close
close
Your Network of Tomorrow
Your Network of Tomorrow
Plan your path toward a faster, more secure, and more resilient network designed for the applications and users that you support.
          Experience Netskope
          Get Hands-on With the Netskope Platform
          Here's your chance to experience the Netskope One single-cloud platform first-hand. Sign up for self-paced, hands-on labs, join us for monthly live product demos, take a free test drive of Netskope Private Access, or join us for a live, instructor-led workshops.
            A Leader in SSE. Now a Leader in Single-Vendor SASE.
            A Leader in SSE. Now a Leader in Single-Vendor SASE.
            Netskope debuts as a Leader in the Gartner® Magic Quadrant™ for Single-Vendor SASE
              Securing Generative AI for Dummies
              Securing Generative AI for Dummies
              Learn how your organization can balance the innovative potential of generative AI with robust data security practices.
                Modern data loss prevention (DLP) for Dummies eBook
                Modern Data Loss Prevention (DLP) for Dummies
                Get tips and tricks for transitioning to a cloud-delivered DLP.
                  Modern SD-WAN for SASE Dummies Book
                  Modern SD-WAN for SASE Dummies
                  Stop playing catch up with your networking architecture
                    Understanding where the risk lies
                    Advanced Analytics transforms the way security operations teams apply data-driven insights to implement better policies. With Advanced Analytics, you can identify trends, zero in on areas of concern and use the data to take action.
                        The 6 Most Compelling Use Cases for Complete Legacy VPN Replacement
                        The 6 Most Compelling Use Cases for Complete Legacy VPN Replacement
                        Netskope One Private Access is the only solution that allows you to retire your VPN for good.
                          Colgate-Palmolive Safeguards its "Intellectual Property” with Smart and Adaptable Data Protection
                          Colgate-Palmolive Safeguards its "Intellectual Property” with Smart and Adaptable Data Protection
                            Netskope GovCloud
                            Netskope achieves FedRAMP High Authorization
                            Choose Netskope GovCloud to accelerate your agency’s transformation.
                              Let's Do Great Things Together
                              Netskope’s partner-centric go-to-market strategy enables our partners to maximize their growth and profitability while transforming enterprise security.
                                Netskope solutions
                                Netskope Cloud Exchange
                                Netskope Cloud Exchange (CE) provides customers with powerful integration tools to leverage investments across their security posture.
                                  Netskope Technical Support
                                  Netskope Technical Support
                                  Our qualified support engineers are located worldwide and have diverse backgrounds in cloud security, networking, virtualization, content delivery, and software development, ensuring timely and quality technical assistance
                                    Netskope video
                                    Netskope Training
                                    Netskope training will help you become a cloud security expert. We are here to help you secure your digital transformation journey and make the most of your cloud, web, and private applications.
                                      Netskope Threat Labs Report:

                                      Europe 2025

                                      The 2025 Netskope Threat Labs Europe report details malware distribution via cloud applications, the increasing adoption of generative AI, and trends in data policy violations observed over the last year.
                                      Netskope Threat Labs Report
                                      10 min read

                                      In this report link link

                                      The evolving cybersecurity landscape presents significant challenges for organizations where cloud application adoption increases and generative AI (genAI) becomes more embedded in daily operations. This report analyzes recent trends in malware distribution, data policy violations, and the utilization of genAI applications across European organizations.

                                      Malware distribution: Cloud apps continue to be a channel for malware delivery, with 16% of European organizations seeing malware downloads from GitHub, an example that highlights growing threats in trusted developer platforms.

                                      Phishing: In Europe, phishing scams often pretend to be well-known cloud apps. Adobe is the most frequently impersonated app brand, followed closely by Microsoft.

                                      Data policy violations: In Europe, the primary concern for data security is the misuse of regulated data. Regulated data, source code, and intellectual property are the sensitive data types most frequently uploaded to personal cloud applications, generative AI tools, and other unapproved platforms.

                                      GenAI usage: 91% of organizations use genAI apps directly, with 97% using apps that incorporate genAI features and 96% using apps that leverage user data for training. Organizations are responding to the resulting sensitive data exposure risk by increasing their adoption of DLP.

                                       

                                      test answer

                                      Malware downloads link link

                                      Malware distribution via cloud apps

                                      Attackers often strategically choose where to host their malware, making the hosting part of a broader effort to trick users through social engineering. They tend to use platforms that people already trust, especially widely used cloud apps, because that trust makes it more likely that someone will open a malicious file. While attackers host malware through hundreds of different apps, the chart below focuses on the four most common ones, based on how many organizations in Europe downloaded malicious content.

                                      This year, GitHub tops the list, with 16% of organizations in the European region seeing malware downloads from the platform each month. That’s a noticeable shift from last year, when Microsoft OneDrive was the most used service for delivering malware. GitHub’s rise is likely tied to its popularity among developers and its role in hosting red teaming tools, some used legitimately, others abused by threat actors.

                                      Right behind GitHub are OneDrive, Google Drive, and Amazon S3. These are some of the most common enterprise cloud storage services, making them appealing targets for attackers. All of these providers work to detect and take down malicious files quickly, so the ‘success’ of a specific malware is usually determined by how fast the content gets removed versus how quickly it spreads.

                                      Netskope Threat Labs Report - Europe 2025 - Top apps for malware in Europe

                                       

                                      Phishing link link

                                      Cloud app phishing

                                      Phishing takes a few common forms: attackers might set up a fake login page that closely mimics a real one, use a reverse proxy to intercept credentials, or build a fake application to trick users into granting access. Despite most companies requiring employees to complete security awareness training, phishing attacks are increasing. A major driver behind this rise is the increase in critical business data that now lives within SaaS applications, and the fact that access to these tools depends almost entirely on credentials, session cookies, OAuth grants, or access tokens. This shift has made phishing a go-to method for attackers looking to get past security controls and access sensitive environments. Users are now constantly dealing with phishing attempts, which have become so common and credible that even careful people can make mistakes.

                                      Among cloud apps in the European region, Adobe is the most commonly impersonated brand, appearing in 29% of cloud phishing campaigns aimed at stealing credentials for other services. Microsoft follows at 26%, with phishing efforts focusing on direct access to Microsoft 365 accounts.

                                      Netskope Threat Labs Report - Europe 2025 - Top cloud phishing targets by links clicked in Europe

                                       

                                      Data policy violations link link

                                      Data policy violations in cloud apps

                                      In Europe, the most common type of data policy breach happens when people upload regulated information to websites or cloud services that their company hasn’t approved. Regulated data accounted for 57% of all policy violations in Europe, while another 17% involved data such as passwords and auth secrets. These data policy violation trends highlight the need for stronger data protection measures and better employee education around the dangers of uploading sensitive data to unapproved locations.

                                      Netskope Threat Labs Report - Europe 2025 - Type of data policy violations in Europe

                                      When we look more closely at personal apps, the overall pattern of data policy violations remains largely the same, with regulated data still making up the largest portion. However, what stands out is the relatively higher rate of individuals uploading intellectual property to these personal cloud apps, which now represents 26% of all violations. This shift highlights a growing trend where commercially sensitive business information is being placed in unapproved locations.

                                      Netskope Threat Labs Report - Europe 2025 - Data policy violations for personal apps in Europe

                                       

                                      GenAI usage link link

                                      GenAI organizational adoption and usage trends

                                      GenAI is now widely used across Europe, with 91% of organizations integrating cloud-based genAI tools into their operations. Most organizations (97%) work with tools that include genAI-powered features and 96% use applications that rely on user data for training. Usage rates in the region are closely aligned with global levels, where 94% of organizations have adopted genAI apps in the cloud.

                                      Meanwhile, the use of personal genAI accounts has dropped noticeably over the past year, falling from 73% to 58%. This decline points to a clear shift toward company-approved genAI solutions that offer more control and better protection for sensitive data. As more businesses move in this direction, European organizations need to keep focusing on secure, enterprise-grade platforms that support innovation while maintaining compliance and reducing risk.

                                      Netskope Threat Labs Report - Europe 2025 - GenAI usage personal vs. organization account breakdown in Europe

                                      Most used GenAI apps

                                      The top 10 genAI apps used by European organizations are similar to global trends, with the following highlights:

                                      • ChatGPT is by far the most widely used genAI app in Europe, in use in 79% of organizations.
                                      • Google Gemini is steadily gaining traction as a leading alternative to ChatGPT.

                                      The remainder of the top 10 is a range of domain-specific and embedded AI tools.

                                      Netskope Threat Labs Report - Europe 2025 - Most popular genAI apps based on the percentage of orgs using those apps in Europe

                                      The chart below shows how the popularity of these same 10 apps has shifted over the past year, highlighting how quickly the genAI apps are evolving. Google Gemini’s usage has nearly doubled in 12 months with steady adoption growth.

                                      Netskope Threat Labs Report - Europe 2025 - Most popular apps by percentage of organizations in Europe

                                      GenAI app usage and data policy violations

                                      With genAI apps now widely adopted across Europe and the world, many organizations are turning to data loss prevention (DLP) tools to help manage the growing security risks tied to their use. A significant amount of the sensitive data being shared with genAI platforms includes source code, regulated information, and intellectual property. Indeed, more than a third of the data policy violations for genAI apps in Europe relate to specifically regulated data (data protected by the GDPR and other privacy rules), demonstrating the scale of the data protection risk of AI usage within the region. Organizations risk significant financial repercussions if found to be negligent in managing and handling these types of data.

                                      The high volume of source code exposure isn’t limited to Europe, it mirrors what’s being seen across global organizations. While genAI tools, especially in day-to-day developer workflows, are driving innovation and efficiency, they are also opening up new paths for potential data exposure. To move forward safely, European organizations need to find the right balance between embracing genAI’s benefits and enforcing strong data governance to protect sensitive information.

                                      Netskope Threat Labs Report - Europe 2025 - Type of data policy violations for genAI apps in Europe

                                      Shadow AI

                                      Even when it comes to personal genAI apps, employees are still actively engaging with them, often in ways that carry real data security risks for their employer. Source code stands out as the most commonly exposed type of sensitive information being shared. This pattern suggests that developers, in particular, are turning to these tools to speed up their work, even if it means using unapproved platforms outside the company’s control. It underscores the need for organizations to set clear boundaries and visibility around how genAI tools are being used even when they are not managed by the company.

                                      Netskope Threat Labs Report - Europe 2025 - Type of data policy violations for personal genAI apps in Europe

                                      Rising DLP adoption

                                      A growing number of organizations across Europe are putting DLP policies in place to mitigate the data risks that come with the use of genAI apps. Over the past year, the number of organizations using DLP to monitor and control genAI usage has increased from 26% to 43%. It is a clear sign that businesses are becoming more aware of the risks tied to unmonitored use of these tools and are taking action to protect sensitive information. By rolling out DLP controls, they’re not just reacting; they are getting ahead of a growing problem.

                                      Netskope Threat Labs Report - Europe 2025 - Percentage of orgnizations using DLP to control genAI app access in Europe

                                      Most blocked genAI apps

                                      Organizations may block different genAI apps depending on their specific policies, but some tools keep showing up with high block rates across the board. If any apps in the top 10 list below show up in your environment, it is a good reason to take a closer look. It is also a good time to review how you are handling entire categories of genAI apps, not just individual ones. In the European region, Stable Diffusion stands out as the most commonly blocked genAI app, often flagged because of concerns around privacy or licensing issues. Other apps on the list, including AIchatting, notebookLM, Writesonic, and Grok AI, are also frequently blocked, typically in favor of more secure or better-aligned alternatives. As a comparison, ChatGPT is blocked by 9.8% of organizations, and Gemini is blocked by 9.2%.

                                      Netskope Threat Labs Report - Europe 2025 - Most blocked AI apps by percentage of organizations enacting a blanket ban on the apps in Europe

                                       

                                      Recommendations link link

                                      With the growing use of generative AI tools (both sanctioned and personal), alongside the rise in phishing tactics, misuse of personal cloud apps, strengthening visibility, refining policies, and prioritizing proactive defenses will be key to staying protected in this fast-changing threat landscape.

                                      Based on the trends uncovered in this report, Netskope Threat Labs strongly encourages organizations across Europe to take a fresh look at their overall security posture:

                                      • Inspect all HTTP and HTTPS downloads, including all web and cloud traffic, to prevent malware from infiltrating your network. Netskope customers can configure their Netskope NG-SWG with a Threat Protection policy that applies to downloads from all categories and applies to all file types.
                                      • Block access to apps that do not serve any legitimate business purpose or that pose a disproportionate risk to the organization. A good starting point is a policy to allow reputable apps currently in use while blocking all others.
                                      • Use DLP policies to detect potentially sensitive information, including source code, regulated data, passwords and keys, intellectual property, and encrypted data, being sent to personal app instances, genAI apps, or other unauthorized locations.
                                      • Use Remote Browser Isolation (RBI) technology to provide additional protection when there is a need to visit websites that fall into categories that can present higher risk, like newly observed and newly registered domains.

                                       

                                      Netskope Threat Labs link link

                                      Staffed by the industry’s foremost cloud threat and malware researchers, Netskope Threat Labs discovers, analyzes, and designs defenses against the latest cloud threats affecting enterprises. Our researchers are regular presenters and volunteers at top security conferences, including DefCon, BlackHat, and RSA.

                                       

                                      About This Report link link

                                      Netskope provides threat protection to millions of users worldwide. Information presented in this report is based on anonymized usage data collected by the Netskope One platform relating to a subset of Netskope customers with prior authorization.

                                      The statistics in this report are based on the period from March 1, 2024, through March 31, 2025. Stats reflect attacker tactics, user behavior, and organization policy.

                                      Threat Labs Reports

                                      In the monthly Netskope Threat Labs Report, you will find the top 5 malicious domains, malware, and apps that the Netskope Security Cloud platform blocked plus recent publications and a threat roundup.

                                      Threat labs

                                      Accelerate your cloud, data, AI, and network security program with Netskope