Ukraine is third in world for cyberattacks after US and Israel, and first in Europe. Machine-speed assaults run continuously and without fatigue
Malware accounts for 33% of incidents in the first half of 2026, and system compromises for 4.5%.
In 2026, the United States and Israel were the countries most frequently targeted by cyberattacks, followed by Ukraine, which ranked third in the world and first in Europe, according to Microsoft's Digital Defense Report. Ukraine accounted for 4.8% of all victims worldwide, up from fifth place and third in Europe the previous year, the report revealed.
Microsoft processes over 165 trillion security signals daily, allowing it to track how often attackers target customers in each nation. Russian state hackers were responsible for 14% of recorded activity against Ukraine, surpassed only by the United States. The era of rapid cyberattacks driven by machine speed has arrived, with government agencies and services becoming the most frequently targeted sector at 27%, a significant increase from 17% in 2025.
Phishing attacks accounted for 23% of intrusions investigated by Microsoft, up from 7% a year earlier, and the median time to weaponize a vulnerability has dropped below 24 hours. Artificial intelligence is pushing cyberspace into a new era of "machine-speed" attacks that operate continuously and tirelessly, according to Natalia Burlakova, Security Sales and Engineering Lead at Microsoft.
The use of AI agents on behalf of users, combined with their access rights, enables machine-scale actions, she explained. Ukraine's own data show a similar trend, with malware responsible for 33% of cyber incidents in the first half of 2026, followed by social engineering at 31%. System infections made up 15% of incidents, and system compromises accounted for 4.5%.
Attackers focus less on technical complexity and more on trust, as reported by Ukraine's State Service of Special Communications and Information Protection. Hacker groups create fake pages mimicking government and defense systems to trick users. Microsoft recommends five steps for governments to prepare for faster-moving threats, including assigning roles, coordinating agencies beforehand, treating AI security as part of national resilience, and planning for incidents that spread, given that 52.2% of intrusions involving valid accounts led to additional credential theft.
Written by urgent.news from Euromaidan Press's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.