Live Cyber Threat Pulse

Global attack activity

Top origin countries of global attack traffic from Cloudflare Radar, alongside live honeypot observations from the SANS Internet Storm Center. Updated every 30 minutes.

Global threat level (ISC Infocon)

green
United States of America: 22.5% of global attack trafficIndia: 10.5% of global attack trafficPeople's Republic of China: 5.3% of global attack trafficGermany: 4.5% of global attack trafficIndonesia: 4.4% of global attack trafficNetherlands: 4.2% of global attack trafficFrance: 3.3% of global attack trafficBrazil: 3.2% of global attack trafficTürkiye: 2% of global attack trafficVietnam: 1.8% of global attack trafficSouth Korea: 1.7% of global attack trafficUnited Kingdom: 1.6% of global attack trafficJapan: 1.4% of global attack trafficUnited States of America: 25.3% of global attack trafficPeople's Republic of China: 6.4% of global attack trafficGermany: 5% of global attack trafficNetherlands: 4.7% of global attack trafficFrance: 4.5% of global attack trafficIndonesia: 4.2% of global attack trafficBrazil: 3.2% of global attack trafficIndia: 3% of global attack trafficTürkiye: 2.8% of global attack trafficRussian Federation: 2.1% of global attack trafficUnited Kingdom: 1.8% of global attack trafficVietnam: 1.7% of global attack trafficSouth Korea: 1.6% of global attack trafficUnited States of America: 24.2% of global attack trafficPeople's Republic of China: 5.8% of global attack trafficIndonesia: 5.7% of global attack trafficGermany: 5.1% of global attack trafficIndia: 4.1% of global attack trafficNetherlands: 4% of global attack trafficFrance: 2.9% of global attack trafficBrazil: 2.8% of global attack trafficJapan: 2.5% of global attack trafficRussian Federation: 1.8% of global attack trafficVietnam: 1.7% of global attack trafficCanada: 1.6% of global attack trafficUnited Kingdom: 1.5% of global attack traffic

Top attack source countries

  • USUnited States of America22.5%
  • INIndia10.5%
  • CNPeople's Republic of China5.3%
  • DEGermany4.5%
  • IDIndonesia4.4%
  • SGSingapore4.3%
  • NLNetherlands4.2%
  • FRFrance3.3%

Most targeted ports

  • 443HTTPS533,976 reports
  • 80HTTP464,414 reports
  • 22SSH326,042 reports
  • 2222SSH (alt)219,124 reports
  • 8080HTTP (alt)100,213 reports
  • 23Telnet90,967 reports
  • 5141378,060 reports
  • 1676770,880 reports

Most active attacking IPs

  • 185.94.111.1first seen 2021-09-11
  • 74.50.61.103first seen 2021-11-19
  • 66.240.205.34first seen 2021-09-11
  • 80.82.77.33first seen 2021-09-12
  • 80.82.77.139first seen 2021-09-12
  • 207.90.244.3first seen 2022-12-08
  • 207.90.244.5first seen 2022-12-10
  • 71.6.199.23first seen 2021-09-11

Top attack source countries

  • USUnited States of America25.3%
  • CNPeople's Republic of China6.4%
  • DEGermany5%
  • NLNetherlands4.7%
  • SGSingapore4.6%
  • FRFrance4.5%
  • IDIndonesia4.2%
  • BRBrazil3.2%

Most targeted ports

  • 80HTTP2,433,406 reports
  • 22SSH1,733,897 reports
  • 8080HTTP (alt)1,600,951 reports
  • 443HTTPS1,573,595 reports
  • 80001,422,485 reports
  • 23Telnet523,321 reports
  • 2222SSH (alt)518,718 reports
  • 16767183,984 reports

Most active attacking IPs

  • 212.103.72.193first seen 2021-11-09
  • 212.103.72.201first seen 2021-11-09
  • 89.248.163.200first seen 2022-09-21
  • 91.191.209.198first seen 2022-06-13
  • 185.94.111.1first seen 2021-09-11
  • 74.50.61.103first seen 2021-11-19
  • 66.240.205.34first seen 2021-09-11
  • 207.90.244.6first seen 2022-12-10

Top attack source countries

  • USUnited States of America24.2%
  • CNPeople's Republic of China5.8%
  • IDIndonesia5.7%
  • DEGermany5.1%
  • SGSingapore4.6%
  • INIndia4.1%
  • NLNetherlands4%
  • FRFrance2.9%

Most targeted ports

  • 22SSH1,411,931 reports
  • 80HTTP1,215,144 reports
  • 23Telnet852,409 reports
  • 8080HTTP (alt)386,346 reports
  • 2222SSH (alt)362,112 reports
  • 8000314,385 reports
  • 443HTTPS248,715 reports
  • 54954110,135 reports

Most active attacking IPs

  • 212.103.72.193first seen 2021-11-09
  • 212.103.72.201first seen 2021-11-09
  • 89.248.163.200first seen 2022-09-21
  • 91.191.209.198first seen 2022-06-13
  • 185.94.111.1first seen 2021-09-11
  • 74.50.61.103first seen 2021-11-19
  • 66.240.205.34first seen 2021-09-11
  • 207.90.244.6first seen 2022-12-10

Last updated: 12 Sept 2026, 12:52 · isc.sans.edu Data: SANS Internet Storm Center (DShield) and Cloudflare Radar — refreshed every 30 minutes. Figures reflect each network's observations, not all global traffic.

Publicly reported cyber incidents in Croatia

A selection of major incidents that were publicly reported by Croatian media and the affected organisations.

38

state-sponsored (APT) attacks on Croatian targets in 2024

2,390

cybercrime offences recorded in 2024 (+17.6% year over year)

26.1%

of Croatian companies had at least one security incident (EU average: 21.5%)

Source: tportal.hr (SOA)
2026Data breach

Ministry of Health

A weekend cyberattack hit selected ministry applications; the ministry confirmed the system holding patient medical data was not affected (June 2026).

Source: glas-slavonije.hr
2026Data breach

Hotel booking platform (Phobsa)

Personal data of over 100,000 hotel guests was stolen from a Croatian booking platform and abused for WhatsApp fraud attempts; financial data was reportedly not included (June 2026).

Source: dnevnik.hr
2025Ransomware

Ruđer Bošković Institute

A ransomware attack exploiting the SharePoint 'ToolShell' vulnerabilities hit the institute's mail and administrative network; IRB refused to pay and restored systems from backups (July 2025).

Source: irb.hr
2024Ransomware

Split Airport

A ransomware attack disrupted airport systems; the government confirmed a classic ransomware case, stated there would be no negotiations, and an international group was suspected (July 2024).

Source: vlada.gov.hr
2024DDoS

Ministry of Finance, Tax Administration, HNB, Zagreb Stock Exchange

Pro-Russian group NoName057(16) claimed DDoS attacks that kept the websites of several Croatian financial institutions unavailable for hours (June 2024).

Source: tportal.hr
2024Ransomware

University Hospital Centre Zagreb (KBC Zagreb)

LockBit 3.0 ransomware attack forced the hospital to shut down its IT systems and revert to manual operations; the group claimed to have stolen patient and employee data (June 2024).

Source: tportal.hr
2022Data breach

A1 Croatia

A data breach exposed personal data (name, address, personal ID number, phone) of roughly 10% of customers; the attacker demanded a ransom, and the regulator later fined the operator (February 2022).

Source: telegram.hr
2020Ransomware

INA Group

A Clop ransomware infection took large parts of the oil company's business systems offline; fuel sales continued but invoicing, loyalty cards and vouchers were disrupted (February 2020).

Source: ina.hr

Compiled from publicly available media reports and official statements. The list is illustrative, not exhaustive, and is provided for awareness purposes only.