Major European Cyber Incidents in 2025 and What to Learn from Them

Europe has seen a series of high-profile security incidents this year. The data is clear: phishing is the most common entry vector; DDoS dominates by volume; but ransomware continues to cause the biggest business damage. 

October is Cybersecurity Awareness Month — a good moment to look at the facts. ENISA’s ETL 2025 (ENISA Threat Landscape) analyses nearly 4,900 curated incidents from July 1, 2024 to June 30, 2025. 

Hacktivist DDoS makes up 76.7% of all records, while ransomware and credential abuse remain the primary business-impact drivers. Phishing is the leading initial vector (~60%), followed by vulnerability exploitation (21.3%).

Where are hackers aiming? The top five sectors are: public administration (38.2%), transportation (7.5%), digital infrastructure and services (4.8%), finance (4.5%), and manufacturing (2.9%). A growing component of attacks is AI and large language models: up to 80% of social-engineering campaigns (phishing, vishing, etc.) now leverage AI support. 

The report shows that isolated breaches have given way to a constant, convergent pressure that erodes collective resilience. The practical response for companies is not only prevention, but demonstrable protection and recoverability. Below are incidents that resonated across the EU this year. 

European Airports Brought to a Standstill

An outage of the MUSE/​Collins Aerospace check-in platform forced baggage check-in into manual mode across multiple European airports — a textbook case of vendor concentration risk (many organisations depending on a single supplier or system). What happened? 

Letiště Heathrow

Shortly before midnight on Friday, September 19, 2025, Collins Aerospace detected unusual activity on the MUSE platform. On Saturday, September 20, ransomware began encrypting key databases, taking automated check-in systems offline at numerous airports. Operations switched to manual processing and passenger throughput fell by roughly half, triggering severe delays and cancellations. Problems continued into Sunday, September 21. On Monday, September 22, ENISA confirmed ransomware as the cause of the outage.

Takeaway for every business: map third-party dependencies thoroughly. Prepare a reduced-operations plan (what can run offline and for how long) and maintain a tested disaster recovery runbook. Require key suppliers to regularly attest to RTO/RPO and DR test outcomes — and rehearse your own fallback on a routine basis. 

Nearly One Million People Put at Risk

Orange Belgium confirmed that a breach in late July exposed data from 850,000 customer accounts. Attackers obtained names and phone numbers as well as SIM identifiers and PUK codes — a combination that significantly raises the risk of targeted phishing and fraud. The company stressed that passwords, emails, and payment data were not affected; however, experts warn that linking names to numbers and SIM identifiers enables highly convincing attacks against users. The incident became public on August 21, 2025. 

In response, the operator strengthened verification on support lines (secret challenge questions) and now requires ID checks in stores. Customers were advised to be extra vigilant against scam messages and to rotate strong passwords regularly; Orange said it had seen no evidence of data misuse or service disruption. Even so, the case highlights a structural vulnerability in telecoms: without any “critical” data, leakage of SIM- and identity-adjacent metadata can still power targeted fraud, social engineering, and potential account-takeover attempts. 

The Czech Republic Mirrors the Trend

The domestic picture matches Europe: throughout 2025, waves of DDoS (notably from pro-Russian hacktivists) alternated with individual ransomware cases impacting healthcare (hospitals switching to “paper mode” and restoring from backups) and public administration (agencies and emergency services experiencing partial outages). The Czech NCSC (NÚKIB) consistently reports that availability attacks are the most numerous, while the most painful impacts come from intrusions and encryption — reinforcing the point that verified backups and fast, reliable recovery are critical. 

“I Back Up” ≠ “I Can Restore”

A green checkbox in your backup console doesn’t guarantee you can actually bring the business back. In practice, teams often hit silent data corruption, inconsistent application snapshots, or retention policies that don’t match business reality. The right approach is to define RTO/RPO and continuously prove you can run key services in a degraded mode and in a full recovery. 

With Veeam, you can raise assurance using SureBackup, which validates recoverability by booting backups in an isolated Virtual Lab (no impact on production) and running automated checks. In practice this means: 

  • Boot from backup: VMs start directly from compressed/​deduplicated backups via vPower NFS (read-only).
  • Automated tests: heartbeat, ping, and application checks against live services (optionally malware/​YARA scans).
  • Integrity control: optional CRC validation of backup files after tests.
  • Reporting: a run report with status (including a “0 errors” outcome) suitable for audit/​NIS2 evidence.

For end-to-end validation you define an Application Group (dependencies) and a Virtual Lab (isolated network). Tests then run as a scheduled SureBackup job. Goal: not just a green checkbox, but proof that specific services will actually start — and users can log in. 

The Proven Baseline

The golden 3 – 2‑1 – 1‑0 backup rule is worth keeping in mind at all times (we’ve written about it before). Beyond that, don’t forget regular employee training — one careless click can become an attack vector. Want peace of mind and assured business continuity? Our experts will make sure your backups are secure, routinely verified, and that recovery follows a clear plan — fast and reliably. 

Glossary

RTO (Recovery Time Objective) – “speed of recovery”
The maximum acceptable time a service can be down. It dictates how quickly you must restore critical systems after an incident to avoid unacceptable loss of revenue or reputation. 

RPO (Recovery Point Objective) – “tolerance for data loss”
How much data (in time) you can afford to lose between the last backup and the incident. It drives the frequency of backups and replication — the smaller the RPO, the more frequent the backups and the higher the infrastructure demands. 

DR runbook (Disaster Recovery runbook)
A practical recovery playbook — who does what, in what order, and with which privileges. Includes contacts, decision matrices, DNS/VPN/ACL procedures, application start-up ordering, and criteria for “back to production.” Goal: fast, repeatable, auditable recovery, not improvisation. 

Phishing
Fraudulent emails/​websites impersonating a trusted service, luring victims to log in, pay, or download malware. The most common initial attack vector. 

Vishing (voice phishing)
Fraudulent phone calls (e.g., “bank/​IT support/​police”) aiming to extract codes and passwords or to trick victims into installing malicious software.

Smishing (SMS phishing)
Fraudulent SMS with a link to a fake site (“parcel,” “invoice,” “security alert”) harvesting credentials or payment details.

29. 10. 2025