Наталя ХандусенкоHot News
6 October 2026, 18:06
2026-10-06
Ukraine ranks third in the world in terms of the number of cyberattacks and first in Europe
In the first half of 2026, Ukraine ranked third in the world and first in Europe among the countries most frequently targeted by cyberattacks. Our country accounted for 4.8% of the total number of victims in the world - higher figures were recorded only in the USA and Israel. Last year, Ukraine ranked fifth in the world and third in the European ranking.
In the first half of 2026, Ukraine ranked third in the world and first in Europe among the countries most frequently targeted by cyberattacks. Our country accounted for 4.8% of the total number of victims in the world - higher figures were recorded only in the USA and Israel. Last year, Ukraine ranked fifth in the world and third in the European ranking.
This is stated in the new Microsoft Digital Defense Report 2026.
According to Microsoft, Ukraine remains one of the main targets for Russian state hackers: it accounts for 14% of their total recorded activity (more is directed only against the United States).
The company's analysts emphasize that the public sector has become the main target of cyberattacks in the world. The share of government institutions and services among all victims has increased to 27% (versus 17% in 2025). Attackers are attracted by confidential information and the opportunity to disrupt critical infrastructure.
Key findings of the report
Phishing accounted for 23% of recorded intrusions (up from 7% in 2025). Compromised credentials remain the main “door” for hackers.
In 52.2% of cases where valid accounts were used, attackers stole additional data. A typical initial intrusion quickly escalates into ransomware attacks, cyberespionage, or service disruptions.
It now takes less than 24 hours for a vulnerability to be actively exploited by hackers, and the number of publicly disclosed vulnerabilities (CVEs) is expected to reach a record 72,000 in 2026.
Attackers remain undetected for longer in compromised systems because they skillfully mimic legitimate user activity.
The use of artificial intelligence is moving cyberspace into a phase of “machine-speed” attacks that continue continuously and tirelessly.
“With AI, this risk takes on two new dimensions. First, attackers are already using AI, while many organizations are still hesitant to involve it in security operations… Second, the uncontrolled use of AI creates a new dangerous attack surface. Many AI agents act on behalf of users and with their access rights, so a compromised agent combines user-level access with machine-scale actions,” emphasized Natalia Burlakova, Security Sales and Engineering Lead at Microsoft.
To limit the damage and ensure the continuity of critical services, Microsoft suggests that governments implement five steps:
Prepare for the rapid development of threats: clearly allocate roles and build coordination between agencies before a crisis situation occurs.
Build security into the AI ecosystem: consider AI security as an element of national resilience (through security by design and supply chain protection).
Consider incident spread: develop response plans that take into account contractors, partners, and cross-border cooperation.
Ensure two-way information exchange: establish operational exchange of threat analytics between the public and private sectors.
Prepare critical services for operation during failures: identify the most important systems and conduct regular scenario training.
Reference
This year's Microsoft Digital Defense Report covers an analysis of cyberthreat trends from July 2025 to June 2026.