TLDRocket
Sign in

Cyberattacks: These Are the 10 Hardest-Hit Countries

Trending Topics Jakob Steinschaden

Microsoft says the US got 25.5% of attacks it saw, with Israel and Ukraine next. AI is speeding up hacks, and ransomware is surging hardest in Europe.

Based on reporting by Trending Topics, Jakob Steinschaden — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Microsoft’s latest Digital Defense Report points to a blunt pattern: the places under military and geopolitical pressure are also the places getting hit hardest online. In the first half of 2026, the United States accounted for 25.5% of all attacks Microsoft observed on customers by country. Israel came next at 7.6%, Ukraine at 4.8%, and Taiwan at 3.9%. Germany was the only EU country in the top 10, at No. 10 with 1.7%.

The ranking reads less like a random list of big targets and more like a map of active conflict and strategic rivalry. Microsoft says Ukraine and NATO countries remain key targets for Russian attackers, while Chinese state-backed groups focus on the Indo-Pacific, the United States and strategic technology hubs. Taiwan has already been hit by a campaign using AI agents, uncovered by the Israeli-Austrian cybersecurity company Dream. And beyond the headline countries, Microsoft says cybercrime is rising in Latin America, Africa and Southeast Asia, where digital adoption is moving faster than defenses.

Ransomware is becoming especially ugly in Europe. Microsoft says cases in Germany jumped from 59 to 222 year over year, a 276 percent increase. Italy nearly tripled, Switzerland more than doubled, and the United States still led the pack with 1,087 cases. Israel saw a 21 percent rise. Microsoft also names Qilin and Akira as the most active ransomware families, and says Qilin’s operators let affiliates keep 80 to 85 percent of ransom payments.

The bigger shift, though, is artificial intelligence. Microsoft says attackers are using it to move faster and at larger scale, while defenders use it to spot threats sooner. But AI is also becoming a target: Microsoft found a malicious browser extension with more than 600,000 installs that stole conversation histories from ChatGPT and DeepSeek and affected nearly 10,000 organizations. Microsoft says data was stolen in 63 percent of intrusions, cloud workloads were attacked after an average of 5.3 hours, and it detected more than 46 million business impersonation attacks over the past 12 months.

My take — AI-written commentary, not fact-checked reporting

This is what happens when cybercrime meets geopolitics and gets a software upgrade. The loudest promise around AI is still being sold by people who act surprised when the same tools speed up the attack side first. Passkeys and phishing-resistant MFA are not glamorous, but they’re a lot less embarrassing than learning about security from a ransomware bill.

Read more about this at: Trending Topics

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.