CTOs and CIOs can celebrate the improved efficiency and flexibility of renting rather than buying, this distributed architecture brings with it concentration risk.

An attacker does not need to compromise your organisation directly. They can compromise a supplier that has access to your systems, credentials or data and potentially then pivot into your organisation.

A resilient business must therefore take an ecosystem approach to cyber security and identify potential consequences from incidents happening across their end to end supply chain.

Ransomware remains a business continuity problem

Ransomware continues to be one of the clearest threats to business operations across Europe.

ENISA identifies ransomware as the most impactful short-term cyber threat often targeting manufacturing and other business services, not just to encrypt files but for wider harms including data theft, extortion, publication of the stolen information, theft and resale of credentials and exploitation of other vulnerabilities identified.

Businesses need to know how they will continue operating if systems are unavailable, how quickly critical services can be restored, who makes decisions during an incident, how customers and suppliers will be communicated with, and what happens if sensitive information has been stolen.

Those planning for a successful ransomware response should ask: "If our critical systems disappeared tomorrow, how long could we continue operating?"

Employees remain a major target and attacks are evolving

Phishing is not new, but the ENISA report shows the growing sophistication and industrialisation behind social engineering attacks.

Phishing remained the dominant social-engineering technique in 2025 driven by phishing kits and Phishing-as-a-Service platforms.

Techniques such as ClickFix, smishing and device-code phishing demonstrate a change in attacker behaviour.

Rather than simply sending a suspicious email containing an obvious malicious attachment that may never bypass an email gateway, attackers increasingly attempt to persuade users to perform apparently legitimate actions.

The ClickFix technique tries to trick users into manually copying and running malicious system commands on their own computers and may not align with traditional security awareness messages.

These attacks are designed to look like a normal system authentication prompt, tech support or software-fix process to view or download.

User awareness must now be paired with strong identity controls, phishing-resistant authentication, conditional access policies, intelligent endpoint protection, the granting of least privilege plus effective monitoring and rapid incident response capabilities to contain events.

What can business owners do?

The ENISA report is clear - businesses cannot eliminate cyber risk. Instead, they must become more resilient and ready for digital disruptions with 7 key steps:

1. Identify the systems that keep the business running

Create a list of your most important business processes and identify the technology, data, suppliers and people each process depends upon.

Prioritise those systems rather than attempting to protect everything equally.

2. Build a recovery strategy before an incident occurs

This step is simple - a recovery plan that exists only on paper is not organisational resilience:

  • Test backups
  • Test restoration
  • Test alternative communications
  • Test how employees would operate without key IT systems
  • Test the assumptions made by management about current security posture

3. Strengthen identity security

Prioritise privileged accounts, remote access and key cloud services.

Use strong authentication, minimise administrative privileges and monitor for unusual authentication activity.

Treat stolen credentials and session tokens as serious security events and seek to address root causes.

4. Document your third-party risk exposure

Identify your critical suppliers and review what access they have to your IT environment.

Workshop and document what happens if a major SaaS provider, cloud service, MSP or software supplier becomes unavailable or compromised.

Once these dependencies are agreed upon, document the consequences of failure or outage.

5. Prioritise exploitable vulnerabilities

Maintain an accurate asset inventory so you know what needs protecting and patching.

Focus on internet-facing and business-critical systems, vulnerabilities known to be exploited and weaknesses that could provide privileged access.

6. Prepare for AI-enabled attacks

Update phishing and fraud awareness training to cover ClickFix and more.

Review the permissions granted to AI tools and the systems and data they can reach.

Prevent sensitive data from being unnecessarily exposed to external AI services.

Consider how the growing use of AI could change your organisation's threat model over the next 12 months.

7. Make incident response a management capability

Cyber incidents are business crises, not just IT problems.

Make sure senior management knows:

  • who has authority to make decisions
  • who contacts customers
  • who deals with regulators
  • who manages suppliers
  • who communicates with employees
  • who deals with law enforcement
  • how the organisation prioritises recovery of key systems.

The bigger lesson

The ENISA Threat Landscape report for 2026 shows how existing threats are becoming faster, more scalable and more interconnected.

The answer is not to try to predict the next attack. It's to build an organisation that can prevent the common attacks, detect abnormal activity, contain incidents quickly and continue operating when security controls do ultimately fail.

An organisation that knows their critical processes, dependencies and exposures and have practiced what happens when those things fail will be in a much stronger position to survive.

The 2026 report is available at the ENISA website alongside previous analyses of the European landscape and key economic sectors.

Similar posts

Identify. Secure. Assure.

Ready to simplify cybersecurity compliance for critical infrastructure?
Book a demo