Skip to content

Security1 publisher2 min readPublished

Government-portal DDoS accounts for a quarter of ENISA's 8,257 EU incidents in 2025

ENISA counted 8,257 EU incidents in 2025 and found that denial of service against public-facing services supplies most of the volume, while its warning about compromised technology suppliers rests on one named Swedish case.

The Watch · Security desk

Illustration accompanying Government-portal DDoS accounts for a quarter of ENISA's 8,257 EU incidents in 2025

What happened

  • ENISA's Threat Landscape 2026 analyzed 8,257 incidents recorded between January 1 and December 31, 2025, drawn mainly from open sources plus anonymized data from member states and its partnership programme.
  • Public administration was the most affected sector at 31.8% of incidents, followed by business services at 8.5%, transport at 8%, manufacturing at 6.9%, and finance and banking at 5.6%.
  • ENISA cited a ransomware attack on a Swedish IT supplier that reached around 200 municipalities and regional authorities and disrupted the systems they used for human resources reporting.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • contradiction ENISA frames the year around compromises of shared technology providers, but the distribution it published is dominated by denial of service, so ranking work by the report's volume and ranking it by the report's framing produce different priorities.
  • constraint Counting incidents limits what this data can say about concentration risk: a supplier compromise registers as supplier-scale only if the tally counts affected customer organisations.
  • exposure For an EU public body, the thing attackers reached most often in 2025 was the public portal. Keeping that portal online under load falls outside what endpoint agents do.
  • decision A security lead bidding for availability capacity can cite a sector-level percentage; the supplier case brings a single example to the same budget round.

In this distribution, ransomware is a sub-category of unauthorized access, which is 39.5% of the total [4][7]. The business services figures show how that nesting works: the sector took 8.5% of 8,257 incidents, about 702; unauthorized access was 56.7% of those, about 398; ransomware deployments were 54% of that subset, about 215 [1][7][11][12][6]. Data breaches were 26.5% of the sector's unauthorized-access incidents [12].

Public administration absorbed 31.8% of incidents, roughly 2,626, and DDoS was 81.8% of those, roughly 2,148 [6][8][2][3]. That one cell is about 26% of everything ENISA counted and about half of the estimated 4,236 DDoS incidents in the dataset [3][4][5]. Hacktivist groups were linked to much of that activity, against government websites and online portals in connection with elections, law enforcement operations and geopolitical developments including Russia's war against Ukraine and conflicts in the Middle East [5][9]. State-linked groups kept working on ministries, diplomatic organizations and other government institutions for cyberespionage [19].

In the same report, the supplier argument runs through individual cases. ENISA cited a ransomware attack on a Swedish IT supplier that affected around 200 municipalities and regional authorities and disrupted the systems they used for human resources reporting [15]. The agency also recorded compromised software, repositories and browser extensions, plus attacks on widely used libraries and packages [16]. Its published incident-type and sector distributions do not include a category for supplier or supply-chain compromise [8]. So the Swedish event enters the record as one intrusion at one company and about 200 public bodies that lost a service [15][21].

"The analysis highlights how threats become more interconnected and how threat groups spread their impact across the larger map of digital services and infrastructures," said ENISA Executive Director Juhan Lepassaar [17]. The agency's reasoning on why suppliers are hit is straightforward: their systems connect to multiple customers, and an intrusion at one of them can interrupt services or open a route into other parts of a digital supply chain [20].

Phishing was 77.8% of the social engineering techniques identified in incidents targeting the EU, and ENISA observed increased use of ClickFix, which gets a user to run a malicious command presented as instructions for fixing a computer problem [13][14]. For a municipality those are two different programmes with two different budgets: keeping a portal up under hacktivist load, and stopping credential theft behind it. Of financially motivated incidents affecting public administration, data breaches were 38.4% and ransomware claims 36%, primarily hitting municipalities [10].

What to watch

  • Whether the full Threat Landscape 2026 publishes a supplier-driven share or a count of affected customer organisations alongside the incident count.
  • Whether member states begin reporting affected-authority totals when a shared IT supplier is hit, as in the Swedish case.
  • Whether ClickFix keeps gaining against the 77.8% phishing share when ENISA next counts social engineering techniques.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories