A new report by the EU Agency for Cybersecurity (ENISA) has found that public administrations across the bloc are increasingly being targeted by hacktivists, with Distributed Denial of Service (DDoS) attacks emerging as the most common threat.
The findings, published in the ENISA NIS360 report, assess the sector as being in the “risk zone” as it continues to align with the requirements of the NIS2 Directive — the EU’s updated cybersecurity legislation for essential sectors. Public administration is considered highly critical under the directive, playing a central role in delivering essential services such as education, healthcare, and public transport.
ENISA said the sector remains in the early stages of developing its cybersecurity resilience. According to its latest cyber threat landscape report, public administration was the most targeted sector in the EU in 2024, accounting for 38% of all recorded cyber incidents.
“Cyber-securing public administrations is central to citizens’ welfare and to the good functioning of the single market across the EU,” said ENISA Executive Director, Juhan Lepassaar. “Public administrations provide reliable and effective public services, so it is essential to ensure a high-level of cybersecurity within their wider network of national, regional and local bodies.”
The analysis draws on 586 publicly reported cyber incidents from 2024. ENISA said that, because public administrations manage high volumes of sensitive data and deliver essential services in an increasingly digital environment, they are highly vulnerable to disruption — with such incidents also capable of undermining public trust.
Hacktivists Dominate, DDoS Attacks Lead the Way
Among the key findings, central government bodies were the most frequently targeted, accounting for 69% of incidents. The majority of these involved websites of parliaments, ministries, and national agencies, with DDoS attacks representing 60% of all cases. While typically short-lived and limited in impact, the cumulative effect of such campaigns has been significant.
Data breaches and ransomware were less common but more disruptive. Data-related threats — including breaches (17.4%) and exposures (1%) — were the second most frequent category of incidents in 2024. Common targets included employment services, local government platforms, law enforcement portals, and educational systems.
Hacktivist groups were identified as the main perpetrators, accounting for nearly 63% of incidents. These ideologically motivated actors primarily sought attention and disruption, often targeting ministry and municipal websites.
Cybercrime operators made up around 16% of incidents, while state-linked intrusion campaigns represented just 2.5%, though ENISA noted that the latter could have a disproportionate impact on national security due to the strategic value of the data targeted.
Phishing remained a common entry point for attacks, while the increased use of AI tools was identified as a growing risk factor, particularly for social engineering and multi-extortion campaigns. Such incidents, ENISA warned, could lead to serious service outages affecting tax systems, e-ID platforms, and court scheduling — eroding confidence in public digital services.
The agency also highlighted the cascading risks of shared digital infrastructure, where a single compromise can affect multiple entities.
With public administration now formally covered under the NIS2 Directive, ENISA has set out a series of recommendations to help authorities strengthen their defences.
Recommended reading
- 60% of UK IT Leaders Urge for Data Sovereignty In Wake of US Tariffs
- Tariffs and Trade War Are the Top Emerging Risks of Q2 2025
- Report: Cybersecurity Tops Tariffs as Q1 Priority for Supply Chains
These include enrolling critical portals behind content delivery networks (CDNs) or web application firewalls (WAFs) to mitigate DDoS risks; publishing static fallback sites with DNS failover; and implementing multi-factor authentication, privileged access management, and endpoint detection tools to reduce the likelihood and impact of ransomware or data breaches.
Further guidance encourages governments to build shared remediation capabilities, make use of the EU’s forthcoming Cybersecurity Reserve under the Cyber Solidarity Act, and enhance cross-border preparedness and response.
ENISA concluded that public administrations are likely to remain prime targets for cyber attacks in the near term. By prioritising the measures outlined in the report, the agency said, EU institutions and member states can better safeguard critical services and strengthen public confidence in an increasingly volatile digital landscape.





