Global attack activity
Top origin countries of global attack traffic from Cloudflare Radar, alongside live honeypot observations from the SANS Internet Storm Center. Updated every 30 minutes.
Global threat level (ISC Infocon)
greenTop attack source countries
- USUnited States of America20%
- BRBrazil6.7%
- IDIndonesia6.6%
- CNPeople's Republic of China4.7%
- FRFrance4.1%
- DEGermany4%
- INIndia3%
- SGSingapore2.8%
Most targeted ports
Most active attacking IPs
- 54.183.203.240first seen 2026-07-30
- 34.245.179.162first seen 2026-07-30
- 34.209.67.20first seen 2026-07-30
- 3.99.162.190first seen 2026-07-30
- 3.97.114.99first seen 2026-07-30
- 3.82.127.245first seen 2026-07-30
- 3.76.116.72first seen 2026-07-30
- 3.64.252.84first seen 2026-07-30
Top attack source countries
- USUnited States of America20%
- BRBrazil10.5%
- CNPeople's Republic of China5.1%
- DEGermany4.6%
- IDIndonesia4%
- SGSingapore3.7%
- INIndia3.3%
- NLNetherlands2.9%
Most targeted ports
- 22SSH1,351,297 reports
- 80HTTP897,930 reports
- 51413—497,680 reports
- 443HTTPS488,493 reports
- 23Telnet453,852 reports
- 2222SSH (alt)420,139 reports
- 5683—388,899 reports
- 8080HTTP (alt)242,773 reports
Most active attacking IPs
- 212.103.72.193first seen 2021-11-09
- 212.103.72.201first seen 2021-11-09
- 89.248.163.200first seen 2022-09-21
- 91.191.209.198first seen 2022-06-13
- 185.94.111.1first seen 2021-09-11
- 74.50.61.103first seen 2021-11-19
- 66.240.205.34first seen 2021-09-11
- 207.90.244.6first seen 2022-12-10
Top attack source countries
- USUnited States of America21.8%
- BRBrazil9.1%
- CNPeople's Republic of China5.3%
- IDIndonesia4.6%
- INIndia4.4%
- FRFrance4.2%
- DEGermany3.8%
- SGSingapore3.1%
Most targeted ports
- 22SSH1,053,407 reports
- 443HTTPS926,076 reports
- 23Telnet523,333 reports
- 80HTTP484,385 reports
- 2222SSH (alt)410,420 reports
- 51413—298,840 reports
- 16881—239,069 reports
- 8080HTTP (alt)236,611 reports
Most active attacking IPs
- 212.103.72.193first seen 2021-11-09
- 212.103.72.201first seen 2021-11-09
- 89.248.163.200first seen 2022-09-21
- 91.191.209.198first seen 2022-06-13
- 185.94.111.1first seen 2021-09-11
- 74.50.61.103first seen 2021-11-19
- 66.240.205.34first seen 2021-09-11
- 207.90.244.6first seen 2022-12-10
Last updated: 30 Jul 2026, 02:38 · isc.sans.edu — Data: SANS Internet Storm Center (DShield) and Cloudflare Radar — refreshed every 30 minutes. Figures reflect each network's observations, not all global traffic.
Publicly reported cyber incidents in Croatia
A selection of major incidents that were publicly reported by Croatian media and the affected organisations.
38
state-sponsored (APT) attacks on Croatian targets in 2024
2,390
cybercrime offences recorded in 2024 (+17.6% year over year)
26.1%
of Croatian companies had at least one security incident (EU average: 21.5%)
Ministry of Health
A weekend cyberattack hit selected ministry applications; the ministry confirmed the system holding patient medical data was not affected (June 2026).
Source: glas-slavonije.hrHotel booking platform (Phobsa)
Personal data of over 100,000 hotel guests was stolen from a Croatian booking platform and abused for WhatsApp fraud attempts; financial data was reportedly not included (June 2026).
Source: dnevnik.hrRuđer Bošković Institute
A ransomware attack exploiting the SharePoint 'ToolShell' vulnerabilities hit the institute's mail and administrative network; IRB refused to pay and restored systems from backups (July 2025).
Source: irb.hrSplit Airport
A ransomware attack disrupted airport systems; the government confirmed a classic ransomware case, stated there would be no negotiations, and an international group was suspected (July 2024).
Source: vlada.gov.hrMinistry of Finance, Tax Administration, HNB, Zagreb Stock Exchange
Pro-Russian group NoName057(16) claimed DDoS attacks that kept the websites of several Croatian financial institutions unavailable for hours (June 2024).
Source: tportal.hrUniversity Hospital Centre Zagreb (KBC Zagreb)
LockBit 3.0 ransomware attack forced the hospital to shut down its IT systems and revert to manual operations; the group claimed to have stolen patient and employee data (June 2024).
Source: tportal.hrA1 Croatia
A data breach exposed personal data (name, address, personal ID number, phone) of roughly 10% of customers; the attacker demanded a ransom, and the regulator later fined the operator (February 2022).
Source: telegram.hrINA Group
A Clop ransomware infection took large parts of the oil company's business systems offline; fuel sales continued but invoicing, loyalty cards and vouchers were disrupted (February 2020).
Source: ina.hrCompiled from publicly available media reports and official statements. The list is illustrative, not exhaustive, and is provided for awareness purposes only.