Shapefin

CrowdStrike Report Highlights Escalating Ransomware and State-Sponsored Cyber Threats Across Europe

Share It:

CrowdStrike’s 2025 European Threat Landscape Report reveals that European organizations accounted for nearly 22% of global ransomware and extortion victims, placing the region second only to North America amidst a rapid escalation of cyberattacks.

The report, released at Fal.

Con Europe 2025 in Barcelona, highlights that ransomware operations are increasing in speed. CrowdStrike observed adversary groups like SCATTERED SPIDER accelerating ransomware deployment by 48%, resulting in an average attack duration of 24 hours. Adversaries operating in and targeting Europe have leveraged underground marketplaces that commoditize services such as Malware-as-a-Service, initial access brokerage, and phishing toolkits.

In parallel, state-sponsored adversaries from Russia, China, North Korea, and Iran have expanded regional targeting across various industries. This expansion reflects a growing convergence of eCrime activities with geopolitical threats.

Based on frontline intelligence from CrowdStrike Counter Adversary Operations, which tracks over 265 named adversaries, the report details several key findings. Since January 1, 2024, more than 2,100 victims across Europe have been named on extortion leak sites. The United Kingdom, Germany, France, Italy, and Spain were identified as the most targeted nations, with 92% of cases involving both file encryption and data theft. Fueling these operations, 260 initial access brokers advertised to over 1,400 European organizations.

Russian-nexus actors continued to target Ukraine, conducting credential phishing, intelligence collection, and destructive operations against government, military, energy, telecom, and utilities sectors. Concurrently, DPRK-nexus actors expanded their focus on European defense, diplomatic, and financial institutions, combining espionage with cryptocurrency theft to advance strategic interests.

Underground ecosystems in Europe continue to evolve. English- and Russian-language forums, including BreachForums—a successor to RaidForums whose administrators were linked to actors in France and the United Kingdom—remain central to Europe’s eCrime landscape. These platforms facilitate the exchange of stolen data, malware, and criminal services. Additionally, platforms like Telegram, Tox, and Jabber have enabled collaboration, recruitment, and monetization among threat actors.

Physical crime has also found digital avenues, with Violence-as-a-Service (VaaS) emerging as a threat across Europe. Threat actors utilize Telegram-based networks to coordinate physical attacks, kidnappings, and extortion linked to cryptocurrency theft. Groups associated with “The Com” ecosystem and hybrid adversaries such as RENAISSANCE SPIDER are reportedly bridging cyber and physical operations, offering payments for sabotage, arson, and targeted violence.

Chinese state-sponsored adversaries targeted industries in 11 countries, exploiting cloud infrastructure and software supply chains to steal intellectual property. Persistent campaigns focused on healthcare and biotechnology, with VIXEN PANDA identified as a significant threat to European government and defense entities.

Iranian operations have also expanded into Europe, with IRGC-linked actors intensifying phishing, hack-and-leak, and Distributed Denial-of-Service (DDoS) campaigns against the United Kingdom, Germany, and the Netherlands. HAYWIRE KITTEN claimed responsibility for a DDoS attack against a Dutch news outlet, while multiple Iran-nexus actors masqueraded as hacktivists to obscure state-sponsored espionage efforts.

Adam Meyers, head of Counter Adversary Operations at CrowdStrike, stated, “The cyber battlefield in Europe is more crowded and complex than ever. We’re seeing a dangerous convergence of criminal innovation and geopolitical ambition, with ransomware crews using enterprise-grade tools and state-backed actors exploiting global crises to disrupt, persist, and conduct espionage. In this high-stakes environment, intelligence-led defense powered by AI and guided by human expertise is the only combination designed to stop cyber threats.”

CrowdStrike, a global cybersecurity provider listed on NASDAQ as CRWD, develops a cloud-native platform designed to protect critical areas of enterprise risk, including endpoints, cloud workloads, identity, and data. The CrowdStrike Falcon platform, leveraging the CrowdStrike Security Cloud and artificial intelligence, utilizes real-time indicators of attack, threat intelligence, evolving adversary tradecraft, and enriched telemetry to deliver detections, automated protection, remediation, threat hunting, and observability of vulnerabilities.

Latest Posts