Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Data researcher comparing official cyber reports and statistical tables in a London observatory
Editorial illustration

Open data · 2025 edition

2025 public digital threat observatory.

Comparable facts where possible, explicit scopes everywhere. This page brings together selected official indicators without adding incompatible datasets or presenting them as IIS incident statistics.

Selected indicators

Three official viewpoints, three distinct scopes.

1 366incidents known to ANSSI in 2025
4 875incidents analysed by ENISA over its stated period
More than 500 000victims assisted through Cybermalveillance.gouv.fr in 2025
60%of observed initial-access vectors attributed to phishing by ENISA

Reading rule: Scopes and definitions differ between organisations. These values must not be added together.

ANSSI · France

Events known to the agency: 2024 and 2025.

Metric20242025Interpretation
Security events4 3863 586Reports and incidents in the stated ANSSI scope.
Reports3 0042 209Events that did not necessarily become confirmed incidents.
Incidents1 3611 366Confirmed handling category used by the publisher.

ANSSI also reports 460 possible data-leak events in 2025, with 42% confirmed after investigation. Education and research represent 34% of targeted sectors in this breakdown, followed by ministries and local government at 24%.

ENISA · European Union

Attack volume does not equal operational impact.

DDoS share77%77%
Phishing in initial access60%60%
Vulnerability exploitation in initial access21.3%21.3%
NIS2 essential entities53.7%53.7%

ENISA analysed 4,875 incidents from 1 July 2024 to 30 June 2025. Approximately 80% were associated with hacktivist activity in the published analysis, while the agency notes that only 2% of hacktivist incidents caused service disruption. Percentages must therefore be read with both denominator and consequence in mind.

ENISA · 22 September 2026

A newer EU report covers a different observation window.

The ENISA Threat Landscape 2026, published on 22 September 2026, analyses events observed from 1 January to 31 December 2025. It supplements the 2025 edition above, whose window runs from July 2024 to June 2025.

51 %Recorded cases involving DDoS
32 %Public administration among targeted sectors
73 %Essential and important entities under NIS2

Selected published values. The period overlaps the 2025 edition; the two editions do not form a directly comparable series. The 2026 NIS2 categories combine essential and important entities.

Read the ENISA 2026 publication and its full scope.

Cybermalveillance.gouv.fr · France

Assistance demand reveals the pressure felt by users.

≈ 33%of individual assistance requests related to phishing
15 000approximate individual assistance searches for fake bank advisers (+159%)
13 000approximate individual assistance searches for bank-transfer fraud (+196%)
+517%change in individual assistance searches for phone-number spoofing

Methodology

How this observatory is built and should be used.

IIS transcribed a limited set of headline indicators from the public publisher pages linked below. Values retain their publisher, period, wording and scope. No extrapolation was applied, and no incompatible count was added to another.

The machine-readable files use neutral keys for reuse. The CSV contains 20 headline rows; the JSON also preserves sector distributions. Consult the source publication before using a value in a decision, report or comparison.

Data quality and interpretation limits

Published ANSSI totals are not recalculated: reports + incidents differ from the total by 11 in 2025 and 21 in 2024. The linked source provides no reconciliation here. Cybermalveillance indicators other than the headline total concern individuals; 500,000 is an exceeded threshold, not an exact count.

Checked against the linked primary publications on 2 October 2026. CSV qualifiers distinguish an exact published value, an approximation and an exceeded threshold.

Checks before comparing or adding figures

For ANSSI 2025, the source publishes 3,586 events, 2,209 reports and 1,366 incidents. The two latter values total 3,575. This observatory retains the published values and does not invent an explanation for the difference of 11. Do not reconstruct the total by addition.

The ENISA 2025 publication also carries a version 1.3 revision notice dated 22 September 2026. The indicators here are sourced to the linked publisher summary; for detailed analysis, consult the revised report and identify the version used. Report and revision notice.

FAQ

Read the figures without overstating them.

Can these figures be added together?

No. Each organisation uses a different population, reporting route, period and definition. The figures describe separate scopes.

Are these IIS client incident statistics?

No. They are selected public indicators published by ANSSI, ENISA and Cybermalveillance.gouv.fr. IIS mission data is not included.

Why can a percentage and a count appear together?

A count describes volume in one dataset; a percentage describes a share or change within its own stated denominator. Read each metric with its scope and source.

From indicators to exposure

Public statistics provide context. A scoped assessment determines what is actually relevant to your organisation.

Scope an assessment