The European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA), acting through the Joint Committee of the European Supervisory Authorities (ESAs), have published their first annual report on major ICT-related incidents affecting the EU financial sector in 2025, pursuant to Article 22(2) of the Digital Operational Resilience Act (DORA). The report provides, on an anonymised and aggregated basis, the first empirical overview of the operation of the EU-wide incident-reporting framework, covering the number, nature, impact, underlying causes, remedial measures and costs associated with incidents classified as “major” under DORA.
During 2025, financial entities reported 3,383 major ICT-related incidents, equivalent to an average of 282 incidents per month and 0.18 major incidents per financial entity subject to DORA. More than three quarters of all reported incidents were concentrated in the most digitally intensive and customer-facing sectors: over 60% occurred in the credit sector, while a further 16% affected the payments sector. The ESAs caution, however, that this concentration should not automatically be regarded as evidence of lower resilience in those sectors, as it may also reflect market structure, the highly digital nature of the relevant services and the existence of incident-reporting requirements predating DORA, particularly under PSD2.
The cross-border dimension of ICT risk is particularly noteworthy. Approximately one third of major incidents — 1,056 cases — had effects extending beyond the Member State in which the incident was reported. Around 8% of all major incidents affected more than ten countries, confirming that shared infrastructure, common service providers and cross-border business models can allow operational disruptions to propagate rapidly across entities, sectors and jurisdictions.
As regards the nature of the incidents, system failures were the most frequently reported category, accounting for 51% of all major incidents, followed by external events (27%) and payment-related incidents (18%). Cybersecurity-related incidents represented approximately 10% of the total. Within the latter category, DDoS attacks accounted for 33% of the techniques reported, while data exfiltration and manipulation, including identity theft, represented 31%. The ESAs note that the relatively limited proportion of cybersecurity incidents classified as major may indicate that existing safeguards and detection mechanisms were generally effective in preventing such events from escalating, while stressing the need to maintain high cybersecurity standards in light of the evolving threat landscape and the potential use of AI-driven capabilities by threat actors.
One of the report’s most significant findings concerns third-party dependency. 29% of major incidents originated from failures attributable to third-party providers. More broadly, when other financial entities and infrastructure providers are also taken into account, the ESAs observe that almost one third of major incidents originated from failures at third parties. The report expressly calls for financial entities to further strengthen their ICT third-party risk management frameworks, noting that dependencies on providers that have not been formally designated as “critical” may nevertheless represent an area of supervisory concern and may have significant operational or systemic consequences.
In terms of impact, the findings are comparatively reassuring. In almost 60% of cases, the impact on clients was either absent or affected fewer than 1,000 customers. As regards transactions, 32% of major incidents affected no transactions at all and a further 26% affected fewer than 1,000 transactions. Only approximately 1% of incidents affected more than one million transactions. In addition, fewer than 18% of major incidents had an impact on other financial counterparties. According to the ESAs, these findings suggest that timely detection, together with effective incident response and containment measures, frequently succeeded in limiting operational harm and spillover effects.
The report also provides useful evidence regarding the remedial measures adopted in practice. During the initial response phase, financial entities generally relied on rapid technical interventions aimed at restoring service continuity. These were followed by longer-term corrective measures, including enhanced monitoring and alerting, improvements to testing and change-management processes, system configuration adjustments, correction or reconstruction of affected data and, where incidents originated from third-party providers, coordination with those providers to agree and implement additional safeguards.
The ESAs also provide a detailed analysis of two major cross-border events that materially affected the 2025 figures: the TARGET Services incident in February 2025, which rendered T2 and T2S unavailable for approximately ten and eight hours respectively, and the Iberian Peninsula blackout in April 2025. Although the latter did not generally compromise major banks’ and insurers’ data centres due to the availability of backup power generation, it caused significant disruption to branches, telecommunications and payment services. These cases demonstrate that operational resilience must be assessed not only against cyberattacks in the strict sense, but also against broader external and infrastructure-related events.
For financial entities subject to DORA, the report therefore provides a number of relevant operational indications. Organisations should reassess whether their incident-management arrangements allow for the timely detection, classification and escalation of events; review the effectiveness of business-continuity and recovery procedures; and, most importantly, strengthen the governance of ICT third-party dependencies. The 29% figure is particularly relevant in demonstrating that a financial entity’s resilience is materially dependent on the resilience of the broader technology ecosystem on which it relies.
Against this background, financial entities should consider using the report’s findings to stress-test their DORA frameworks by identifying concentration risks and single points of failure within the ICT supply chain, reviewing contractual escalation and incident-cooperation arrangements with service providers, incorporating third-party failure scenarios into resilience testing and ensuring that monitoring, change management and remediation activities generate appropriate and auditable evidence.
Finally, the ESAs emphasise that 2025 was the first year of operation of DORA’s new incident-reporting framework and that divergences in reporting practices and data-quality limitations remain. Approximately 15% of notified incidents were excluded from the analysis because no final report had been received by the 5 February 2026 cut-off date. During 2026, the ESAs intend to enhance supervisory convergence, improve reporting quality and further integrate incident data with the DORA Register of Information, including with a view to identifying major incidents originating at critical ICT third-party providers and gaining a clearer understanding of systemic ICT concentration risks across the EU financial sector.