Israel News
Microsoft Report: Nearly 40% of Iranian Cyberattacks Target Israel
Microsoft’s global digital defense report finds that Israel ranks second worldwide, after the United States, in the volume of malicious cyber activity directed at it, and tops the list of targets in the Middle East and Africa.
(Illustration: Nati Shohat, Flash90)Microsoft released its annual Digital Defense Report today (Thursday). According to the report, about 40% of all Iranian cyberattacks were aimed at targets in Israel. The data shows that most attacks targeted research and academic institutions, technology companies, and transportation infrastructure.
Key findings from the report: Israel ranks second in the world, after the United States, in the volume of malicious cyber activity recorded against it. In the Middle East and Africa, Israel is at the top of the list; Iran focused most of its efforts on Israel (39%), while only 23% of its attacks targeted the United States and 9% targeted the United Arab Emirates. Next on the global list of targets are Ukraine with 4.8%, and Taiwan with 3.9%.
Iranian attackers combine destructive cyberattacks, such as data deletion and disruption of operational systems, with influence and perception campaigns on social media. There has also been an increase in ransomware attacks, with a 21% rise in ransomware incidents in Israel.
The report notes that these attacks are now also being used as a tool to create chaos and harm infrastructure, rather than solely for financial extortion. In addition, the use of artificial intelligence has become a central tool for attackers, allowing them to accelerate the pace of attacks, refine impersonation methods, and conduct influence operations on a broad scale.
Microsoft is publishing the report for the seventh year. It is based on cyberthreat activity observed between July 2025 and June 2026 through Microsoft’s global monitoring network, which processes more than 165 trillion security signals every day.
According to the company, the central message for organizations is that cyber defense can no longer rely only on blocking malware. It requires ongoing identity protection, strong authentication, rapid monitoring of unusual activity, and shortening the time between detecting a threat and responding to it.

