Global attack activity
Top origin countries of global attack traffic from Cloudflare Radar, alongside live honeypot observations from the SANS Internet Storm Center. Updated every 30 minutes.
Global threat level (ISC Infocon)
greenTop attack source countries
- USUnited States of America24.7%
- CNPeople's Republic of China6.6%
- IDIndonesia5.6%
- DEGermany5.2%
- SGSingapore4.4%
- BRBrazil3.6%
- NLNetherlands3.2%
- FRFrance3.2%
Most targeted ports
- 80HTTP775,472 reports
- 22SSH436,139 reports
- 23Telnet208,708 reports
- 443HTTPS88,621 reports
- 2222SSH (alt)87,785 reports
- 8080HTTP (alt)79,479 reports
- 8000—72,658 reports
- 3702—67,820 reports
Most active attacking IPs
- 91.191.209.198first seen 2022-06-13
- 185.94.111.1first seen 2021-09-11
- 74.50.61.103first seen 2021-11-19
- 66.240.205.34first seen 2021-09-11
- 207.90.244.6first seen 2022-12-10
- 80.82.77.33first seen 2021-09-12
- 80.82.77.139first seen 2021-09-12
- 207.90.244.3first seen 2022-12-08
Top attack source countries
- USUnited States of America21.5%
- IDIndonesia6%
- CNPeople's Republic of China5.3%
- NLNetherlands5.2%
- SGSingapore4.6%
- DEGermany4.4%
- INIndia3.9%
- FRFrance3.1%
Most targeted ports
- 22SSH866,671 reports
- 443HTTPS749,275 reports
- 23Telnet298,549 reports
- 80HTTP229,392 reports
- 8080HTTP (alt)189,843 reports
- 853—173,273 reports
- 59086—172,747 reports
- 8000—154,671 reports
Most active attacking IPs
- 212.103.72.193first seen 2021-11-09
- 212.103.72.201first seen 2021-11-09
- 89.248.163.200first seen 2022-09-21
- 91.191.209.198first seen 2022-06-13
- 185.94.111.1first seen 2021-09-11
- 74.50.61.103first seen 2021-11-19
- 66.240.205.34first seen 2021-09-11
- 207.90.244.6first seen 2022-12-10
Top attack source countries
- USUnited States of America19.6%
- BRBrazil11.4%
- CNPeople's Republic of China5.3%
- IDIndonesia4.4%
- DEGermany4.3%
- NLNetherlands3.9%
- FRFrance3.5%
- INIndia3.4%
Most targeted ports
- 22SSH1,158,601 reports
- 23Telnet545,648 reports
- 51413—509,748 reports
- 443HTTPS418,726 reports
- 80HTTP388,505 reports
- 2222SSH (alt)253,634 reports
- 16881—237,798 reports
- 8080HTTP (alt)223,551 reports
Most active attacking IPs
- 212.103.72.193first seen 2021-11-09
- 212.103.72.201first seen 2021-11-09
- 89.248.163.200first seen 2022-09-21
- 91.191.209.198first seen 2022-06-13
- 185.94.111.1first seen 2021-09-11
- 74.50.61.103first seen 2021-11-19
- 66.240.205.34first seen 2021-09-11
- 207.90.244.6first seen 2022-12-10
Last updated: 15 Aug 2026, 21:37 · isc.sans.edu — Data: SANS Internet Storm Center (DShield) and Cloudflare Radar — refreshed every 30 minutes. Figures reflect each network's observations, not all global traffic.
Publicly reported cyber incidents in Croatia
A selection of major incidents that were publicly reported by Croatian media and the affected organisations.
38
state-sponsored (APT) attacks on Croatian targets in 2024
2,390
cybercrime offences recorded in 2024 (+17.6% year over year)
26.1%
of Croatian companies had at least one security incident (EU average: 21.5%)
Ministry of Health
A weekend cyberattack hit selected ministry applications; the ministry confirmed the system holding patient medical data was not affected (June 2026).
Source: glas-slavonije.hrHotel booking platform (Phobsa)
Personal data of over 100,000 hotel guests was stolen from a Croatian booking platform and abused for WhatsApp fraud attempts; financial data was reportedly not included (June 2026).
Source: dnevnik.hrRuđer Bošković Institute
A ransomware attack exploiting the SharePoint 'ToolShell' vulnerabilities hit the institute's mail and administrative network; IRB refused to pay and restored systems from backups (July 2025).
Source: irb.hrSplit Airport
A ransomware attack disrupted airport systems; the government confirmed a classic ransomware case, stated there would be no negotiations, and an international group was suspected (July 2024).
Source: vlada.gov.hrMinistry of Finance, Tax Administration, HNB, Zagreb Stock Exchange
Pro-Russian group NoName057(16) claimed DDoS attacks that kept the websites of several Croatian financial institutions unavailable for hours (June 2024).
Source: tportal.hrUniversity Hospital Centre Zagreb (KBC Zagreb)
LockBit 3.0 ransomware attack forced the hospital to shut down its IT systems and revert to manual operations; the group claimed to have stolen patient and employee data (June 2024).
Source: tportal.hrA1 Croatia
A data breach exposed personal data (name, address, personal ID number, phone) of roughly 10% of customers; the attacker demanded a ransom, and the regulator later fined the operator (February 2022).
Source: telegram.hrINA Group
A Clop ransomware infection took large parts of the oil company's business systems offline; fuel sales continued but invoicing, loyalty cards and vouchers were disrupted (February 2020).
Source: ina.hrCompiled from publicly available media reports and official statements. The list is illustrative, not exhaustive, and is provided for awareness purposes only.