
One in six geopolitical cyberattacks worldwide targeted Israel in first half of 2026
Israel recorded more than twice as many hacktivist DDoS attacks as Ukraine, with the conflict with Iran helping mobilize roughly 60 groups against Israel, the U.S. and Gulf states.
Israel was the target of nearly one in every six DDoS attacks claimed by geopolitical hacktivist groups worldwide during the first half of 2026, widening its lead over other countries as the conflict with Iran drew dozens of additional actors into the digital battlefield, according to a new report by Israeli cybersecurity company Radware.
The attacks are increasingly becoming a visible extension of geopolitical conflicts. Radware recorded 784 attacks against organizations in Israel during the first six months of the year, more than twice the 390 recorded against Ukraine, which ranked second. The United States followed with 359 attacks and the United Kingdom with 285.
Israel accounted for 16.9% of all DDoS attacks claimed by hacktivist groups during the period, up from 12.2% in 2025. Its share of global activity therefore increased by 38.5%, while the gap between Israel and the second-ranked country widened from 2.8 percentage points to 8.5 percentage points.
The escalation with Iran appears to have been a major catalyst. After months in which attack volumes were declining worldwide, the Israeli and U.S. campaign against Iran triggered a sharp reversal in March. The number of DDoS attacks claimed by hacktivist groups jumped 103.1% that month to 1,308 attacks.
Roughly 60 groups quickly joined campaigns targeting infrastructure in Israel, the United States and Gulf states. The attackers included Iran-aligned groups as well as anti-Western and pro-Russian actors, bringing a broader collection of politically motivated hackers into the conflict.
The online campaign was also reflected in the activity of the groups themselves. The hashtag #OPISRAEL appeared 469 times across their channels during the period, with more than 250 mentions recorded in March alone.
For the organizations on the receiving end, DDoS attacks are less about stealing information than making services unavailable. Attackers overwhelm websites or online services with traffic until they slow down or stop functioning, without necessarily penetrating the underlying systems.
That makes the attacks particularly suited to wartime campaigns. Disrupting a government website, financial service or company providing essential services can create an immediate and highly visible sense of disruption, even when the underlying damage is temporary.
Government organizations accounted for 37.2% of hacktivist activity, making them by far the most targeted sector. The Middle East accounted for 26.1% of global activity, while Radware customers in the region experienced the highest attack frequency in the world, averaging 520 attacks per customer per day.
The surge in politically motivated attacks is part of a much broader increase in attempts to knock digital services offline. Worldwide, web DDoS attacks increased 110.6% compared with the first half of 2025 and 36.3% compared with the preceding six months. In just six months, Radware said it mitigated an attack volume equivalent to about 83% of all the activity recorded during the whole of 2025.
Network-layer attacks also increased sharply. The average Radware customer faced 110 attacks per day, 36.6% more than the average during the previous year. The technology sector accounted for 59.4% of those attacks, averaging 509 attacks per customer per day, while financial services accounted for another 20.8%.
But the threat landscape is not being shaped only by groups seeking political impact. Attacks motivated primarily by financial gain are also increasing, particularly against websites and APIs.
Malicious activity targeting websites and APIs rose 104%, exceeding 14,000 actions per application per day. The objective in these attacks is different: attackers seek to take over accounts, steal data and money, and commit fraud.
APIs are an increasingly important target because they can provide direct access to data and core system functionality, potentially bypassing some of the security layers surrounding conventional web interfaces. The problem is compounded by the difficulty organizations have in keeping track of the APIs they create internally.
More than 70% of organizations increased their use of internally developed APIs over the past year, according to the report. Yet only 6.9% document all of their APIs, while 43% document fewer than 70% of them.
That creates an attack surface that can be difficult for an organization to see but can still be discovered and exploited by attackers.
Artificial intelligence is adding another layer to the problem by accelerating how vulnerabilities can be found and exploited. According to the report, AI tools can scan operating systems and applications, identify relationships that traditional code reviews may miss and generate malicious code capable of exploiting vulnerabilities.
The report points to Anthropic's Claude Mythos as an example, saying it identified a 27-year-old vulnerability in an OpenBSD networking component and successfully completed a 32-step network attack without human intervention.
The result is a shrinking window between the discovery of a vulnerability and its exploitation. Vulnerability exploitation accounted for 62.1% of attacks recorded against applications and APIs, while as of July 23, 2026, the first attack against a vulnerability was observed an average of eight hours before its official disclosure.
More than 80% of exploited vulnerabilities were attacked before developers and security organizations knew about them, according to the report.
“The most significant finding is not merely that Israel once again ranks first, but that the gap between it and the other countries continues to widen,” said Ron Meyran, vice president of cyber intelligence at Radware.
“The digital arena has become an inseparable part of every military conflict, and the campaign against Iran demonstrated how quickly dozens of groups can mobilize and act against organizations in Israel,” Meyran said.
An Israeli organization, he added, cannot assume it will have time to understand an attack before responding. “It must operate on the assumption that the next attack will begin alongside the security event - and sometimes even before the vulnerability being exploited has been disclosed.”














