According to Microsoft’s annual cyber defense report, Israel ranked second globally in the volume of observed cyber activity targeting it between July 2025 and June 2026, trailing only the United States. Israel accounted for 7.6% of all measured global cyber threat activity, compared to 25.5% for the U.S., 4.8% for Ukraine, and 3.9% for Taiwan. Within the Middle East and Africa, Israel led the region in targeted attacks.
The report, published for the seventh consecutive year, is based on security telemetry observed between July 2025 and June 2026 across Microsoft systems processing over 165 trillion security signals daily. According to Microsoft, artificial intelligence continues to transform the cyber threat landscape. AI enables attackers to launch larger-scale campaigns, craft highly convincing personalized phishing attempts, and automate processes that previously required significant manual resources. Simultaneously, the proliferation of AI tools and autonomous AI agents creates a broader attack surface, requiring organizations to protect the identities and permission levels of autonomous systems as well.
The report identifies Iran as the primary state-backed driver of cyber operations targeting Israel. Israel was the target of 39% of all activity originating from threat actors linked to Tehran, followed by the U.S. (23%), the UAE (9%), Egypt (6%), and India (6%).
Microsoft notes that during periods of heightened regional tension and military escalation, Iranian state-linked actors deployed multi-layered campaigns against Israel and regional neighbors, while substantially expanding operations against American interests. These campaigns increasingly converged cyberattacks, kinetic military actions, and foreign influence operations to maximize operational and psychological impact.
Alongside espionage and intelligence gathering, Microsoft observed a marked shift toward disruptive and destructive capabilities, including data wipers and operational technology (OT) disruptions. Iranian actors continue seeking persistent access to research and academic institutions, IT and telecom providers, critical infrastructure, government entities, defense supply chains, NGOs, and dissident communities, both for intelligence collection and to stage potential future operational disruption.
Iranian threat groups rely heavily on exploiting known software vulnerabilities, weak authentication protocols, and unpatched internet-facing systems. Credential theft and phishing remain primary initial-access vectors; post-compromise, attackers frequently leverage cloud infrastructure, including Microsoft Azure, to maintain persistence and pivot laterally.
Furthermore, Microsoft highlights a growing convergence in tactics among distinct Iranian threat groups, allowing them to scale operations and amplify potential impact.
Ransomware attacks targeting Israeli organizations also rose significantly. The volume of observed ransomware incidents in Israel increased by 21% year-over-year, with Israel’s share of globally affected activity rising from 19% to 23%. This surge occurred despite a 3% global decline in total recorded ransomware incidents (dropping from 8,749 to 8,521). Microsoft assesses that this sustained focus reflects Iran’s integration of ransomware into its hybrid warfare strategy. Modern ransomware incidents are no longer isolated endpoint compromises, but complex operations involving identity theft, network infiltration, vulnerability exploitation, and enterprise domain takeovers.
Globally, threat actors are maintaining longer dwell times undetected within victim networks, while state-sponsored groups increasingly rely on pre-acquired access. Microsoft specifically highlights growing threats from open-source software supply chain compromises, edge device exploits (such as firewalls and routers), and AI utilization as a force multiplier.
To mitigate these evolving threats, Microsoft recommends prioritizing robust identity protection, mandatory multi-factor authentication (MFA), continuous anomaly monitoring, and rapid intrusion response alongside resilient backup and recovery protocols and public-private security partnerships.