Israel is the world’s No. 1 target for hacktivist attacks — by far

Report finds Israel was the world's top target for hacktivist DDoS attacks in the first half of 2026, accounting for nearly one in six attacks globally as the Iran conflict triggered a sharp surge in activity

Israel not only remained the leading target for hacktivist attacks but widened its lead over other countries, a new report published Wednesday revealed.
Radware's threat intelligence team recorded 784 DDoS attacks against Israeli organizations during the first six months of 2026, compared with 390 against second-place Ukraine, 359 against the United States and 285 against the United Kingdom.
מתקפת סייבר מצד איראן
מתקפת סייבר מצד איראן
Israel accounted for 16.9% of all DDoS attacks claimed by geopolitical hacktivist groups
(Photo: Shutterstock)
Israel accounted for 16.9% of all DDoS attacks claimed by geopolitical hacktivist groups, up from 12.2% during the same period a year earlier. Its share of global activity rose by nearly 40%, while the gap between Israel and the second-ranked country widened significantly.
The surge was closely tied to events in the region. After months of declining attack volumes worldwide, the Israeli and U.S. campaign against Iran reversed the trend in March. Hacktivist groups claimed more than 1,300 DDoS attacks that month, roughly double the previous month's total.
Dozens of groups quickly joined campaigns targeting infrastructure in Israel, the United States and Gulf states. Alongside Iran-aligned groups, anti-Western and pro-Russian actors also took part, extending the military confrontation into cyberspace.
The hashtag #OPISRAEL appeared hundreds of times across the groups' channels during the period, with more than half of those mentions recorded in March alone. The escalation with Iran therefore did more than trigger another wave of attacks: It mobilized a broader range of actors against Israel.
For organizations, DDoS attacks can cause immediate and highly visible disruption. Attackers overwhelm websites or online services with traffic, slowing them down or taking them offline without necessarily breaching systems or stealing data.
That makes DDoS attacks an effective wartime tool. They can disrupt government websites, financial services and companies operating essential infrastructure, creating a visible sense of disruption even when the underlying damage is temporary.
Government organizations were the most heavily targeted sector, accounting for more than a third of hacktivist activity. The Middle East accounted for more than a quarter of global activity, while Radware customers in the region experienced the highest attack frequency, averaging hundreds of attacks per customer each day.
מתקפת סייבר בבית החולים
מתקפת סייבר בבית החולים
Government organizations were the most heavily targeted sector
(Photo: Shutterstock)
The attacks linked to the conflict were part of a broader increase in attempts to take digital services offline. Web DDoS attacks worldwide more than doubled compared with the first half of 2025. In the first six months of this year, Radware mitigated an attack volume equivalent to most of the activity recorded during all of 2025.
Network-layer attacks also increased sharply, with the average Radware customer facing more than 100 attacks a day. The technology sector absorbed nearly 60% of those attacks, followed by financial services.
The concentration of attacks in those sectors highlights the potential public impact of even temporary disruptions. Technology companies underpin a large share of the economy's online services, while financial institutions provide services that consumers and businesses rely on daily.
At the same time, financially motivated attacks against websites and APIs also surged. Malicious activity targeting those systems more than doubled, reaching tens of thousands of actions per application each day.
Unlike hacktivist attacks, the goal in these campaigns is generally not public disruption but account takeovers, data theft, financial fraud and other forms of exploitation.
APIs have become an increasingly important attack surface because they provide direct access to data and core system functions. When APIs are poorly documented or inadequately protected, attackers can exploit them to extract sensitive information or manipulate business processes.
More than 70% of organizations increased their use of internally developed APIs over the past year, according to Radware. Yet only a small share document all of their APIs, while many organizations document fewer than 70% of them. That leaves parts of the digital attack surface invisible to the organizations responsible for protecting them.
מתקפת סייבר מצד איראן
מתקפת סייבר מצד איראן
Alongside Iran-aligned groups, anti-Western and pro-Russian actors also took part, extending the military confrontation into cyberspace
(Photo: Shutterstock)
Artificial intelligence is adding another layer of risk by accelerating the discovery and exploitation of vulnerabilities. AI tools can scan operating systems and applications, identify relationships that traditional code reviews may miss and generate malicious code capable of exploiting vulnerabilities.
The report cites Anthropic's Claude Mythos as an example, saying it identified a decades-old vulnerability in an OpenBSD networking component and completed a 32-step network attack without human intervention.
The speed of exploitation is becoming a particular concern. Vulnerability exploitation accounted for more than 60% of attacks recorded against applications and APIs. As of July 23, Radware said attackers were exploiting newly discovered vulnerabilities an average of eight hours before their official disclosure.
More than 80% of exploited vulnerabilities were attacked before developers and security organizations were aware of them, according to the report.
"The most significant finding is not merely that Israel once again ranks first, but that the gap between it and the other countries continues to widen," said Ron Meyran, vice president of cyber intelligence at Radware.
"The digital arena has become an inseparable part of every military conflict, and the campaign against Iran demonstrated how quickly dozens of groups can mobilize and act against organizations in Israel," he said.
"An Israeli organization cannot assume it will have time to understand what is happening and only then respond. It must operate on the assumption that the next attack will begin alongside the security event — and sometimes even before the vulnerability being exploited has been disclosed."
"Protecting digital services has become part of the operational resilience of the country and its economy, and attacks must be detected and blocked in real time."
Comments
The commenter agrees to the privacy policy of Ynet News and agrees not to submit comments that violate the terms of use, including incitement, libel and expressions that exceed the accepted norms of freedom of speech.
""