Israel Ranks Second Globally in Cyberattack Frequency, Microsoft Report Finds
Translated & summarized from Ynet by baba
The story in 5 lines · by baba
- Israel ranked second globally in cyberattack frequency in early 2026.
- Iran is a primary source of cyberattacks targeting Israel.
- Microsoft's report details global cyber threat trends and Iranian tactics.
- AI is increasingly used to accelerate and expand cyberattacks.
- Israel's defense relies on an integrated national system.
In the first half of 2026, Israel was the second most frequently targeted country worldwide for cyberattacks, experiencing 7.6% of all measured activity in this domain. The United States led with 25.5%, while Israel ranked first in the Middle East and Africa. This data comes from Microsoft's annual Digital Defense Report, which details global cyber threat landscapes. Following Israel, Ukraine was targeted with 4.8% of attacks, and Taiwan with 3.9%. The report, based on cyber threat intelligence from Microsoft's global monitoring system processing over 165 trillion security signals daily between July 2025 and June 2026, also highlights Iran as a primary source of cyberattacks against Israel, with 39% of Iranian-directed attacks aimed at the Jewish state. The U.S. was second with 23%, followed by the UAE with 9% of Iranian-directed attacks.
Iranian-affiliated threat actors have conducted extensive campaigns against Israel and other Middle Eastern nations, while significantly increasing their activity against the U.S. and American interests. These actors are intensifying their methods by integrating cyber operations with military actions and social media influence campaigns. The report notes destructive disruptions by Iran, including data deletion and attacks on operational technologies, with the aim of gaining system access for espionage and future disruption. Ransomware incidents against Israel saw a 21% increase compared to the previous year, which Microsoft views as part of a broader geopolitical cyber warfare strategy. Iranian activity continues to focus on strategically valuable sectors, with research and academic institutions being the most targeted (28%), followed by IT (12%), transportation (11%), government bodies (8%), and research institutes and NGOs (8%).
Iranian attackers primarily exploit known security vulnerabilities, weak authentication mechanisms, and internet-exposed systems for initial access, using stolen credentials and phishing attacks. Cloud infrastructure is leveraged for persistent access. Over 99% of initial cloud intrusion attempts observed involved brute-force password attacks. Microsoft also notes a consolidation of tactics among various Iranian attack groups to amplify their reach and impact. The company emphasizes that cyber defense must evolve beyond malware blocking to include continuous identity protection, strong authentication, anomaly monitoring, and rapid threat response. The increasing use of artificial intelligence is accelerating and expanding attacks, creating a new attack surface that requires specific protection for identities and permissions.
Yossi Kardi, Head of the National Cyber Directorate, commented on the report, stating that Israel's maintained operational continuity amidst such threats is a result of an integrated national defense system involving the National Cyber Directorate, security agencies, government ministries, the economy, the cyber industry, and global companies. He stressed that the cyber arena is a 24/7 battle with no ceasefire, requiring constant defense due to the lack of absolute resilience. Kardi added that AI is accelerating attack speeds and expanding their scope, and that victories are often silent, manifesting as thwarted attacks, prevented damage, and continued normalcy.
Read the original at YnetMentioned
