Belgium Faces Surge in Cyber Incidents Amid NIS2 Directive Implementation

Belgium Faces Surge in Cyber Incidents Amid NIS2 Directive Implementation

First seen 27 Mar 2026, 08:45 UTC Ccb.Belgium.BeIndustrialcyber.Co 81% similarity 58.0

Article Content

Browse articles
ThreatCluster

In 2025, Belgium experienced a notable increase in cyber incidents, with the Centre for Cybersecurity Belgium (CCB) reporting 635 total incidents, a 70% rise from the previous year. Of these, 556 were confirmed cyber incidents, reflecting a 58% year-on-year increase. The uptick in reporting is attributed to the NIS2 directive, which has enhanced awareness and compliance among organizations. Account compromise was the most prevalent threat, with 144 cases reported, while ransomware incidents remained stable at 105 but became more impactful. Phishing attacks surged, with nearly 10 million suspicious emails reported through the Safeonweb platform. The threat landscape also included state-linked activities, particularly from pro-Russian hacktivist groups targeting critical infrastructure. Despite the increase in incidents, the real-world impact of attacks was mitigated by the CCB's coordination efforts. The average time-to-exploit for vulnerabilities decreased significantly, highlighting the urgency for rapid response and patching. Overall, the data indicates a shift towards greater visibility of cyber threats rather than a proportional increase in attacks.

Key Points: • Belgium reported 635 cyber incidents in 2025, a 70% increase from 2024. • Account compromise (144 cases) and ransomware (105 incidents) were the top threats. • Nearly 10 million phishing emails were reported, indicating a rise in phishing activity.

ThreatCluster AI How this analysis works

Timeline

2025-01-01
NIS2 directive implemented, increasing reporting requirements.
2025-12-31
CCB reports 635 total incidents for 2025.
2025-12-31
CCB identifies account compromise as the most common threat.
2025-12-31
CCB reports nearly 10 million phishing emails processed.
2025-12-31
Ransomware incidents reported stable but more impactful.

Community

Browse all →

Tracked Entities in This Story