Ireland among five EU countries 'targeted' by Chinese text-scam group 

The Enisa Threat Landscape 2026 said cybercrime was one of the main threats across the EU, representing almost of all cyber events it identified last year. File picture

The Enisa Threat Landscape 2026 said cybercrime was one of the main threats across the EU, representing almost of all cyber events it identified last year. File picture

Ireland is one of five EU countries being “targeted” by a Chinese text-scam gang, according to the EU cyber security agency.

In addition, Ireland is ranked 11th out of 25 member states for ransomware claims, where cyber gangs disable computer systems of companies or agencies and demand payment to unlock them.

EU cyber security agency Enisa said Chinese group Smishing Triad conducts “large scale” operations in five EU member states, including Ireland, through ‘smishing’ — which is fraud conducted through text messages on mobile phones or messaging apps.

Criminals typically pretend to be a legitimate body — such as a bank, delivery company, or government agency — and encourage message recipients to click on a link and enter in personal and bank information.

The Enisa Threat Landscape 2026 said cybercrime was one of the main threats across the EU, representing almost of all cyber events it identified last year.

It said ransomware accounted for nearly half of cybercrime, or financially motivated, events.

It said Smishing Triads was one of the three most active gangs in the EU and “notably targeted” France, Ireland, Poland, Germany, and Lithuania” in 2025.

Keepnet, a London-based cybersecurity firm, estimates that Smishing Triad sends out 100,000 smishing texts every day and earned $1bn (€870m) through scams in the last three years.

Enisa said 40% of financially-motivated cybercrimes involve ransomware — involving malicious software encrypting targeted computer systems, which steal data and demand ransoms.

A ransomware attack, carried out by Russian Conti group, crippled the HSE in 2021. It cost the health service €100m to fix and the State auditor estimated €660m would be required.

Enisa said the most active ransomware operators in the EU are Qilin, SafePay, Akira, INC Ransom, and Hunters International — all of them operating in Ireland.

The report places Ireland 11th out of 25 EU member states for ransomware claims in 2025. Ireland is one of just eight EU states where all five have attacked.

Ireland scores the fourth highest in terms of attacks from SafePay group.

It said Russia and China, followed by North Korea and Iran, are most involved in state-linked cyber incidents.

It said Russian groups focus on cyberespionage campaigns against public administration, defence, and energy sectors in EU member states, while China focused on telecommunications, maritime, semiconductors, and manufacturing

The report said there were 440 detected foreign information manipulation and interference incidents in 2025.

  • Cormac O'Keefe is Security Correspondent.

More in this section

Lunchtime News

Newsletter

Get a lunch briefing straight to your inbox at noon daily. Also be the first to know with our occasional Breaking News emails.

Cookie Policy Privacy Policy Brand Safety FAQ Help Contact Us Terms and Conditions

© Examiner Echo Group Limited