Nearly every member state of the European Union was subjected to cyberattacks attributed to nation-state actors, primarily from Russia and China, over a 12-month period ending in July. According to the European Union Agency for Cybersecurity (ENISA), these attacks have steadily intensified, with only Luxembourg not publicly disclosing such incidents, a situation likely due to underreporting rather than absence of activity. ENISA's latest annual threat landscape report documented 46 nation-state-backed cyberattacks during this period, representing 7.2% of all known cyber incidents across the EU. Russian-linked threat actors were responsible for approximately half of these nation-state activities, with APT29 (Russia's Foreign Intelligence Service), APT28, and Sandworm (Units 26165 and 74455 of Russia's GRU) identified as the most active groups. The primary targets of these campaigns included public administration, diplomatic entities, defense organizations, and digital infrastructure within EU member states. Notably, APT29 was implicated in attacks against the European Space Agency and NATO partners, employing sophisticated compromise techniques. Chinese threat actors were also cited as significant contributors to the surge in cyberespionage and offensive cyber operations against European interests. The report highlights a trend of increasing sophistication and persistence in the tactics used by these nation-state actors, with a focus on intelligence gathering and disruption of critical sectors. ENISA emphasized that the true scale of these operations may be underrepresented due to limited public disclosures and possible underreporting by some member states. The agency's findings underscore the growing threat posed by state-sponsored cyber operations to the security and stability of the European Union. The attacks have prompted calls for enhanced cyber defense measures and greater information sharing among EU countries. The targeting of digital infrastructure and sensitive government entities raises concerns about the potential for long-term strategic impact and the erosion of trust in public institutions. ENISA's report serves as a warning to both policymakers and private sector leaders about the evolving landscape of nation-state cyber threats. The agency recommends increased investment in cybersecurity capabilities and cross-border cooperation to counteract these persistent threats. The findings also highlight the need for improved incident reporting and transparency to better assess and respond to the risks posed by foreign cyber operations. The ongoing campaigns by Russian and Chinese actors demonstrate a clear intent to influence, disrupt, or gather intelligence from European targets, necessitating a coordinated and robust response from the EU and its allies.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
ENISA publicly reported that Russian- and Chinese-linked actors were responsible for the majority of nation-state cyberattacks against EU member states in the year ending July 2025. The assessment highlighted Russian espionage by APT29, APT28, and Sandworm, and a recent spike in Chinese operations using edge-device compromises and relay boxes to hinder attribution.
In recent months before July 2025, ENISA assessed that Chinese-linked groups including Mustang Panda, APT41, and multiple Panda/Salt Typhoon clusters increased operations against maritime, shipping, and telecommunications targets in Europe. ENISA attributed 43% of the recorded nation-state hacks in its dataset to Chinese actors.
Dutch intelligence issued a warning that Chinese threat activity was targeting Dutch semiconductor-related organizations for strategic data collection and intellectual property theft. ENISA cited this as part of a broader rise in China-linked operations against Europe.
ENISA reported that APT29 also impersonated Amazon and Microsoft domains in phishing or deception activity aimed at EU foreign ministries. The operation reflected continued Russian espionage targeting of European government and diplomatic entities.
During the reporting period, ENISA said APT29 used compromised Microsoft infrastructure to steal RDP credentials from the European Space Agency and NATO partners. The activity was part of a broader Russian cyberespionage focus on public administration, diplomatic entities, defense, and digital infrastructure.
Over the 12 months from July 2024 to July 2025, ENISA recorded 46 nation-state-backed cyberattacks affecting EU member states, with nearly every member state experiencing at least one such incident. The agency said these attacks accounted for 7.2% of known cyber incidents in the EU during the period.
5 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcethecyberexpress.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcejamestown.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.