The European Court of Auditors found that the EU is insufficiently prepared to detect and respond to major cyberattacks, despite allocating €1.4 billion to European cyber defence. An EU early-warning capability remained not fully operational roughly 20 months after its creation, while auditors also identified weak oversight of funding distributed to third parties and called for stronger coordination and less duplicated work.
The audit identified inadequate information-sharing among member states as a central weakness. Following a September 2025 attack on an IT service provider that disrupted passenger handling at multiple European airports, Germany, Belgium and Ireland reportedly did not notify ENISA or other member states adequately, limiting coordinated defensive action; national-security interests and secrecy rules can further restrict cross-border exchange of cyber-threat information.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
A large cyberattack against an IT service provider disrupted passenger handling at airports including London, Brussels and Dublin, forcing airlines to conduct parts of check-in manually or with external equipment.
The European Court of Auditors found the EU insufficiently prepared to detect and respond to major cyberattacks, citing inadequate information sharing among member states. Auditors also found that the EU early-warning system was not fully operational roughly 20 months after its creation and identified oversight deficiencies in distributing cyber-defence funding to third parties.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.