After 16 years in software engineering, one lesson has stayed constant: security is paramount, whatever industry you work in. Fintech, healthcare, SaaS or a five-person startup, it doesn’t matter. If you hold data, run services or have people with logins, you are a target.
And with the surge in AI-enabled attacks, this matters more than ever. Attackers can now write convincing phishing messages, impersonate colleagues and move faster than before.
But security teams don’t need another list of scary headlines. They need to know what to do about them.
The ENISA Threat Landscape 20261 analyses threat activity observed during 2025. Below are the key threats highlighted in the report, with one practical prevention step for each.
Note: these are threats highlighted in the 2026 report, not necessarily attacks that first emerged in 2026.
The 10 key threats in the ENISA Threat Landscape 2026
1. Smishing Triad
Large-scale SMS phishing campaigns designed to steal credentials and payment information.
How to prevent it: Train staff not to click links in unsolicited SMS messages and enforce phishing-resistant MFA.
2. Mydocs
A major data-breach actor responsible for a significant share of observed breaches.
How to prevent it: Minimise exposed sensitive data and enforce strong access controls, MFA and monitoring around data repositories.
3. Hazy Hawk
Malicious activity that exploits organisations through compromised infrastructure and services.
How to prevent it: Continuously monitor internet-facing assets and patch vulnerabilities quickly.
4. ShinyHunters
A prominent data-breach actor, accounting for the largest share of observed activity in the report.
How to prevent it: Secure SaaS and CRM environments with MFA, least-privilege access and continuous monitoring.
5. Qilin
One of the most active ransomware operators affecting organisations in the EU.
How to prevent it: Maintain tested offline or immutable backups and practise rapid recovery.

6. Akira
A significant ransomware operation that was particularly active earlier in 2025.
How to prevent it: Prioritise rapid patching of internet-facing systems and remote-access infrastructure.
7. SafePay
A major ransomware operator with notable peaks in activity during 2025.
How to prevent it: Use endpoint detection and response (EDR) to catch ransomware behaviour before encryption spreads.
8. NoName057(16)
The most active hacktivist group during Q2 2025, with elevated activity continuing into Q3.
How to prevent it: Deploy DDoS protection and maintain resilient, redundant public-facing services.
9. ClickFix
A social-engineering technique that tricks users into running malicious commands under the guise of fixing a problem.
How to prevent it: Train employees never to paste or run commands supplied by websites, pop-ups or unsolicited support messages.
10. AI-enabled attacks
Growing use of AI in malicious cyber activity, including phishing and other attack stages.
How to prevent it: Strengthen identity security and employee verification processes. AI makes convincing impersonation and phishing far easier.
The common theme
Look closely, and a pattern appears. Many of these threats still rely on organisations getting the basics wrong:
- Weak identity controls
- Poor patching
- Excessive access
- Limited monitoring
- Untrained employees
- Untested recovery plans
You don’t always need more security tools. You need to make sure the controls you already have are actually working.
In a nutshell
The ENISA Threat Landscape 2026 covers threat activity observed during 2025, and the list is dominated by data-breach actors, ransomware operators, hacktivists and social engineering. AI is making phishing and impersonation faster and more convincing than ever before, yet most attacks still succeed through the same basic gaps: identity, patching, access, monitoring, training and recovery. Fix the fundamentals first, then test them regularly.
Frequently asked questions
What is the ENISA Threat Landscape 2026?
It is the EU cybersecurity agency’s annual report on the cyber threat landscape, analysing threat activity observed during 2025.
What is the biggest threat in the ENISA Threat Landscape 2026?
ShinyHunters accounts for the largest share of observed activity, while ransomware operators such as Qilin, Akira and SafePay remain among the most damaging.
How can small businesses protect themselves from these threats?
Start with phishing-resistant MFA, fast patching of internet-facing systems, least-privilege access and tested offline backups. These basics block a large share of the attacks in the report.
Which of these threats do you think organisations are underestimating? Let me know.
Not sure if your controls are actually working? Get in touch and let’s review your security fundamentals together.
Related posts
🔗 If you are building rather than scaling, start with my 5 Tech Stack Strategies, 5 Database Strategies and 5 App Maintenance Strategies for Non-Technical Founders.
📌 Follow Anjana Silva (LinkedIn) for engineering leadership and remote team building.
♻️ Share this with an engineer or founder who is concerned about cybersecurity.
