European Union cyber agency logs 60% jump in threat actors targeting institutions in 2025
At least 174 distinct threat actors targeted European Union institutions and their ecosystem last year, up from 110 in 2024, according to the Threat Landscape Report 2025 from CERT-EU.
Source: CERT-EU · August 6, 2026 at 2:54 PM · AI-assisted report
KUALA LUMPUR, 6 AUGUST 2026 —
Listen to this article
DomainFork Audio · read aloud
At least 174 distinct threat actors targeted European Union institutions and their ecosystem last year, up from 110 in 2024, according to the Threat Landscape Report 2025 from CERT-EU.
Cyberespionage and pre-positioning accounted for 38% of recorded incidents, the report said, while cybercrime rose to 30%. The remaining activity comprised influence operations, hacktivism and other malicious actions.
China-linked actors led in volume, focusing on broad exploitation of software flaws and supply-chain compromises, CERT-EU said. Russia-linked groups concentrated on Ukrainian and EU entities supporting Kyiv. Vulnerability exploitation in internet-facing software remained the dominant initial access route, triggering seven of the nine major incidents CERT-EU handled in 2025, including two zero-day compromises.
Edge devices—firewalls, VPN appliances and network management solutions—were the primary targets, the report showed. Fortinet, Ivanti, Cisco and Palo Alto products accounted for the bulk of observed attacks. The number of software products targeted by threat actors rose to 198 from 110 in 2024.
Social engineering tactics diversified sharply. E-mail-based spear-phishing fell to 31% of initial access attempts from 41% in 2024, while voice phishing, adversary-in-the-middle attacks, ClickFix abuse and device-code authentication exploitation increased. In one campaign, threat actor UNC6040 used voice phishing to trick employees at more than 90 organisations—including several vendors to Union entities—into authorising malicious OAuth applications in Salesforce environments.
Artificial intelligence was weaponised at scale, the report said. Threat groups deployed voice cloning, personalised phishing content and deepfakes of officials. A reportedly China-linked actor directed a jailbroken agentic AI system against 30 entities across sectors, achieving autonomous intrusion in a small number of cases.
Geopolitical events drove reactive operations. Eight national elections in EU and neighbouring countries were targeted, often with distributed-denial-of-service attacks by pro-Russia hacktivist groups. Destructive attacks remained rare outside conflict zones, but the Sandworm-attributed attempted wiper strike on a Polish renewable-energy operator in December showed such threats can reach EU territory.
Partner organisations bore the brunt of third-party risk. CERT-EU recorded 178 incidents affecting 90 partners, with public administrations hit 60% of the time. Actors exploited trusted partner relationships to reach Union entities, mainly via credential phishing from compromised partner mailboxes and data leaks from partner breaches.
Service providers were also in the crosshairs. Thirty-two providers supporting Union entities were compromised, including a case where a provider’s foothold inside a Union entity’s internal network led to a major incident. Telecommunications providers were repeatedly targeted, creating significant downstream risk.
CERT-EU issued ten prioritised recommendations. Timely patching of internet-facing systems and edge devices remained the single highest-impact defensive action based on 2025 data. The agency also called for phishing-resistant multi-factor authentication and default end-to-end encryption for sensitive communications.
CERT-EU, the EU’s cybersecurity service for institutions, bodies, offices and agencies, published the report under Regulation (EU, Euratom) 2023/2841. The document is classified TLP:CLEAR and available for download without restriction. Feedback can be sent to services@cert.europa.eu.
Related: Intel
Malaysia Impact
Global development — watch for knock-on effects on oil prices, the ringgit, and KLCI risk sentiment.