Only the US and Israel were hit by more cyberattacks than Ukraine this year. Ukraine ranked third in the world and first in Europe among the countries whose organizations and users were most often targeted by cyberattacks in the first half of 2026, accounting for 4.8% of all victims worldwide, up from fifth in the world and third in Europe a year earlier, Microsoft said in its Digital Defense Report 2026.
Microsoft processes more than 165 trillion security signals a day, which lets it show how often attackers go after customers in each country. Russian state hackers aimed 14% of their recorded activity at Ukraine, more than at any country except the US.
The era of machine-speed cyberattacks is here
Government agencies and services were the most targeted sector worldwide at 27%, up from 17% in 2025. Phishing drove 23% of intrusions Microsoft investigated, up from 7% a year earlier, and the median time from finding a vulnerability to weaponizing it has fallen well below 24 hours.
The use of artificial intelligence is pushing cyberspace into an era of “machine-speed” attacks that operate continuously and without fatigue, according to Dev.
“Many AI agents act on behalf of users and with their access rights, so a compromised agent combines user-level access with machine-scale actions,” Natalia Burlakova, Security Sales and Engineering Lead at Microsoft, says.
Deception beats code in attacks on Ukraine
Ukraine's own agency data show a similar pattern. Malware accounted for 33% of cyber incidents in the first half of 2026, and social engineering 31%, the State Service of Special Communications and Information Protection reported on 30 September. System infections made up 15%, and system compromises 4.5%.
Attackers rely less on technical complexity than on trust, according to the report by Ukraine's computer emergency response team, CERT-UA. Hacker groups create fake pages that mimic CERT-UA, Ukraine's Parliament's document management system, and the Brave1 defense technology platform.
Microsoft urges five government steps
Microsoft asks governments to prepare for faster-moving threats by assigning roles and coordinating agencies in advance of a crisis, and to treat AI security as part of national resilience. It also asks them to plan for incidents that spread, noting that 52.2% of intrusions involving valid accounts led to additional credential theft.
Read also
-
Hours after Trump declared an energy ceasefire, Russia hit Kharkiv power plant, one of 200-plus strikes on Ukraine’s grid this week, Zelenskyy says
-
Ukraine ordered 54% more FPV attack drones this year than in all of 2025, and deliveries jumped almost fourfold
-
Ukraine wants to draft 15 of every 100 workers at its weapons plants. Arms makers say this could slow guns soldiers need


