Israel Ranks Second Globally in Cyberattack Exposure, Microsoft Report Finds
Translated & summarized from Calcalist by baba
The story in 5 lines · by baba
- Israel ranked second globally in cyberattack exposure in early 2026.
- Iran is a primary source of cyber activity targeting Israel.
- Ransomware attacks against Israel increased by 21% year-over-year.
- AI is transforming cyber threats, enabling larger and more sophisticated attacks.
- Microsoft's report covers data from July 2025 to June 2026.
In the first half of 2026, Israel was the second most targeted country globally for cyberattack activity, trailing only the United States, according to Microsoft's annual cybersecurity report. Israel accounted for 7.6% of measured cyber activity, compared to 25.5% for the U.S., 4.8% for Ukraine, and 3.9% for Taiwan. Within the Middle East and Africa region, Israel led in this metric. The report, based on data from July 2025 to June 2026 and Microsoft's systems processing over 165 trillion daily security signals, highlights the growing impact of artificial intelligence on cyber threats. AI enables attackers to conduct larger-scale attacks, create more convincing impersonations, and automate previously resource-intensive processes. The increasing use of AI also creates new attack surfaces, requiring organizations to secure autonomous systems' identities and permissions.
Iran is identified as a primary source of cyber activity against Israel, with Israel being the target of 39% of attacks attributed to Iranian actors. The U.S. followed with 23%, the UAE with 9%, and Egypt and India with 6% each. Microsoft noted that during periods of regional tension, Iranian-linked entities launched extensive, multi-layered campaigns against Israel and other Middle Eastern nations, while also significantly increasing activity against the U.S. and its interests. These operations increasingly blended cyberattacks, military actions, and influence operations to maximize operational and psychological impact. The report observes a trend beyond espionage and data collection towards more destructive actions, including data deletion and attacks on operational technology (OT) systems. Iranian actors are also actively seeking persistent access to research institutions, IT and communication companies, critical infrastructure, government entities, defense supply chains, NGOs, and dissident communities, for both espionage and potential future disruption.
Key targets of Iranian activity included research and academia (28%), IT (12%), transportation (11%), government (8%), and think tanks and non-profits (8%). Iranian attackers primarily exploit known security vulnerabilities, weak authentication mechanisms, and internet-exposed systems. Credential theft and phishing remain central to gaining initial access, with cloud infrastructure like Microsoft Azure being used for maintaining access and expanding operations post-breach. Microsoft also points to a convergence in tactics among Iranian attack groups, enhancing their operational scale and potential for damage.
The report also indicates a rise in ransomware attacks in Israel, with observed incidents increasing by 21% compared to the previous year, reaching 23% of affected countries, while global ransomware incidents decreased by 3%. Microsoft suggests this increase in Israel may reflect Iran's use of ransomware as part of hybrid warfare. Ransomware attacks are now characterized as part of a broader strategy involving identity theft, infrastructure infiltration, vulnerability exploitation, and organizational system takeover.
Globally, Microsoft observes an increase in the dwell time of attackers within networks before detection and continued use of previously acquired access by state actors. The company warns specifically about threats to software supply chains, attacks on edge devices like firewalls and routers, and the use of AI as a force multiplier. Addressing these trends requires stronger identity protection, multi-factor authentication, anomaly monitoring, and faster intrusion detection, alongside rapid recovery capabilities, business continuity, and public-private sector collaboration.
Read the original at CalcalistMentioned
