Global attack activity
Top origin countries of global attack traffic from Cloudflare Radar, alongside live honeypot observations from the SANS Internet Storm Center. Updated every 30 minutes.
Global threat level (ISC Infocon)
greenTop attack source countries
- USUnited States of America22.5%
- INIndia10.5%
- CNPeople's Republic of China5.3%
- DEGermany4.5%
- IDIndonesia4.4%
- SGSingapore4.3%
- NLNetherlands4.2%
- FRFrance3.3%
Most targeted ports
- 443HTTPS533,976 reports
- 80HTTP464,414 reports
- 22SSH326,042 reports
- 2222SSH (alt)219,124 reports
- 8080HTTP (alt)100,213 reports
- 23Telnet90,967 reports
- 51413—78,060 reports
- 16767—70,880 reports
Most active attacking IPs
- 185.94.111.1first seen 2021-09-11
- 74.50.61.103first seen 2021-11-19
- 66.240.205.34first seen 2021-09-11
- 80.82.77.33first seen 2021-09-12
- 80.82.77.139first seen 2021-09-12
- 207.90.244.3first seen 2022-12-08
- 207.90.244.5first seen 2022-12-10
- 71.6.199.23first seen 2021-09-11
Top attack source countries
- USUnited States of America25.3%
- CNPeople's Republic of China6.4%
- DEGermany5%
- NLNetherlands4.7%
- SGSingapore4.6%
- FRFrance4.5%
- IDIndonesia4.2%
- BRBrazil3.2%
Most targeted ports
- 80HTTP2,433,406 reports
- 22SSH1,733,897 reports
- 8080HTTP (alt)1,600,951 reports
- 443HTTPS1,573,595 reports
- 8000—1,422,485 reports
- 23Telnet523,321 reports
- 2222SSH (alt)518,718 reports
- 16767—183,984 reports
Most active attacking IPs
- 212.103.72.193first seen 2021-11-09
- 212.103.72.201first seen 2021-11-09
- 89.248.163.200first seen 2022-09-21
- 91.191.209.198first seen 2022-06-13
- 185.94.111.1first seen 2021-09-11
- 74.50.61.103first seen 2021-11-19
- 66.240.205.34first seen 2021-09-11
- 207.90.244.6first seen 2022-12-10
Top attack source countries
- USUnited States of America24.2%
- CNPeople's Republic of China5.8%
- IDIndonesia5.7%
- DEGermany5.1%
- SGSingapore4.6%
- INIndia4.1%
- NLNetherlands4%
- FRFrance2.9%
Most targeted ports
- 22SSH1,411,931 reports
- 80HTTP1,215,144 reports
- 23Telnet852,409 reports
- 8080HTTP (alt)386,346 reports
- 2222SSH (alt)362,112 reports
- 8000—314,385 reports
- 443HTTPS248,715 reports
- 54954—110,135 reports
Most active attacking IPs
- 212.103.72.193first seen 2021-11-09
- 212.103.72.201first seen 2021-11-09
- 89.248.163.200first seen 2022-09-21
- 91.191.209.198first seen 2022-06-13
- 185.94.111.1first seen 2021-09-11
- 74.50.61.103first seen 2021-11-19
- 66.240.205.34first seen 2021-09-11
- 207.90.244.6first seen 2022-12-10
Last updated: 12 Sept 2026, 12:52 · isc.sans.edu — Data: SANS Internet Storm Center (DShield) and Cloudflare Radar — refreshed every 30 minutes. Figures reflect each network's observations, not all global traffic.
Publicly reported cyber incidents in Croatia
A selection of major incidents that were publicly reported by Croatian media and the affected organisations.
38
state-sponsored (APT) attacks on Croatian targets in 2024
2,390
cybercrime offences recorded in 2024 (+17.6% year over year)
26.1%
of Croatian companies had at least one security incident (EU average: 21.5%)
Ministry of Health
A weekend cyberattack hit selected ministry applications; the ministry confirmed the system holding patient medical data was not affected (June 2026).
Source: glas-slavonije.hrHotel booking platform (Phobsa)
Personal data of over 100,000 hotel guests was stolen from a Croatian booking platform and abused for WhatsApp fraud attempts; financial data was reportedly not included (June 2026).
Source: dnevnik.hrRuđer Bošković Institute
A ransomware attack exploiting the SharePoint 'ToolShell' vulnerabilities hit the institute's mail and administrative network; IRB refused to pay and restored systems from backups (July 2025).
Source: irb.hrSplit Airport
A ransomware attack disrupted airport systems; the government confirmed a classic ransomware case, stated there would be no negotiations, and an international group was suspected (July 2024).
Source: vlada.gov.hrMinistry of Finance, Tax Administration, HNB, Zagreb Stock Exchange
Pro-Russian group NoName057(16) claimed DDoS attacks that kept the websites of several Croatian financial institutions unavailable for hours (June 2024).
Source: tportal.hrUniversity Hospital Centre Zagreb (KBC Zagreb)
LockBit 3.0 ransomware attack forced the hospital to shut down its IT systems and revert to manual operations; the group claimed to have stolen patient and employee data (June 2024).
Source: tportal.hrA1 Croatia
A data breach exposed personal data (name, address, personal ID number, phone) of roughly 10% of customers; the attacker demanded a ransom, and the regulator later fined the operator (February 2022).
Source: telegram.hrINA Group
A Clop ransomware infection took large parts of the oil company's business systems offline; fuel sales continued but invoicing, loyalty cards and vouchers were disrupted (February 2020).
Source: ina.hrCompiled from publicly available media reports and official statements. The list is illustrative, not exhaustive, and is provided for awareness purposes only.