Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Data researcher comparing official cyber reports and statistical tables in a London observatory

Open data · 2025 edition

2025 public digital threat observatory.

Comparable facts where possible, explicit scopes everywhere. This page brings together selected official indicators without adding incompatible datasets or presenting them as IIS incident statistics.

Selected indicators

Three official viewpoints, three distinct scopes.

1 366incidents known to ANSSI in 2025
4 875incidents analysed by ENISA over its stated period
500 000victims assisted through Cybermalveillance.gouv.fr in 2025
60%of observed initial-access vectors attributed to phishing by ENISA

Reading rule: Scopes and definitions differ between organisations. These values must not be added together.

ANSSI · France

Events known to the agency: 2024 and 2025.

Metric20242025Interpretation
Security events4 3863 586Reports and incidents in the stated ANSSI scope.
Reports3 0042 209Events that did not necessarily become confirmed incidents.
Incidents1 3611 366Confirmed handling category used by the publisher.

ANSSI also reports 460 possible data-leak events in 2025, with 42% confirmed after investigation. Education and research represent 34% of targeted sectors in this breakdown, followed by ministries and local government at 24%.

ENISA · European Union

Attack volume does not equal operational impact.

DDoS share77%
Phishing in initial access60%
Vulnerability exploitation in initial access21.3%
NIS2 essential entities53.7%

ENISA analysed 4,875 incidents from 1 July 2024 to 30 June 2025. Approximately 80% were associated with hacktivist activity in the published analysis, while the agency notes that only 2% of hacktivist incidents caused service disruption. Percentages must therefore be read with both denominator and consequence in mind.

Cybermalveillance.gouv.fr · France

Assistance demand reveals the pressure felt by users.

≈ 33%of assistance requests related to phishing
15 000fake bank adviser assistance journeys (+159%)
13 000bank transfer fraud assistance journeys (+196%)
+517%change in searches related to phone-number spoofing

Methodology

How this observatory is built and should be used.

IIS transcribed a limited set of headline indicators from the public publisher pages linked below. Values retain their publisher, period, wording and scope. No extrapolation was applied, and no incompatible count was added to another.

The machine-readable files use neutral keys for reuse. The CSV contains 20 headline rows; the JSON also preserves sector distributions. Consult the source publication before using a value in a decision, report or comparison.

FAQ

Read the figures without overstating them.

Can these figures be added together?

No. Each organisation uses a different population, reporting route, period and definition. The figures describe separate scopes.

Are these IIS client incident statistics?

No. They are selected public indicators published by ANSSI, ENISA and Cybermalveillance.gouv.fr. IIS mission data is not included.

Why can a percentage and a count appear together?

A count describes volume in one dataset; a percentage describes a share or change within its own stated denominator. Read each metric with its scope and source.

From indicators to exposure

Public statistics provide context. A scoped assessment determines what is actually relevant to your organisation.

Scope an assessment