Live Cyber Threat Pulse

Global attack activity

Top origin countries of global attack traffic from Cloudflare Radar, alongside live honeypot observations from the SANS Internet Storm Center. Updated every 30 minutes.

Global threat level (ISC Infocon)

green
United States of America: 24.7% of global attack trafficPeople's Republic of China: 6.6% of global attack trafficIndonesia: 5.6% of global attack trafficGermany: 5.2% of global attack trafficBrazil: 3.6% of global attack trafficNetherlands: 3.2% of global attack trafficFrance: 3.2% of global attack trafficIndia: 2.9% of global attack trafficCanada: 2.1% of global attack trafficRussian Federation: 1.7% of global attack trafficJapan: 1.7% of global attack trafficVietnam: 1.7% of global attack trafficMexico: 1.5% of global attack trafficItaly: 1.5% of global attack trafficUnited States of America: 21.5% of global attack trafficIndonesia: 6% of global attack trafficPeople's Republic of China: 5.3% of global attack trafficNetherlands: 5.2% of global attack trafficGermany: 4.4% of global attack trafficIndia: 3.9% of global attack trafficFrance: 3.1% of global attack trafficBrazil: 2.7% of global attack trafficJapan: 1.8% of global attack trafficUnited Kingdom: 1.7% of global attack trafficRussian Federation: 1.7% of global attack trafficItaly: 1.6% of global attack trafficVietnam: 1.6% of global attack trafficSouth Korea: 1.5% of global attack trafficUnited States of America: 19.6% of global attack trafficBrazil: 11.4% of global attack trafficPeople's Republic of China: 5.3% of global attack trafficIndonesia: 4.4% of global attack trafficGermany: 4.3% of global attack trafficNetherlands: 3.9% of global attack trafficFrance: 3.5% of global attack trafficIndia: 3.4% of global attack trafficCanada: 2.5% of global attack trafficUnited Kingdom: 2.1% of global attack trafficRussian Federation: 1.9% of global attack trafficVietnam: 1.7% of global attack trafficFinland: 1.7% of global attack trafficSouth Korea: 1.6% of global attack traffic

Top attack source countries

  • USUnited States of America24.7%
  • CNPeople's Republic of China6.6%
  • IDIndonesia5.6%
  • DEGermany5.2%
  • SGSingapore4.4%
  • BRBrazil3.6%
  • NLNetherlands3.2%
  • FRFrance3.2%

Most targeted ports

  • 80HTTP775,472 reports
  • 22SSH436,139 reports
  • 23Telnet208,708 reports
  • 443HTTPS88,621 reports
  • 2222SSH (alt)87,785 reports
  • 8080HTTP (alt)79,479 reports
  • 800072,658 reports
  • 370267,820 reports

Most active attacking IPs

  • 91.191.209.198first seen 2022-06-13
  • 185.94.111.1first seen 2021-09-11
  • 74.50.61.103first seen 2021-11-19
  • 66.240.205.34first seen 2021-09-11
  • 207.90.244.6first seen 2022-12-10
  • 80.82.77.33first seen 2021-09-12
  • 80.82.77.139first seen 2021-09-12
  • 207.90.244.3first seen 2022-12-08

Top attack source countries

  • USUnited States of America21.5%
  • IDIndonesia6%
  • CNPeople's Republic of China5.3%
  • NLNetherlands5.2%
  • SGSingapore4.6%
  • DEGermany4.4%
  • INIndia3.9%
  • FRFrance3.1%

Most targeted ports

  • 22SSH866,671 reports
  • 443HTTPS749,275 reports
  • 23Telnet298,549 reports
  • 80HTTP229,392 reports
  • 8080HTTP (alt)189,843 reports
  • 853173,273 reports
  • 59086172,747 reports
  • 8000154,671 reports

Most active attacking IPs

  • 212.103.72.193first seen 2021-11-09
  • 212.103.72.201first seen 2021-11-09
  • 89.248.163.200first seen 2022-09-21
  • 91.191.209.198first seen 2022-06-13
  • 185.94.111.1first seen 2021-09-11
  • 74.50.61.103first seen 2021-11-19
  • 66.240.205.34first seen 2021-09-11
  • 207.90.244.6first seen 2022-12-10

Top attack source countries

  • USUnited States of America19.6%
  • BRBrazil11.4%
  • CNPeople's Republic of China5.3%
  • IDIndonesia4.4%
  • DEGermany4.3%
  • NLNetherlands3.9%
  • FRFrance3.5%
  • INIndia3.4%

Most targeted ports

  • 22SSH1,158,601 reports
  • 23Telnet545,648 reports
  • 51413509,748 reports
  • 443HTTPS418,726 reports
  • 80HTTP388,505 reports
  • 2222SSH (alt)253,634 reports
  • 16881237,798 reports
  • 8080HTTP (alt)223,551 reports

Most active attacking IPs

  • 212.103.72.193first seen 2021-11-09
  • 212.103.72.201first seen 2021-11-09
  • 89.248.163.200first seen 2022-09-21
  • 91.191.209.198first seen 2022-06-13
  • 185.94.111.1first seen 2021-09-11
  • 74.50.61.103first seen 2021-11-19
  • 66.240.205.34first seen 2021-09-11
  • 207.90.244.6first seen 2022-12-10

Last updated: 15 Aug 2026, 21:37 · isc.sans.edu Data: SANS Internet Storm Center (DShield) and Cloudflare Radar — refreshed every 30 minutes. Figures reflect each network's observations, not all global traffic.

Publicly reported cyber incidents in Croatia

A selection of major incidents that were publicly reported by Croatian media and the affected organisations.

38

state-sponsored (APT) attacks on Croatian targets in 2024

2,390

cybercrime offences recorded in 2024 (+17.6% year over year)

26.1%

of Croatian companies had at least one security incident (EU average: 21.5%)

Source: tportal.hr (SOA)
2026Data breach

Ministry of Health

A weekend cyberattack hit selected ministry applications; the ministry confirmed the system holding patient medical data was not affected (June 2026).

Source: glas-slavonije.hr
2026Data breach

Hotel booking platform (Phobsa)

Personal data of over 100,000 hotel guests was stolen from a Croatian booking platform and abused for WhatsApp fraud attempts; financial data was reportedly not included (June 2026).

Source: dnevnik.hr
2025Ransomware

Ruđer Bošković Institute

A ransomware attack exploiting the SharePoint 'ToolShell' vulnerabilities hit the institute's mail and administrative network; IRB refused to pay and restored systems from backups (July 2025).

Source: irb.hr
2024Ransomware

Split Airport

A ransomware attack disrupted airport systems; the government confirmed a classic ransomware case, stated there would be no negotiations, and an international group was suspected (July 2024).

Source: vlada.gov.hr
2024DDoS

Ministry of Finance, Tax Administration, HNB, Zagreb Stock Exchange

Pro-Russian group NoName057(16) claimed DDoS attacks that kept the websites of several Croatian financial institutions unavailable for hours (June 2024).

Source: tportal.hr
2024Ransomware

University Hospital Centre Zagreb (KBC Zagreb)

LockBit 3.0 ransomware attack forced the hospital to shut down its IT systems and revert to manual operations; the group claimed to have stolen patient and employee data (June 2024).

Source: tportal.hr
2022Data breach

A1 Croatia

A data breach exposed personal data (name, address, personal ID number, phone) of roughly 10% of customers; the attacker demanded a ransom, and the regulator later fined the operator (February 2022).

Source: telegram.hr
2020Ransomware

INA Group

A Clop ransomware infection took large parts of the oil company's business systems offline; fuel sales continued but invoicing, loyalty cards and vouchers were disrupted (February 2020).

Source: ina.hr

Compiled from publicly available media reports and official statements. The list is illustrative, not exhaustive, and is provided for awareness purposes only.