Skip to content

ENISA report reveals surge in DDoS and data breaches against EU public administration

Industrialcyber.Co November 10, 2025

A new report from ENISA (European Union Agency for Cybersecurity) warns that public administrations across the EU are facing a surge in cyberattacks, with hacktivists increasingly relying on distributed denial-of-service (DDoS) campaigns. Central governments were the most targeted, accounting for 69% of incidents. The majority of incidents targeted the websites of parliaments, ministries, and national authorities/agencies, largely skewed by DDoS attacks.

As these institutions handle vast amounts of sensitive data and provide essential public services amid growing digitization, even a single incident can cause major disruption and erode public trust. The 42-page report identifies DDoS attacks, data breaches, ransomware, and social engineering as the most prevalent threats. ENISA’s latest sectoral analysis offers a comprehensive view of these risks, aiming to inform better risk assessments , strengthen mitigation strategies, and guide policymaking across the public sector.

The ‘Sectorial Threat Landscape for Public Administration’ outlines the major threats affecting the sector in 2024, drawing on open-source intelligence to detail key adversaries, common attack types, and evolving tactics. ENISA’s findings aim to help government entities strengthen their cybersecurity posture, maturity, and resilience against these escalating attacks.

Set as highly critical under the NIS2 Directive , the public administration sector plays a key role in delivering essential services to European citizens. Since it ensures effective governance and delivery of important services to civil society, such as education, healthcare, public transportation, etc., public administration is a fundamental sector of the economy.

However, being newly regulated under the NIS2 Directive, the sector is still developing its cybersecurity resilience as it remains in the early stages of aligning with the requirements. Public administration was therefore assessed as lying in the ‘risk zone’ in the study published in the ENISA NIS360 report . With 38% of all incidents in the latest ENISA cyber threat landscape report, public administration is reportedly the most targeted sector in the EU.

ENISA expects several trends to shape the cyber threat landscape for the EU’s public administration sector in 2025. DDoS campaigns are likely to continue, particularly around major events such as elections and international summits, though they may not cause significant operational disruptions. State-linked activity is also expected to persist, with Russia- and China-aligned intrusion groups maintaining cyber espionage campaigns aimed at collecting strategic data from EU institutions.

The use of artificial intelligence in social engineering is projected to grow, with generative language models, voice-cloning, and face-swap tools increasingly leveraged for phishing, vishing, and misinformation campaigns. These operations may move beyond simple extortion to focus on manipulating public opinion and eroding trust. Opportunistic ransomware attacks are also anticipated to continue, causing occasional but notable service disruptions across the public sector.

These emerging trends threaten both operational continuity and public trust in EU governance. AI-driven phishing could breach sensitive citizen-data repositories, triggering identity fraud and regulatory liabilities. Multi-extortion campaigns might amplify service outages, undermining confidence in digital government.

Additionally, supply-chain exploits risk simultaneous compromise of multiple agencies, triggering complexities in cross-border responses and heightening political fallout. Given the inclusion of the public administration sector under the NIS2 Directive , which underscores the sector’s criticality, in the chapter of this report, ENISA proposes a set of strategic priorities to enhance its maturity and readiness to address ongoing challenges.

ENISA found that ransomware incidents made up 10% of reported cases, leading to some service disruptions. Data-related threats accounted for nearly one in five incidents, often targeting sensitive platforms, such as employment services and law enforcement portals. DDoS attacks represented almost two-thirds of all incidents and primarily affected ministerial and municipal websites. These attacks emerged as the most common threat type, with the pro-Russia hacktivist group NoName057(16) linked to 46% of them. Many of these campaigns were tied to geopolitical developments, including EU support for Ukraine, with notable surges recorded in July and December.

“Cyber-securing public administrations is central to citizens’ welfare and to the good functioning of the single market across the EU,” Juhan Lepassaar, ENISA executive director, stated in a recent media statement. “Public administrations provide reliable and effective public services, so it is essential to ensure a high level of cybersecurity within their wider network of national, regional, and local bodies.”

ENISA reported that threats against data include data breaches (17.4%) or data exposures (1%). Data-related incidents represent the second most frequent threat type recorded against public administration entities in the EU in 2024. Targets notably include employment services, local government platforms, law enforcement portals, and educational systems.

Public administration represents a high-value target for state-nexus intrusion sets mainly due to the strategic value of data collection, for economic or defence purposes. Cyberespionage campaigns in 2024 only accounted for 2.5% of all incidents. Despite being limited in number, their impact on EU Member States’ national security can be significant. Still, hacktivist activities remain the most prevalent in sheer volume. In 2024, hacktivists accounted for nearly 63% of incidents, while cybercrime operators and state-nexus intrusion sets represented approximately 16% and 2.5%, respectively. ​

Ideologically motivated hacktivist groups mainly seek to draw attention and cause disruption. Targets notably included municipal websites and ministry portals. Despite being observed in fewer incidents, phishing is still a common initial access vector.

The trends identified in the report show that public administrations in the EU are likely to remain the most targeted sector in the short-to-mid-term. Besides, the surge and increased capacity of AI tools are likely to increase AI-powered social engineering for follow-up malicious activities.

Multi-extortion campaigns can have worse adverse effects on service outage of tax portals, e-ID systems, and court scheduling, undermining confidence in digital services. Additionally, incidents involving shared systems or service providers show how one single compromise can cascade across multiple public entities. With the public administration sector covered by the NIS2 Directive , acknowledging the sector’s criticality, ENISA sets strategic priorities to enhance its capacity to address those challenges.

The agency also reported that cybercrime operators continued leveraging ransomware-as-a-service (RaaS) models, leading to operational disruptions in the public administration sector in the EU. Ransomware attacks remained opportunistic, with limited volume but notable disruptions. With ransomware incidents representing 10% of total events, ransomware-as-a-service (RaaS) programs were commonly used, with notable strains deployed against the public administration sector in the EU, including RansomHub and LockBit3.0 .

The report also identified state-nexus intrusion sets publicly documented as associated with Russia and China that were active in cyberespionage campaigns against the public administration in the EU, notably targeting governmental entities.

Looking forward, given the sector’s low maturity and being identified as a potentially high-value target, the public administration sector in the EU is highly likely to remain a target in the mid-to-long term. Hacktivist-led DDoS activity is expected to persist around noteworthy geopolitical events, while statenexus intrusion sets will probably continue carrying out long-term cyberespionage campaigns. Opportunistic ransomware and data breaches are likely to continue to impact business continuity and lead to reputational damage.

ENISA outlined a set of practical recommendations for public administration entities across the EU, aligned with the sector’s current threat landscape. The guidance addresses the surge in DDoS attacks, the steady flow of data-related incidents, ongoing ransomware activity, and persistent campaigns linked to state- actors.

As DDoS attacks were the most common threat type, ENISA recommends measures to strengthen both architectural resilience and operational readiness. Critical portals such as those of ministries, parliaments, and municipalities should be placed behind a Content Delivery Network (CDN) or Web Application Firewall (WAF) with always-on protection at both the network and application layers. These defenses absorb and filter malicious traffic before it reaches core systems, minimizing outages.

ENISA also advises filtering network traffic, implementing network intrusion prevention, and publishing static fallback sites with Domain Name System (DNS) failover. This ensures that if the primary site goes offline, a read-only version remains accessible to provide essential information until full services are restored.

While most DDoS attacks cause limited disruption, data-related incidents can severely impact an organization’s operations. To reduce these risks, ENISA recommends enforcing multi-factor authentication (MFA) across all systems, with conditional access and Privileged Access Management (PAM) for administrators, since compromised credentials are a common attack vector. Using Data Loss Prevention (DLP) technologies is also advised to prevent large-scale data exfiltration.

Additionally, ENISA urges organizations to harden email and web security by implementing Domain-based Message Authentication, Reporting and Conformance (DMARC), Sender Policy Framework (SPF), and DomainKeys Identified Mail (DKIM); using up-to-date Transport Layer Security (TLS); securing content management systems (CMS); and conducting targeted application testing.

Despite the public administration sector being mostly an opportunistic target for ransomware operators, the implementation of specific controls related to this kind of threat can minimise potential disruptions and enhance the cybersecurity posture of these entities.

ENISA recommends deploying Endpoint Detection and Response (EDR) solutions with behavioral rules, enforcing application allow-listing, and restricting the use of administrative tools such as PowerShell, Windows Management Instrumentation Command-line (WMIC), and PSExec to prevent unauthorized execution.

Document macros should be hardened by allowing only signed versions and blocking them by default whenever possible, reducing common initial infection paths. Network segmentation is also essential to limit the spread of intrusions. In addition, organizations should maintain backups with immutable or offline copies and conduct regular restore tests to ensure data recovery capability in the event of an attack.

As a high-value target for state- intrusion groups, the public administration sector must adopt concrete measures to prevent compromise by such adversaries. Regular threat-hunting should be conducted with a focus on Advanced Persistent Threat (APT) tactics, techniques, and procedures. Systems must be hardened, particularly against attack vectors observed in recent incidents, through consistent software updates and restrictions on web-based content.

Moreover, effective vulnerability and patch management are also essential to reduce exposure. In addition, third-party access should be tightly controlled using least-privilege principles, time-bound permissions, multi-factor authentication, and monitored service accounts to minimize the risk of exploitation.

The latest ENISA NIS360 report underscores a maturity–criticality gap in the public administration sector, where fragmented governance, limited information sharing, and outdated technology continue to leave institutions in the “risk zone.” To close this gap, ENISA recommends several targeted actions that strengthen resilience and support compliance with the NIS 2 Directive.

Public entities should build effective remediation capabilities through shared service models, partnering with peers to operate common security operations centers, identity management, and digital wallet platforms. This approach optimizes resources while reinforcing protection for high-risk services. Governments are also urged to leverage funding from the EU Cyber Solidarity Act alongside national budgets to modernize legacy infrastructure, deploy detection and response tools, and upskill staff, accelerating NIS 2 implementation in a cost-effective way.

Improving preparedness and response is another priority. ENISA advises expanding access to cyber ranges and tabletop exercises that allow teams to test incident response playbooks in realistic but controlled environments. Awareness campaigns should be launched to help leadership and operational staff understand NIS 2 obligations, reporting procedures, escalation protocols, and compliance timelines. Sector-specific threat intelligence should be strengthened by developing public administration–focused intelligence feeds that draw on ENISA’s reporting and national CSIRT capabilities.

Finally, collaborative engagement is essential. ENISA encourages regular workshops, Public Administration ISAC meetings, and cross-sector exercises with private stakeholders to exchange best practices and coordinate defenses for shared dependencies. By taking these steps proactively, public administrations can move closer to both compliance and genuine operational resilience.

Extracted Entities

Countries (3)

Industries (1)

Platforms (1)

Ransomware Groups (2)