EU ransomware and cyber extortion policy

ENISA's 2026 Threat Landscape Shows Ransomware Is a Data Problem Before It Is a Ban Problem

ENISA's 8,257-incident dataset shows ransomware dominates financial crime, but DDoS noise inflates the sector rankings. Proportionate reporting rules fit that evidence.

ENISA Threat Landscape 2026: Ransomware in Context People of Internet Research · EU 8,257 Incidents analysed in 2025 Mostly open-source data covering 1… 47.3% Ransomware share of financial activity Ahead of data breaches at 36.0%. 31.8% Public administration incident share Largely driven by ideology-driven … 72.9% Essential entities' incident share Share of recorded incidents involv… peopleofinternet.com
ENISA Threat Landscape 2026: Ransomwar… People of Internet Research · EU 8,257 Incidents analysed in 2025 47.3% Ransomware share of financial act… 31.8% Public administration i… 72.9% Essential entities' incide… peopleofinternet.com

Key Takeaways

The strongest case for tougher EU ransomware rules is that the harm is concentrated and well documented. ENISA's Threat Landscape 2026, published on 22 September 2026, analysed 8,257 incidents recorded from 1 January to 31 December 2025. It found that ransomware deployment made up 47.3% of recorded financially motivated activity, ahead of data breaches at 36.0%. Regulators who want mandatory payment reporting, harder supervision and more coordination can point to that. Ransomware is the threat ENISA says most hurts EU organisations in the short term.

The same report also shows why headline numbers need careful reading. Policy built on a blurred statistic will be poorly aimed.

Two different rankings, two different problems

ENISA reports that public administration was the most-targeted sector, at 31.8% of recorded incidents, and that essential entities under NIS2 accounted for 72.9% of them. Read alone, those figures suggest ransomware is hollowing out European government. The report does not say that. Its own text says public administration was "largely impacted by ideology-driven DDoS attacks." DDoS made up 51.3% of all recorded incidents, and ENISA calls it "low-impact." Ideology-driven activity was 57.3% of incidents, while financially motivated activity was 29.3%.

The ransomware-specific sector ranking looks different. Among ransomware claims, manufacturing led at 25.2%, business services followed at 18.7%, and public administration came fifth at 6.6%. Multiplying the report's shares gives ransomware at roughly 14% of all incidents. That is my own calculation, not an ENISA figure, but it shows the scale. Ransomware is the costliest category, not the most common one.

Geography is also uneven. Among identified ransomware claims, Germany accounted for 26.5%, France 14.7%, Italy 13.6% and Spain 12.2%. The most active groups were Qilin, SafePay, Akira, INC Ransom and Hunters International, and 15% of claims could not be attributed to any group. ENISA's methodology notes that much of the data comes from open sources and leak-site claims. Those are claims by criminals, not audited incident counts.

What the evidence supports

The most useful finding for lawmakers is a modest one. ENISA identified 33 EU organisations that were repeat victims, and 44% of those cases involved ransomware. The report links repeat targeting to "a lack of restoration practices following incident response." Repeat victims were hit because recovery was incomplete, and no ban would have changed that. Support for backups, segmentation and post-incident cleanup addresses the failure ENISA actually documents.

Law enforcement is having some effect, though ENISA says its impact is "rarely quantified." The report lists Operation Endgame on 19 May 2025, which took down 300 servers and 650 domains and seized €3.5 million in cryptocurrency. It also lists the arrest of Phobos and 8Base figures and the takedown of BlackSuit infrastructure. These operations disrupt criminal supply chains without adding compliance cost for victims.

The EU's two reporting tracks

Two regulatory tracks now overlap, and they should not be conflated. On 11 September 2026, the Cyber Resilience Act's reporting obligations began, and ENISA launched the Single Reporting Platform the same day. Manufacturers must report actively exploited vulnerabilities and severe incidents in products with digital elements. The deadlines are an early warning within 24 hours, a notification within 72 hours, and a final report after a fix is available. That platform is about product security, not about ransomware victims.

The ransomware-specific change is the Commission's 20 January 2026 proposal to amend NIS2. It aims at "streamlining the collection of data on ransomware attacks." According to law-firm analysis, entities reporting a significant ransomware incident could be asked to say whether a demand was made and by whom, whether it was paid, the amount and the payment method. The same proposal creates a "small mid-cap" category, covering firms with fewer than 750 employees and under €150 million in turnover, that would mostly be treated as important entities and supervised after the fact. The proposal is still moving through Parliament and Council.

The proposal is the right design. It asks for information on request, it does not prohibit payment, and it lightens the load for smaller companies. It is also the fix for the data problem above, because ENISA has to reconstruct ransomware activity from leak sites and press reports.

Where to be careful

The risk is a jump from these statistics to blunt measures. A payment ban would push extortion underground and leave hospitals, councils and manufacturers facing an impossible choice with no lawful path. Nothing in ENISA's data shows that a ban would reduce attacks. Broad reporting mandates carry a cost too. The CRA platform launched without API support and in English only, and a separate rule for every threat category multiplies filings for the same event.

The better sequence is to finish the NIS2 amendment, measure confirmed incidents and payments over a full reporting cycle, and only then decide whether stronger tools are justified. ENISA's next report should be able to separate confirmed victims from leak-site claims. Until then, the evidence points to funding recovery capacity, backing law-enforcement takedowns, and collecting better data.

Sources & Citations

  1. ENISA Threat Landscape 2026 (full report)
  2. ENISA: CRA Single Reporting Platform is launched
  3. European Commission: NIS2 simplification and Cybersecurity Act alignment proposal
  4. European Commission: CRA reporting obligations
  5. Covington Global Policy Watch: Commission proposes targeted NIS2 amendments
  6. Help Net Security: ENISA launches CRA Single Reporting Platform