RESEARCH PREVIEW — Attention: Data Spaces may hack the planet.

Europe

Analyse
Primarily a target — 233 received· 43 initiated· 51 responses ·44 countries

This year to date, 240 new cyber operations involving Europe were added to the database: a 1% decrease compared to the previous period. The number of operations is currently 19% below the long-term year-to-date average. The Intensity of cyber operations involving Europe over this year to date is declining to 3.1, compared with 3.1 in the same elapsed span of the previous year. This is above the all-time average for Europe of 2.7.

Maintained by EuRepoC research analysts · updated 05 Oct 2026
233received initiated43
For this year to date, this region appears chiefly as a target — 233 incidents directed at it, 43 it is linked to initiating.
Source: EuRepoC Global Database as of 05 Oct 2026.
01 / 02

Cyber activity

43 incidents · as actor

Operations EuRepoC links to actors based in Europe, and the international responses they drew.

Cyber incident intensity
Mean3.1/15Moderate
Range 1.0–6.0

Drag the ends of the observed range to narrow intensities.

42 coded incidents · This year to date
Database additions by monthincidents linked to Europe
Bar height shows incidents added during this year to date; select a bar to filter this interval; hover for average intensity.
Most-targeted sectorswhat its operations hit
Its operations concentrate on Government / ministries — 12 of 43 incidents.
By targetwho its operations hit
Ukraine 13incidents avg 3.5 · Moderate United States 10incidents avg 3.7 · Moderate Poland 9incidents avg 3.8 · Moderate France 9incidents avg 3.1 · Moderate Germany 9incidents avg 3.7 · Moderate Romania 7incidents avg 4.4 · Moderate United Kingdom 7incidents avg 3.6 · Moderate Croatia 6incidents avg 3.5 · Moderate
Showing 8 of 52
02 / 02

Operations initiated & responses drawn

NONorwegian Digitalisation Agency Norway Norwegian Digitaliseringsdirektoratet Director Frode Danielsen Issues Statement Following DDoS Attack on Digdir's Digital Solutions on 25 August 2026 Operational action 25 Aug 2026
Operational action 25 Aug 2026
NONorwegian Digitalisation Agency Norway
Norwegian Digitaliseringsdirektoratet Director Frode Danielsen Issues Statement Following DDoS Attack on Digdir's Digital Solutions on 25 August 2026
Server Killers Norway ·Digital Provider +1 Russian Threat Actors "Server Killers" Conducted DDoS Attack On Norwegian Digitalisation Agency On 24 August 2026 24 Aug 2026
Incident · Low severity 24 Aug 2026
Server Killers Norway ·Digital Provider +1
Russian Threat Actors "Server Killers" Conducted DDoS Attack On Norwegian Digitalisation Agency On 24 August 2026
(Russia) Poland ·Other Russian Or Belarussian Threat Actors Defaced Pilecki Institute's Website In Poland and Germany On 13-14 August 2026 13 Aug 2026
Incident · Low severity 13 Aug 2026
(Russia) Poland ·Other
Russian Or Belarussian Threat Actors Defaced Pilecki Institute's Website In Poland and Germany On 13-14 August 2026
Cyber Corps (Main Directorate of Intelligence, Ukraine; HUR) Russia ·Corporate Targets Ukraine Military Intelligence (HUR) Disrupted Russian E-Commerce Company Wildberries In Russia On 10-11 August 2026 10 Aug 2026
Incident · Low severity 10 Aug 2026
Cyber Corps (Main Directorate of Intelligence, Ukraine; HUR) Russia ·Corporate Targets
Ukraine Military Intelligence (HUR) Disrupted Russian E-Commerce Company Wildberries In Russia On 10-11 August 2026
Cyber Army of Russia Reborn, CARR (GRU) Canada ·Civil service / administration +1 Russian Hacker Group Hijacked Drinking Water Plant In Saint-Noël, Canada On 23 July 2026 23 Jul 2026
Incident · Low severity 23 Jul 2026
Cyber Army of Russia Reborn, CARR (GRU) Canada ·Civil service / administration +1
Russian Hacker Group Hijacked Drinking Water Plant In Saint-Noël, Canada On 23 July 2026
CACZFRNZ+1216 statesjoint LAUNDRY BEAR (Russian Federation) International Partners Issued Joint Cybersecurity Advisory Warning of Russian State-Supported Laundry Bear's Phishing Campaign Targeting Zimbra Collaboration Suite Users on 23 July 2026 Technical disclosure 23 Jul 2026
Technical disclosure 23 Jul 2026
CACZFRNZ+1216 states LAUNDRY BEAR (Russian Federation)
International Partners Issued Joint Cybersecurity Advisory Warning of Russian State-Supported Laundry Bear's Phishing Campaign Targeting Zimbra Collaboration Suite Users on 23 July 2026
Laundry Bear #N/AUSATBE+2529 countries ·Government / ministries +4 Russia-Aligned Threat Actor TA488 aka LAUNDRY BEAR Stole Emails and Account Credentials from US and European Government Entities Since 22 July 2026 22 Jul 2026
Incident · Low severity 22 Jul 2026
Laundry Bear #N/AUSATBE+2529 countries ·Government / ministries +4
Russia-Aligned Threat Actor TA488 aka LAUNDRY BEAR Stole Emails and Account Credentials from US and European Government Entities Since 22 July 2026
High Representative of the European Union Evgeniy Viktorovich Bashev (Russian Federation) European Union Imposed Sanctions on Russian Entities and Condemned Russia’s Cyber Ecosystem on 13 July 2026 Official policy 13 Jul 2026
Official policy 13 Jul 2026
High Representative of the European Union Evgeniy Viktorovich Bashev (Russian Federation)
European Union Imposed Sanctions on Russian Entities and Condemned Russia’s Cyber Ecosystem on 13 July 2026
Showing the 8 most recent of 63 Open all in advanced search
Search