In the first half of 2026, Israel was the second-most frequently targeted country in the world by cyberattacks, accounting for 7.6% of all measured activity in the field. The United States ranked first with 25.5%. In the Middle East and Africa, Israel ranked first.
The figures come from Microsoft’s annual Digital Defense Report, released Thursday, which provides a global overview of cyber threats. According to Microsoft data, Israel was followed by Ukraine with 4.8% and Taiwan with 3.9%. The report, now in its seventh year, is based on cyber threat activity observed between July 2025 and June 2026 through Microsoft’s global monitoring network, which processes more than 165 trillion security signals each day.
The Iranians are not letting up
According to Microsoft threat intelligence data, Israel is also the primary target of Iranian cyberattacks, with 39% directed against it. The United States ranks second, accounting for 23% of such attacks, followed by the United Arab Emirates with 9%.
The report describes how “threat actors” linked to Iran conducted large-scale campaigns against Israel and other Middle Eastern countries while significantly expanding their activity against the United States and American interests.
To refine their destructive methods, they increased the integration of cyber operations, military activity and influence campaigns on social media.
The report cites Iranian disruption and destructive operations, including data wiping and attacks aimed at disrupting operational technologies. Microsoft continues to identify Iranian activity intended to gain access to systems, both for espionage and to enable possible future disruption.
In this context, the report also points to a 21% increase in ransomware incidents measured against Israel compared with the previous year. The company views this as part of a form of warfare that combines cyber activity with geopolitical objectives.
Iranian activity, the report says, continues to focus on sectors with intelligence and strategic value. Research and academic institutions account for 28% of the targets attacked, information technology 12%, transportation 11%, government bodies 8% and research institutes and nongovernmental organizations 8%.
The primary methods used by Iranian attackers include exploiting known security vulnerabilities, weak authentication mechanisms and internet-exposed systems to gain initial access to organizations.
The main tools are credential theft and phishing attacks, while cloud infrastructure is used to maintain long-term access to systems while waiting for the right moment to act.
More than 99% of observed initial intrusion attempts into cloud environments were based on attacks in which attackers tried commonly used passwords at random across large numbers of accounts.
Microsoft also reports that it is identifying growing convergence in the methods used by different Iranian attack groups, aimed at expanding the scale of their activity and increasing its potential impact.
According to the company, the key message for organizations is that cyber defense can no longer rely solely on blocking malware. Continuous identity protection, strong authentication, rapid monitoring of unusual activity and reducing the time between threat detection and response are now required.
The report also notes that one of the major recent trends is the use of artificial intelligence to accelerate and expand attacks. AI agents are becoming a new “attack surface,” requiring dedicated protection for identities and permissions.
Microsoft’s report stresses that a cyber incident is not necessarily limited to the first organization affected: a breach involving an internet provider, an account or a development platform can affect additional organizations across the supply chain.
National Cyber Directorate chief Brig. Gen. (res.) Yossi Karadi commented on the Microsoft report. “The fact that Israel maintains operational continuity under this scale of threats should not be taken for granted,” he said. “It is the result of an integrated national defense system in which the National Cyber Directorate operates together with the security agencies, government ministries, the economy, the cyber industry and global companies.”
“In cyber,” Karadi continued, “you may not see missiles in the air, but there is no ceasefire. The campaign is conducted 24/7, and the defense must also operate continuously, with the understanding that there is no such thing as absolute resilience.
“The growing use of artificial intelligence accelerates the pace of attacks, expands their scope and changes the nature of the campaign... The victories are often quiet, reflected in attacks that were blocked, damage that was prevented and routine that continued.”



