Cyber threats in the EU: facts and figures
Cyber threats are increasing in volume and complexity. Besides digital privacy they also impact critical infrastructure and economic stability, and cost trillions of euros globally every year.
The importance of boosting cybersecurity
A cyber threat is any malicious activity aimed at compromising the integrity, confidentiality or availability of digital systems, networks or data.
Cyber threats continue to rise across Europe and the world. In 2020, the global economic cost of cybercrime reached twice the level of 2015.
Cyberattacks are not only increasing in volume but also evolving in complexity, as criminals now use advanced techniques, including generative artificial intelligence (AI), to make their attacks harder to detect and counter.
How the EU combats cybercrime
Major cyber threats impacting the EU
Attacks are becoming more sophisticated and varied, targeting a wide range of sectors. According to the EU agency for cybersecurity (ENISA), there are six cyber threats currently affecting the EU.
Threats to availability
Attacks targeting the availability of a system or service by exhausting resources or overloading network infrastructure
Ransomware
Attackers seize control of assets, demanding ransom for restored access or to prevent the exposure of data
Threats to data
Unauthorised access to sensitive, confidential or protected data, aiming to manipulate, disclose or destroy information
Social engineering
Manipulative tactics that deceive victims into making critical mistakes or handing over sensitive information
Malware
Malicious software designed to infiltrate systems, cause damage, disrupt services and steal data
Supply chain attacks
Attacks targeting an organisation via vulnerabilities in its supply chain, with potential cascading effects
Threats to availability make up 46% of cyber threats
Threats to availability, ransomware and threats to data are the most prominent cyber threats in the EU.
Threats to availability - 46%
Ransomware - 27%
Threats to data - 16%
Others - 10%
Main actors behind cyberattacks
Cyber threat actors are diverse, ranging primarily from state-linked groups to financially motivated criminals, private entities and hacktivists. Each group has distinctive methods and goals:
- state-related actors
government-linked groups conducting attacks for political or strategic goals, like espionage - cybercrime actors
seek financial gain through opportunistic attacks, like social engineering - private sector offensive actors
entities developing and selling cyberweapons, often to governments and private individuals - hacktivists
engage in disruption and hacking for political or social change, sometimes supported by state-related actor
Sectors most targeted by cyber threats
Nearly 20% of cyberattacks target organisations in public administration, a sector essential for public services and security.
Public administration - 19%
Transport - 11%
Finance - 9%
Digital infrastructure - 9%
See also
EU cybersecurity: strategy and key policies
Cybersecurity: social engineering
Online safety
Last review: 5 February 2025