TL;DR: ENISA’s 2025 threat landscape analysis of 5,000 incidents shows phishing remains a dominant initial access path, DDoS accounts for more than 75% of incidents, and ransomware plus AI-supported attacks are reshaping adversary behaviour across Europe, according to Semgrep. The security shift is from reactive controls to intelligence-driven resilience, where attacker convergence and automation matter as much as raw volume.
At a glance
What this is: This is Semgrep’s analysis of ENISA’s 2025 threat landscape, with phishing, DDoS, ransomware, and AI-enabled attack automation emerging as the main patterns.
Why it matters: It matters because identity, access, and human-targeted controls still shape initial compromise, while resilience planning must account for automated campaigns and blurred attacker motivations.
By the numbers:
- ENISA analysed 5,000 incidents across the European Union for its 2025 threat landscape.
- DDoS attacks make up more than 75% of all incidents in the report.
👉 Read Semgrep's analysis of ENISA's 2025 threat landscape
Context
ENISA’s 2025 threat landscape is a broad cyber risk assessment, but the governance lesson is specific: attackers are optimising for scale, repeatability, and human compromise before they ever need to defeat deeper technical controls. For identity and access teams, that keeps phishing, vishing, malspam, and credential theft in the centre of the risk picture, while DDoS and ransomware show how operational disruption and extortion continue to evolve.
The article frames cyber conflict as increasingly automated and industrialised, which is consistent with what security teams now see across cloud, endpoint, and identity programmes. The identity angle is strongest at initial access, where human identity remains the easiest entry point, but the broader signal is that security leaders need intelligence-led prioritisation rather than control sprawl.
Key questions
Q: How should security teams reduce phishing risk in high-value access paths?
A: They should replace phishable MFA methods on privileged and remote access routes with phishing-resistant authentication that binds the factor to the device or certificate chain. The goal is to remove reusable secrets from the most exposed journeys, not simply add another approval step. That approach materially lowers the chance that social engineering becomes account compromise.
Q: Why do DDoS and ransomware require joint resilience planning?
A: Because both attacks are designed to create operational pressure, just through different mechanisms. DDoS interrupts availability directly, while ransomware adds extortion and potential leakage. When teams plan for them separately, they miss the fact that attackers often use disruption to mask intrusion or increase leverage. Shared recovery and identity monitoring reduce that blind spot.
Q: What do security teams get wrong about AI-assisted investigations?
A: They assume the model is the main value. In practice, the value comes from the quality and accessibility of the underlying data plus the consistency of the investigation method. If those are weak, AI simply automates confusion. The right goal is to scale expert judgment, not to replace evidence quality with faster output.
Q: How do organisations know if threat intelligence is actually helping?
A: They should look for shorter time to block new patterns, fewer repeated incidents from the same campaign, and faster coordination between fraud, SOC, and compliance teams. If intelligence is not changing decisions or reducing exposure during peak traffic, it is reporting rather than defence.
Technical breakdown
Phishing as the dominant initial access path
Phishing remains effective because it targets the trust layer, not just the technical perimeter. The article notes that attackers now use vishing, malspam, malvertising, and AI-assisted social engineering to increase success rates and tailor messages at scale. That means initial access is often a human decision failure amplified by automation, not a sophisticated exploit chain. For identity programmes, the practical issue is that authentication controls arrive after the first compromise attempt, so prevention must start with user verification, resistant authentication, and behavioural monitoring.
Practical implication: reduce phishing success before credential capture by tightening identity verification, training, and step-up authentication at the point of risk.
Why DDoS and ransomware now shape the attack economy
DDoS and ransomware illustrate two different industrialised attack models. DDoS creates immediate service disruption and is attractive for hacktivist campaigns, while ransomware is designed for coercion, revenue, and often data leakage as a second pressure point. The article also describes a blurring of motivations, where state-aligned groups adopt ransomware or hacktivist personas to mask intent and increase operational flexibility. From a control perspective, resilience, segmentation, backup integrity, and recovery testing matter as much as detection.
Practical implication: treat availability and recovery controls as part of cyber defence, not just business continuity, because extortion now blends disruption with identity theft and data pressure.
AI-enabled attacker automation and TTP convergence
The report highlights convergence between actor types and the use of AI to scale attack operations. That does not mean AI replaces traditional TTPs. Instead, it compresses time, improves targeting, and supports continuous campaigns rather than one-off incidents. The result is a wider, faster threat surface where defenders must correlate intelligence across email, identity, cloud, and endpoint layers. For practitioners, the key issue is not whether AI is used, but how much faster it lets ordinary attack patterns move from reconnaissance to impact.
Practical implication: align detection engineering and response playbooks to faster campaign tempo, not just to individual attack techniques.
Threat narrative
Attacker objective: The attacker aims to gain initial access quickly, scale campaigns efficiently, and convert compromise into disruption, extortion, or influence effects.
- Entry begins with phishing, vishing, malspam, or malvertising that exploits human trust and delivers the attacker’s first foothold.
- Escalation follows through credential capture, automated campaign scaling, or pivoting into ransomware, persistence, or disruption tactics.
- Impact is service interruption, extortion, election-linked manipulation, or broader operational compromise across targeted sectors.
NHI Mgmt Group analysis
Phishing remains the most durable form of identity abuse because it attacks the human decision point before any control can fail. ENISA’s analysis reinforces that initial access is still heavily shaped by human trust, whether through email, voice, or social platforms. That means identity security cannot be treated as a post-login problem. The governing assumption that users can reliably spot malicious access attempts is still too weak for current attacker economics, and practitioners should design controls that assume human error will occur.
DDoS at scale is a resilience problem, but it is also an identity governance signal when attackers use it to distract from secondary intrusion. The report’s emphasis on over 75% DDoS prevalence shows that availability attacks remain a preferred route for disruption and diversion. For teams running IAM, PAM, and NHI programmes, the lesson is that incident sequencing matters: distraction attacks often create windows for credential abuse or operational drift. Practitioners should connect resilience planning to identity monitoring.
AI has not replaced established attack patterns. It has industrialised them. The report describes AI-assisted phishing and continuous campaigns, which means the decisive change is speed and scale, not a new class of threat. This is the point where security telemetry, campaign intelligence, and identity analytics need to work together. Practitioners should expect faster attacker iteration and shorter decision windows across the full kill chain.
Attack convergence is producing governance debt for security programmes that still separate human identity, endpoint, cloud, and fraud operations. ENISA’s report shows blurred lines between state-sponsored activity, hacktivism, and financially motivated attacks. Converged campaign governance: this is the failure mode where defenders can no longer tell whether an event is a disruption attempt, a persistence probe, or a revenue play. Practitioners should unify triage and ownership across domains so adversary movement is seen as one campaign rather than isolated alerts.
What this signals
Attack convergence changes how programmes should be organised. If phishing, DDoS, ransomware, and AI-supported campaign automation are all part of the same adversary economy, then control ownership cannot stay fragmented across separate teams. Security leaders should expect more incidents that start in one domain and land in another, which makes shared triage, shared telemetry, and cross-domain incident ownership essential. For identity programmes, that means login risk, credential abuse, and access monitoring belong in the same operating rhythm as SOC response.
The new operational risk is not only compromise, but speed. AI-assisted attacks compress the time available to detect, verify, and contain. That puts pressure on identity verification, conditional access, and recovery testing because defenders now have fewer manual decision windows. Practitioners should watch for campaign tempo rising faster than analyst throughput, especially in environments where email, cloud, and endpoint tools are not yet correlated.
Human identity controls remain the first line of defence against automation-heavy attacks. The same phishing pathways described in the report still work because they exploit trust, not technology alone. Where teams need external reference points, MITRE ATT&CK Enterprise Matrix remains useful for mapping the techniques that follow initial access, while CISA cyber threat advisories help contextualise current adversary patterns for response planning.
For practitioners
- Harden initial access controls against human-targeted attack paths Prioritise phishing-resistant authentication, strong email and domain protections, and user verification workflows for high-risk actions. Treat vishing and malvertising as first-class entry vectors rather than edge cases. Link awareness efforts to the specific services attackers most often impersonate.
- Tie resilience planning to identity and access telemetry Correlate DDoS, ransomware, and authentication anomalies in the same operating view so diversion attacks do not hide privilege abuse. Use alerting that distinguishes service disruption from credential-related anomalies and run recovery exercises that include identity restoration.
- Consolidate campaign analysis across security domains Build a shared incident taxonomy that spans email, identity, cloud, endpoint, and SOC teams. The goal is to stop treating each alert stream as a separate problem when attackers are using continuous campaigns and AI-assisted speed to blur boundaries.
- Refresh threat models around automation, not just exploit novelty Assume attackers will use AI to scale reconnaissance, tailor lures, and shorten time-to-impact. Update playbooks and detection rules around campaign tempo, not only around named techniques, and rehearse responses to multi-vector activity.
Key takeaways
- ENISA’s 2025 threat landscape shows that phishing, DDoS, ransomware, and AI-supported automation are converging into a faster and more industrialised attack environment.
- For identity and security teams, the main lesson is that human trust remains the easiest entry point, while resilience now depends on cross-domain visibility and recovery readiness.
- Programmes that separate email, identity, cloud, and SOC response will struggle to keep pace with blended campaigns that move quickly from access to disruption.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001 , Initial Access; TA0006 , Credential Access; TA0040 , Impact | Phishing, credential abuse, and disruptive payloads are central to this report. |
| NIST CSF 2.0 | PR.AA-1 | Identity assurance and access control are directly implicated by phishing-led access paths. |
| NIST SP 800-53 Rev 5 | SI-4 | Monitoring and alerting are needed for AI-assisted campaigns and blended attack sequences. |
| CIS Controls v8 | CIS-8 , Audit Log Management | Cross-domain attack detection depends on log visibility and correlation. |
| NIST Zero Trust (SP 800-207) | Zero trust is relevant because the report centres on identity compromise and repeated access attempts. |
Map campaign stages to ATT&CK and prioritise detection for initial access, credential theft, and impact pathways.
Key terms
- Initial Access: Initial access is the first successful foothold an attacker gains in an environment. In this article's context, it is often achieved through phishing, vishing, malspam, or malvertising that persuades a user or system to trust the wrong source.
- Attack Convergence: Attack convergence is the blending of tactics, motivations, and actor types into fewer distinguishable campaigns. It matters because defenders can no longer assume a neat split between hacktivism, ransomware, espionage, or disruption when one operation may contain all four.
- Campaign Tempo: Campaign tempo is the speed at which adversaries move from reconnaissance to compromise, persistence, and impact. AI-supported automation increases tempo by reducing the time needed to research targets, create lures, and launch large-scale attacks.
What's in the full article
Semgrep's full analysis covers the operational detail this post intentionally leaves for the source:
- ENISA's incident breakdown by attack category and sector, including the specific patterns behind the 5,000 cases
- The article's full discussion of state-linked activity, hacktivism, and financially motivated attack blending
- Examples of how AI is changing phishing research, campaign scale, and attacker efficiency
- The report context for budget planning and defensive prioritisation going into 2026
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management, and workload identity in the context of modern access risk. It helps practitioners connect identity controls to broader security operations and programme resilience.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org