Churn Watch

Europe Faces Surge in Cyberattacks Exposing Defense Gaps

By H Pendleton October 5, 2026
Europe Faces Surge in Cyberattacks Exposing Defense Gaps - europe faces
Poland saw cyberattacks rise by 145% between 2024 and 2025, according to the report.

Europe faces a surge in cyberattacks targeting government ministries and critical infrastructure, exposing gaps in the bloc’s defenses despite years of cybersecurity initiatives.

Increasing Attacks Across the EU

Poland saw cyberattacks rise by 145% between 2024 and 2025, according to the report. In July, hackers stole sensitive data of over 600,000 French taxpayers. August brought a Russian-linked group taking German government systems hostage, encrypting personnel files and passwords, which forced some systems offline. Despite €1.4 billion in EU funding for cybersecurity, an EU Court of Auditors report found the early-warning system not fully operational. These incidents show the urgency of bolstering defensive capabilities across member states as adversaries exploit systemic vulnerabilities.

Cyber threats are growing as artificial intelligence enables hacktivists and state-backed actors to enhance attack speed and scale. Ilias Bakatsis, a cybersecurity expert with ENISA, noted that cybercriminals use AI to improve phishing campaigns and malware development. He expects state-linked groups to integrate AI into their operations, building on traditional methods. The integration of AI into cyberattacks not only accelerates execution but also allows for more sophisticated social engineering, as AI-generated content can mimic trusted sources with greater accuracy and personalization.

Fragmented Defenses and Rising Concerns

Europe’s approach has shifted from reactive to proactive over the past decade, focusing on prevention, detection, and response. However, experts highlight fragmentation across national borders and institutions, raising doubts about Europe’s ability to keep pace with AI-enhanced threats. Public administrations, energy networks, and transport systems are frequent targets, putting essential services at risk.

ENISA reported that 80% of incidents between July 2024 and June 2025 were ideologically driven, followed by financially motivated attacks and espionage. Public administration accounted for 38% of incidents, with transport and logistics also heavily targeted by ransomware groups. State-aligned actors favor less visible targets, exploiting supply-chain vulnerabilities and stolen software certificates in telecommunications and manufacturing. These tactics allow attackers to bypass traditional defenses by compromising trusted third-party vendors or embedding malicious code in legitimate software updates distributed to critical systems.

According to Bakatsis, the cyber threat environment has evolved rather than fundamentally changed, with shifts in techniques and tools. Sven Herpig, a cybersecurity advisor at Interface, emphasized the scale of the challenge, noting that 50,000 German organizations are critical infrastructure. He warned that most cannot defend against military or malicious civilian threats, as virtually every sector is vulnerable. The sheer volume of potential targets, combined with limited defensive resources, creates a environment where even minor breaches can cascade into widespread disruptions across interconnected systems.

The rise of low-cost Chinese open-source AI models, trailing U.S. frontier models by six to eight months, poses an immediate concern, Herpig and Roeland Delrue, a cybersecurity cofounder, argued. These models can be stripped of security features, enabling cheaper, scaled attacks. “We are seeing AI being used across the entire cyber kill chain, and making everything faster, not necessarily better,” Herpig said. The accessibility of these models to less-skilled actors lowers the barrier to entry for launching complex attacks, democratizing the tools once exclusive to state-sponsored groups.

Read Also: Rising anti-Ukrainian sentiment drives migrants out of Poland

Regulatory Moves and ENISA’s Role

European Parliament’s Committee on Security and Defence, SEDE, advocates for a real-time response center to address hybrid threats, including AI and quantum computing. MEP José Cepeda, a rapporteur, envisions it as a potential cyber command. “The whole area of military artificial intelligence, combined with quantum computing, is going to expose us to glaring threats, but in a very short period of time,” said MEP José Cepeda (ES, S&D), one of the rapporteurs of a nonbinding report on hybrid threats approved by the European Parliament on September 15. “That is why we need to establish a European center for real-time response to all types of threats.” However, governments hesitate to share sensitive data, even within their own agencies, complicating coordination. Herpig questioned the feasibility of the initiative, noting that without sharing tools and vulnerabilities among agencies, coordinating in the same room would not yield the desired results.

Countries like the UK, Italy, and France are developing national agencies with intelligence backgrounds to bolster cyber defense. Over the past 15 years, some countries have sought to combine military capabilities with specialist cyber expertise. Joseph Jarnecki of the Royal United Services Institute noted room for cooperation but cautioned against adding layers to an already crowded system. Differences in comfort with offensive cyber operations, such as France’s established capability versus Germany’s cautious shift, highlight challenges in forming a unified approach. These divergent strategies reflect broader questions about the appropriate balance between defensive and offensive operations in an era of escalating cyber conflicts.

The Enforcement Challenge

These changes aim to limit technology from unfriendly countries in sensitive areas like telecommunications. The bloc seeks to phase out high-risk 5G equipment, such as infrastructure from Chinese tech conglomerate Huawei. Officials argue this addresses long-accepted strategic risks in critical networks. The reforms also introduce stricter vetting procedures for foreign technology providers, requiring them to demonstrate compliance with EU security standards before being granted access to sensitive infrastructure.

Brussels is also revising the Network and Information Security 2 directive, or NIS2. The update expands mandatory cybersecurity requirements to more sectors and companies. It also tightens incident reporting rules to national authorities. Implementation gaps and inconsistent national rules previously undermined the original NIS directive’s goals. By mandating uniform standards and faster reporting, NIS2 aims to close loopholes that allowed vulnerable organizations to operate without adequate protections or transparency.

The EU plans to strengthen ENISA’s mandate to improve threat responses. The agency will gain enhanced capabilities to coordinate cyber defense efforts across member states. Additionally, Europe’s tech sovereignty push and a common security strategy aim to bolster the broader cyber ecosystem. These initiatives seek to address systemic vulnerabilities exposed by recent attacks. The strategy also includes funding for research and development of EU-made cybersecurity tools to reduce reliance on non-European technology providers.

Joseph Jarnecki emphasized that new legislation alone cannot solve core issues. He stressed the need to effectively empower and resource regulators to enforce existing rules. Without consistent enforcement, companies may continue neglecting basic security practices, leaving infrastructure exposed to attacks. “As boring as it sounds,” Jarnecki said, “what we need is to effectively empower and resource regulators.” The story has been updated on Sept. 29.

Leave a Reply

Your email address will not be published. Required fields are marked *

© 2026 TGPC Clients. All rights reserved.