Cyberattacks: These Are the 10 Hardest-Hit Countries
Trending Topics Jakob Steinschaden
Microsoft says the US got 25.5% of attacks it saw, with Israel and Ukraine next. AI is speeding up hacks, and ransomware is surging hardest in Europe.
Based on reporting by Trending Topics, Jakob Steinschaden — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Microsoft’s latest Digital Defense Report points to a blunt pattern: the places under military and geopolitical pressure are also the places getting hit hardest online. In the first half of 2026, the United States accounted for 25.5% of all attacks Microsoft observed on customers by country. Israel came next at 7.6%, Ukraine at 4.8%, and Taiwan at 3.9%. Germany was the only EU country in the top 10, at No. 10 with 1.7%.
The ranking reads less like a random list of big targets and more like a map of active conflict and strategic rivalry. Microsoft says Ukraine and NATO countries remain key targets for Russian attackers, while Chinese state-backed groups focus on the Indo-Pacific, the United States and strategic technology hubs. Taiwan has already been hit by a campaign using AI agents, uncovered by the Israeli-Austrian cybersecurity company Dream. And beyond the headline countries, Microsoft says cybercrime is rising in Latin America, Africa and Southeast Asia, where digital adoption is moving faster than defenses.
Ransomware is becoming especially ugly in Europe. Microsoft says cases in Germany jumped from 59 to 222 year over year, a 276 percent increase. Italy nearly tripled, Switzerland more than doubled, and the United States still led the pack with 1,087 cases. Israel saw a 21 percent rise. Microsoft also names Qilin and Akira as the most active ransomware families, and says Qilin’s operators let affiliates keep 80 to 85 percent of ransom payments.
The bigger shift, though, is artificial intelligence. Microsoft says attackers are using it to move faster and at larger scale, while defenders use it to spot threats sooner. But AI is also becoming a target: Microsoft found a malicious browser extension with more than 600,000 installs that stole conversation histories from ChatGPT and DeepSeek and affected nearly 10,000 organizations. Microsoft says data was stolen in 63 percent of intrusions, cloud workloads were attacked after an average of 5.3 hours, and it detected more than 46 million business impersonation attacks over the past 12 months.
My take — AI-written commentary, not fact-checked reporting
This is what happens when cybercrime meets geopolitics and gets a software upgrade. The loudest promise around AI is still being sold by people who act surprised when the same tools speed up the attack side first. Passkeys and phishing-resistant MFA are not glamorous, but they’re a lot less embarrassing than learning about security from a ransomware bill.
Read more about this at: Trending Topics