Analysis of the difference between attempts, detected incidents, and attacks that become public. – Delia NECULA
The news about the French Ministry of Economy and Finance has already circulated widely: there, an attacker managed to access and extract taxpayer data from the systems of the Directorate General of Public Finance (DGFiP). According to information later confirmed by the French authorities, the incident affected approximately 678,000 individuals and entities.
Yes, it happens there too, not just at ANCPI in Romania. The reactions were predictable: “another attack,” “another major breach,” “Europe is under siege.” Is it? And is it only about Europe?
After multiple discussions with my colleagues and after reading dozens or hundreds of articles about cyber incidents, I believe the reaction is no longer a surprise. Cyberattacks are a daily reality. So the question I raise is: how many of them never make the news?
The detail that seems most relevant to me in the French case is not only the fact that the incident occurred, but the timeline. Unauthorized access took place at the end of June. The suspicious activity was stopped at that time, but the data extraction was not identified as such. The public only found out in August, after the attacker claimed the breach and offered the data for sale. Between the two moments, there is a window of approximately 6 weeks during which no one outside the institution knew what had happened. And this gap between compromise, detection, and communication is much more common than we like to believe: M-Trends 2026 places the global median time between compromise and detection at 14 days for 2025, but the difference by detection source is what matters – approximately 9 days when the organization discovers the incident itself, compared to 25 days when it learns about it from an external source.
Three different realities, not a single number
When someone asks “how many attacks are there, actually?”, the answer I would give is: the question is incomplete, because there are three different levels of reality and we constantly confuse them.
The first level is that of attempts: phishing, automated scans, authentication attempts, vulnerability exploitation, and social engineering. All of these happen non-stop, on a scale that no news report can reflect. Anyone who has had access to a SIEM or to the logs of a firewall exposed to the Internet knows exactly what I am talking about: the volume is absurdly large and completely invisible to anyone who does not look directly at it.
The second level is that of detected incidents. Not everything that gets past the first line is observed immediately. Sometimes the signal exists in the logs, but no one investigates it until it is too late. Other times, the organization finds out not from its own systems, but from a partner, an authority, an independent researcher, or, as in the French case, directly from the attacker, when they decide to publicly boast about it.
The third level, the smallest of all, is that of incidents that become public. This is where cases generally end up when they cause a visible disruption, affect many people, involve sensitive data, trigger a legal notification obligation, or hit a name well-known enough for the press to take an interest. Let us remember, for example, the incident that affected ANCPI’s systems and effectively blocked or delayed real estate transactions in Romania.
ENISA analyzed 4,875 incidents for the period July 2024 – June 2025. It is a useful figure, but it is not a census. The agency’s own methodology shows that the analysis is based primarily on open sources and anonymized information voluntarily provided by EU member states and ENISA partners. What is not detected, reported, or observable does not enter the statistics, no matter how official they may be.
Europe is not short of examples – the problem is that we forget them too quickly
If we look only at the last few months, the list is already long. In March, the European Commission confirmed an attack on the cloud infrastructure hosting the Europa.eu platform, with indications of data extraction. In April, France Titres, the French agency responsible for identity documents, confirmed a separate incident; the investigation even led to the questioning of a 15-year-old suspect. In June, INSEE, France’s national statistics institute, reported the compromise of identities and professional contact data for approximately 12,800 employees, former employees, and members of associated professional bodies. Also in June, Novo Nordisk announced unauthorized access to internal systems and the copying of limited data concerning clinical trial participants.
At the beginning of August, Liechtenstein temporarily shut down its beneficial ownership register following a breach in which data associated with approximately 31,000 companies, foundations, and trusts was copied. During the same period, the Cl0p group claimed to have extracted data from nearly 50 companies worldwide, including Philips, Shell, GE, and Fiserv, following the exploitation of vulnerabilities in PTC Windchill and FlexPLM products, used in engineering and manufacturing. A claim of this kind is not automatically definitive proof: the organizations involved reported different situations, and the full extent still appears to be unknown. The pattern, however, is clear: a vulnerability in a widely used product can turn a single weak point into a campaign involving dozens of victims.
What should concern us, beyond each individual case, is that there is not a single type of attacker behind them. We have traditional financial crime, espionage, hacktivism, opportunistic exploitation of vulnerabilities, and, increasingly, young groups for whom online reputation and the chaos they cause matter almost as much as money. The Financial Times describes the phenomenon of young, Western, and reckless attackers, using Scattered Spider and the ecosystem around it as examples. The attackers’ toolkit has also expanded over the past year: Google Threat Intelligence Group has documented the first malware families that call language models during execution, not just during development – PROMPTFLUX, which asks itself for obfuscation techniques to evade signature-based detection, and PROMPTSTEAL, attributed to a state actor and used in real-world operations – while 2026 reports describe the shift from experimentation to large-scale use, including for personalized social engineering and the extraction of proprietary models. The practical conclusion for any company is not to psychologically profile the attacker, but to accept that it can no longer design its defenses around a single predictable adversary.
Why some incidents become news while others remain completely buried
I have consistently observed lately that an incident’s visibility is not necessarily determined by how technically sophisticated it was, but by its external impact. An incident becomes news when it blocks payments or services, affects millions of people, exposes medical or financial data, hits a public institution, or when someone makes a spectacular claim about it, as in the case of Cl0p.
By contrast, an incident remains discreet when it is contained quickly, when it does not cause visible unavailability, when the victim is not a well-known brand, or when the affected organization itself communicates a limited impact. There is also a natural reputational reluctance: many organizations communicate strictly the legal minimum, not a word more. And sometimes the explanation is simpler and more concerning: they simply do not yet know what happened to them.
The volume of news does not measure the volume of attacks. It measures a combination of detection capabilities, impact, reporting obligations, public interest, and communication decisions.