Cybersecurity: main and emerging threats | Topics | European Parliament (2024)

Find out about the top cyber threats in 2022, the most affected sectors and the impact of the war in Ukraine.

The digital transformation has inevitably led to new cybersecurity threats. During the coronavirus pandemic, companies had to adapt to remote working and this created more possibilities for cybercriminals. The war in Ukraine has also affected cybersecurity.


In response to the evolution of cybersecurity threats, Parliament adopted a new EU directive introducing harmonised measures across the EU, including on the protection of essential sectors.

Read more on new EU measures to fight cybercrime

Top 8 cybersecurity threats in 2022 and beyond

According to the Threat Landscape 2022 report by the European Union Agency for Cybersecurity (Enisa), there are eight prime threat groups:

1. Ransomware: hackers seize control of someone’s data and demand a ransom to restore access

In 2022, ransomware attacks continued to be one of the main cyberthreats. They are also getting more complex. According to a survey quoted by Enisa that was conducted at the end of 2021 and in 2022, over half of respondents or their employees had been approached in ransomware attacks.

Data quoted by the EU Agency for Cybersecurity shows that the highest ransomware demand grew from €13 million in 2019 to €62 million in 2021 and the average ransom paid doubled from €71,000 in 2019 to €150,000 in 2020. It is estimated that in 2021 global ransomware reached €18 billion worth of damages – 57 times more than in 2015.

2. Malware: software that harms a system


Malware includes viruses, worms, Trojan horses and spyware. After a global decrease in malware linked to the Covid-19 pandemic in 2020 and early 2021, its use increased heavily by the end of 2021, as people started returning to the office.

The rise of malware is also attributed to crypto-jacking (the secret use of a victim’s computer to create cryptocurrency illegally) and Internet-of-Things malware (malware targeting devices connected to the internet such as routers or cameras).

According to Enisa, there were more Internet-of-Things attacks in the first six months of 2022 than in the previous four years.

3. Social engineering threats: exploiting human error to gain access to information or services

Tricking victims into opening malicious documents, files or emails, visiting websites and thus granting unauthorised access to systems or services. The most common attack of this sort is phishing (through email) or smishing (through text messages).

Almost 60% of the breaches in Europe, the Middle East and Africa include a social engineering component, according to research quoted by Enisa.

The top organisations impersonated by phishers were from the financial and technology sectors. Criminals are also increasingly targeting crypto exchanges and cryptocurrency owners.

4. Threats against data: targeting sources of data to get unauthorised access and disclosure

We live in a data-driven economy, producing huge amounts of data that are extremely important for, among others, enterprises and Artificial Intelligence, which makes it a major target for cybercriminals. Threats against data can be mainly classified as data breaches (intentional attacks by a cybercriminal) and data leaks (unintentional releases of data).

Money remains the most common motivation of such attacks. Only in 10% of cases is espionage the motive.

Read more about how the EU wants to boost data sharing and regulate AI

5. Threats against availability - Denial of Service: attacks preventing users from accessing data or services

These are some of the most critical threats to IT systems. They are increasing in scope and complexity. One common form of attack is to overload the network infrastructure and make a system unavailable.

Denial of Service attacks are increasingly hitting mobile networks and connected devices. They are used a lot in Russia-Ukraine cyberwarfare. Covid-19 related websites, such as those for vaccination have also been targeted.

6. Threats against availability: threats to the availability of the internet

These include physical take-over and destruction of internet infrastructure, as seen in occupied Ukrainian territories since the invasion, as well as the active censoring of news or social media websites.

7. Disinformation/misinformation: the spread of misleading information

The increasing use of social media platforms and online media has led to a rise in campaigns spreading disinformation (purposefully falsified information) and misinformation (sharing wrong data). The aim is to cause fear and uncertainty.

Russia has used this technology to target perceptions of the war.

Deepfake technology means it is now possible to generate fake audio, video or images that are almost indistinguishable from real ones. Bots pretending to be real people can disrupt online communities by flooding them with fake comments.

Read more about the sanctions against disinformation the Parliament is calling for

8. Supply-chain attacks: targeting the relationship between organisations and suppliers

This is a combination of two attacks - on the supplier and on the customer. Organisations are becoming more vulnerable to such attacks, because of increasingly complex systems and a multitude of suppliers, which are harder to oversee.

Top sectors affected by cybersecurity threats


Cybersecurity threats in the European Union are affecting vital sectors. According to Enisa, the top six sectors affected between June 2021 and June 2022 were:

  1. Public administration/government (24% of incidents reported)
  2. Digital service providers (13%)
  3. General public (12%)
  4. Services (12%)
  5. Finance/banking (9%)
  6. Health (7%)

Read more on the costs of cyberattacks

The impact of the war in Ukraine on cyberthreats

Russia’s war on Ukraine has influenced the cyber sphere in many ways. Cyber operations are used alongside traditional military action. According to Enisa, actors sponsored by the Russian state have carried out cyber operations against entities and organisations in Ukraine and in countries that support it.

Hacktivist (hacking for politically or socially motivated purposes) activity has also increased, with many conducting attacks to support their chosen side of the conflict.

Disinformation was a tool in cyberwarfare before the invasion started and both sides are using it. Russian disinformation has focused on finding justifications for the invasion, while Ukraine has used disinformation to motivate troops. Deepfakes with Russian and Ukrainian leaders expressing views supporting the other side of the conflict were also used.

Cybercriminals tried to extort money from people wanting to support Ukraine via fake charities

Cybercrime and cybersecurity

  • (open in a new tab) Enisa: Cybersecurity Threats Fast-Forward 2030
  • (open in a new tab) Europol: cybercrime
Cybersecurity: main and emerging threats  | Topics | European Parliament (2024)

FAQs

What are emerging threats in cyber security? ›

In the realm of cybersecurity, emerging threats refer to new tactics, techniques, and procedures (TTPs) that cybercriminals employ to exploit, disrupt, or breach security systems. These threats constantly evolve, making them harder to predict and mitigate.

What are the top 5 major threats to cybersecurity? ›

Social engineering, third-party exposure, cloud vulnerabilities, ransomware, and IoT are the top threats that organizations should focus on to protect their data, systems, and reputations. These threats can cause organizations to incur significant damage or loss if not addressed properly.

What are the top 5 emerging cyber security challenges? ›

What are the top 5 emerging cyber security challenges?
  • Ransomware resurgence. ...
  • IoT insecurity is affecting people worldwide. ...
  • Supply chain vulnerabilities. ...
  • AI-powered threats getting smarter. ...
  • Identity and access management protection.
May 7, 2024

What are the top cybersecurity threats for 2024? ›

A new report is predicting the top cybersecurity threats for 2024, noting the year could see an evolution in phishing strategies, a focus on the software supply chain and an exploitation of more widely used enterprise software like MOVEit.

What are the 7 types of cyber security threats? ›

Know the types of cyber threats
  • Removable media such as flash drives.
  • Brute force attack using trial and error to decode encrypted data.
  • Web or email attacks.
  • Unauthorized use of your organization's system privileges.
  • Loss or theft of devices containing confidential information.

What are the main types of security threats? ›

  • Malware Attacks. Malware, short for malicious software, takes various forms, including viruses, worms, Trojans, and ransomware. ...
  • Phishing and Social Engineering. ...
  • Data Breaches. ...
  • Denial of Service (DoS) Attacks. ...
  • Man-in-the-Middle (MitM) Attacks. ...
  • Insider Threats. ...
  • IoT Vulnerabilities. ...
  • Password Attacks.
Apr 22, 2023

What is the #1 cybersecurity threat today? ›

Malware, Phishing, and Ransomware.

What is the biggest weakness in cyber security? ›

Top Cybersecurity Vulnerabilities
  • Zero-Day Vulnerabilities. ...
  • Unpatched Software. ...
  • Application Misconfiguration. ...
  • Remote Code Execution. ...
  • Credential Theft. ...
  • Security-Based Software. ...
  • Wi-Fi Security. ...
  • Firewalls.
Jan 22, 2024

What are the 8 common cyber threats? ›

Inside the Top Cyber Threats
  • Ransomware. Ransomware is malware designed to use encryption to force the target of the attack to pay a ransom demand. ...
  • Malware. ...
  • Fileless Attacks. ...
  • Phishing. ...
  • Man-in-the-Middle (MitM) Attack. ...
  • Malicious Apps. ...
  • Denial of Service Attack. ...
  • Zero-Day Exploit.

What are the 5 C's of cyber security? ›

This article discusses and explains the 5 C's of cybersecurity—Change, Continuity, Cost, Compliance, and Coverage—highlighting their importance in modern-day digital defense mechanisms.

What is the latest growing cyber security threat? ›

Ransomware. In 2023, the ransomware trend continued, and we anticipate the future of cybersecurity holds much of the same. As the number of threat actors in this realm increases, we've also seen notable increases in the frequency, scope, and volume of ransomware attacks.

What are the emerging trends in cyber security? ›

Trend 1: Increased Focus on AI and Machine Learning in Cybersecurity. In 2024, AI and Machine Learning (ML) are set to play a more critical role in cybersecurity. AI's advanced data analysis capabilities are increasingly used for identifying and predicting cyber threats, enhancing early detection systems.

What are the top 3 cyber security threats? ›

Top 10 Cybersecurity Threats:
  • Social Engineering.
  • Third-Party Exposure.
  • Configuration Mistakes.
  • Poor Cyber Hygiene.
  • Cloud Vulnerabilities.
  • Mobile Device Vulnerabilities.
  • Internet of Things.
  • Ransomware.
Jan 4, 2024

What are next generation cyber threats? ›

In the next 8 to 15 years, quantum computing will threaten our security system based on the applied public key encryption algorithms. Quantum computers can potentially undermine the whole security system, the economy, communications, transportation, banking, energy, and other critical systems.

What is emerging technology in cyber security? ›

The latest technologies in cybersecurity include Artificial Intelligence (AI) and Machine Learning (ML), Behavioral Biometrics, Zero Trust Architecture, Blockchain, Quantum Computing, Cloud Security, and IoT Security.

What are the security threats in emerging technologies? ›

Cybercriminals can exploit AI to spread misinformation. Currently, they are creating deepfakes and use automated phishing attacks. Maintaining vigilance is crucial as AI-driven threats are evolving in sophistication.

Top Articles
Latest Posts
Article information

Author: Carlyn Walter

Last Updated:

Views: 6536

Rating: 5 / 5 (70 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Carlyn Walter

Birthday: 1996-01-03

Address: Suite 452 40815 Denyse Extensions, Sengermouth, OR 42374

Phone: +8501809515404

Job: Manufacturing Technician

Hobby: Table tennis, Archery, Vacation, Metal detecting, Yo-yoing, Crocheting, Creative writing

Introduction: My name is Carlyn Walter, I am a lively, glamorous, healthy, clean, powerful, calm, combative person who loves writing and wants to share my knowledge and understanding with you.