Ransomware Is the Biggest Short-Term Cyber Threat in the EU
ENISA 2026 report with 2025 data: ransomware has the greatest short-term impact; 57% ideological; DDoS accounts for 51% of cases.

Meta description: ENISA 2026 report with 2025 data: ransomware has the greatest short-term impact; 57% ideological; DDoS accounts for 51% of cases.
The ENISA report, European Union Threat Landscape 2026, concludes that the ransomware was the incident type with the greatest short-term impact on the European Union in 2025, based on events observed from January 1 to December 31, 2025. The agency also identifies a predominance of attacks with political motivations and a high number of distributed denial-of-service (DDoS) events.
ENISA 2026 Report Summary
The document, published by ENISA with 2025 data, maps the threat landscape in the EU over the year. The main conclusion is that ransomware represents the most severe risk in terms of immediate impact on digital services and infrastructures, due to its ability to disrupt critical operations and force rapid contingency decisions. According to ANSA, ENISA bases the report on incidents effectively observed and reported throughout 2025.
"Ransomware is the incident type with the greatest short-term impact in the EU," highlights ENISA's report.
Attack types and motivations: ransomware, DDoS, and ideological reasons
ENISA identifies clear patterns in motivations and techniques used by attackers in 2025:
- Ideological motivations: 57% of incidents affecting the EU were ideologically driven—including hacktivist actions and campaigns with political aims—according to the survey.
- Financial motivations: nearly 30% of incidents had economic ends, traditionally linked to extortion schemes and digital fraud.
- DDoS: low-impact distributed denial-of-service attacks were the majority in number of occurrences, accounting for 51% of cases recorded in the analyzed period.
The report, cited by ANSA, notes that although DDoS dominated in volume, ransomware causes more significant damage per incident, affecting service continuity and requiring emergency responses.
Trends and geopolitical context
ENISA ties the rise and diversity of threats to a geopolitical context marked by regional tensions. These geopolitical tensions have driven activity by various actors—from criminal groups with economic motives to hacktivists with political agendas—expanding the attack surface against critical infrastructures.
- Hacktivists promoted DDoS campaigns against essential entities, often in response to events or political statements, according to ENISA.
- The agency notes growing interconnection of threats, with blended techniques that amplify the effect on digital services and IT supply chains.
ENISA's Executive Director Juhan Lepassaar warned that threats are increasingly integrated and operate to maximize impact on services and digital infrastructures, ANSA reports. This evolution raises the complexity of responses needed by authorities and private operators.
Relevance for Brazilian descendants of Italians
For Brazilians with personal, professional, or digital ties to Italy and other EU countries, the report's conclusions are relevant for two practical reasons:
- European digital services—including administrative, financial, and communications platforms—may suffer interruptions or degradation due to ransomware and DDoS, affecting those who rely on these services remotely.
- The predominance of ideological motivations means that political or social events in Europe could trigger coordinated campaigns targeting transnational targets.
Therefore, Brazilian users and organizations with relationships to Italian institutions should monitor cybersecurity news and guidance, in addition to adopting basic protective practices (updates, backups, strong authentication) to reduce exposure to incidents that can have cross-border effects.
What to monitor and useful links
ENISA recommends strengthening defenses, improving detection and response capabilities, and intensifying public-private cooperation. For readers interested in following developments related to Italy and the Italian-descendant community, the portal publishes analyses and news in sections such as Notícias da Itália, practical information on Cidadania Italiana, and reports on daily life and digital security in Vida na Itália.
Conclusion: the report "European Union Threat Landscape 2026" confirms that in 2025, ransomware was the threat with the greatest immediate impact in the EU, in a landscape numerically dominated by DDoS and marked by ideological motivations. ENISA's recommendation is clear regarding the need for greater resilience and cooperation to contain risks that already cross national borders.
Source: ANSA




