Europe has become the world’s second-largest ransomware target, trailing only North America, amid rising aggression from “Big Four” nation-state actors, a new CrowdStrike report has warned.
The cybersec firm’s 2025 European Threat Landscape Report reveals that European organisations made up nearly a quarter (22%) of global ransomware and extortion victims last year, as state-backed actors from Russia, China, North Korea, and Iran ramped up cross-industry attacks.
Since January 1, 2024, over 2,100 European victims have appeared on extortion leak sites, most from the UK, Germany, France, Italy, and Spain, with 92% of cases involving file encryption and data theft.
CrowdStrike identifies China as one of the most aggressive state actors in data theft, though less focused on ransomware and more intent on infiltrating cloud infrastructure and software supply chains to steal intellectual property.
Persistent campaigns tied to Chinese groups have targeted healthcare and biotech sectors, with Vixen Panda emerging as the leading threat to European government and defence networks.
Iran has also reportedly expanded its cyber operations in Europe, with threat groups linked to the Islamic Revolutionary Guard Corps (IRGC) ramping up their phishing, hack-and-leak, and DDoS campaigns against the UK, Germany, and the Netherlands.
In one notable example of Iran’s growing influence, the Haywire Kitten group (malicious despite its cute name) claimed responsibility for a DDoS attack against a Dutch news outlet, while multiple other Iran-nexus actors masqueraded as hacktivists to obscure state-sponsored espionage efforts.
Meanwhile, more established threat groups linked to Russia have continued to target Ukraine, conducting credential phishing, intelligence collection, and destructive operations targeting government, military, energy, telecom, and utilities, while North Korean groups have expanded their targeting of European defence, diplomatic, and financial institutions, combining espionage with cryptocurrency theft to advance strategic interests.
It’s no coincidence these hostile groups are targeting Europe’s largest economies, home to high-value sectors like manufacturing, professional services, technology, industrials, and engineering, which remain prime targets for the likes of DPRK hackers, who are increasingly concerned with revenue generation to supplement the state’s coffers.
“The cyber battlefield in Europe is more crowded and complex than ever,” said Adam Meyers, head of Counter Adversary Operations at CrowdStrike.
“We’re seeing a dangerous convergence of criminal innovation and geopolitical ambition, with ransomware crews using enterprise-grade tools and state-backed actors exploiting global crises to disrupt, persist, and conduct espionage.
Recommended reading
- Ransom Group LockBit Forms ‘Unholy Alliance’ to Escalate Attacks
- Qilin Emerges as 2025’s Most Active Ransomware Threat
- 93% of Ransomware Victims Lose Data – Even After Paying
Meanwhile, CrowdStrike also observed a jump in threat actor capabilities, with high-profile groups like SCATTERED SPIDER increasing their ransomware deployment speed by 48%, meaning the average attack now takes just twenty-four hours.
This efficiency is supplemented by the evolution of the cyber underground, with English and Russian-language forums becoming central to Europe’s criminal ecosystem, with dark web markets allowing the exchange of stolen data, malware, and criminal services, while platforms like Telegram, Tox, and Jabber facilitate collaboration, recruitment, and monetisation.
More terrifying than any of that, however, is that these groups are no longer restricting themselves to cyber savagery, with Violence-as-a-Service emerging as a fast-growing threat across Europe.
CrowdStrike observed threat actors using Telegram-based networks to coordinate physical attacks, kidnappings, and extortion tied to cryptocurrency theft, saying that groups connected to “The Com” ecosystem are bridging cyber and physical operations, offering payments for sabotage, arson, and targeted violence.





