0 new incidents · last 24 hours CC BY-NC 4.0

The Cyber Threat Landscape

— The Intensity of cyber operations over the last two months is declining to 3.2, compared with the preceding two-month period. This is above the all-time global average of 2.7.

The European Repository records and analyses politically significant cyber incidents and responses across the globe. The database currently includes 4668 incidents and 545 responses. On this page we present you (1) the global distribution of cyber incidents, (2) the most recent incidents, (3) the most recent responses, and (4) our most recent analysis.
01 / 03

Incidents

4668 incidents

Affected countries

All recorded cyber incidents, counted once per affected country.

11211
Jun–Jul 2026 · known origin to target Jun–Jul 2026 · unknown origin

Darker countries have more recorded incidents; color uses a logarithmic scale. 4276 of 4668 incidents map to 155 countries.

Incidents received

All countries · latest six months

Responses initiated

All countries · latest six months

Latest incidents

4668 total
Unknown Angola ·Telecom & digital Unknown Threat Actor Disrupted Mobile Voice, Data and Internet Services of Telecommunications Company Unitel in Angola on 28 July 2026 28 Jul 2026
Incident 28 Jul 2026
Unknown Angola ·Telecom & digital
Unknown Threat Actor Disrupted Mobile Voice, Data and Internet Services of Telecommunications Company Unitel in Angola on 28 July 2026
Unknown Romania ·Government & politics Unknown Threat Actor Launched Ransomware Attack on National Administration Of Penitentiaries in Romania on 28 July 2026 28 Jul 2026
Incident 28 Jul 2026
Unknown Romania ·Government & politics
Unknown Threat Actor Launched Ransomware Attack on National Administration Of Penitentiaries in Romania on 28 July 2026
Unknown United States ·Health Unknown Threat Actors Disrupted Systems of AnMed Hospital in United States on 26 July 2026 26 Jul 2026
Incident 26 Jul 2026
Unknown United States ·Health
Unknown Threat Actors Disrupted Systems of AnMed Hospital in United States on 26 July 2026
(Iran) United States ·Energy & utilities Unknown Threat Actor Breached Multiple Water Utilities Minnesota In United States On 26 and 27 July 2026 26 Jul 2026
Incident 26 Jul 2026
(Iran) United States ·Energy & utilities
Unknown Threat Actor Breached Multiple Water Utilities Minnesota In United States On 26 and 27 July 2026
B133DR00T Argentina ·Government & politics Unattributed Hacker Using Pseudonym B133DR00T Defaced Mendoza Senate's Website in Argentina on 24 July 2026 24 Jul 2026
Incident 24 Jul 2026
B133DR00T Argentina ·Government & politics
Unattributed Hacker Using Pseudonym B133DR00T Defaced Mendoza Senate's Website in Argentina on 24 July 2026
TripleX India ·Finance Cybercriminal Group TripleX Stole and Leaked Customer Data from the Bank of Baroda in India on 24 July 2026 24 Jul 2026
Incident 24 Jul 2026
TripleX India ·Finance
Cybercriminal Group TripleX Stole and Leaked Customer Data from the Bank of Baroda in India on 24 July 2026
Showing the 6 most recent of 4668 Open all in advanced search
02 / 03

Responses

545 responses

The institutional answer across the whole record — response rate, median lag, and the mix of instruments used. Responses are a decoupled stream; they often trail the incidents they cite.

22%of incidents got a response
16 momedian response time
545 responses
Operational · across domains135Operational · in-kind72Rhetorical338
By type545 logged

Latest responses

545 responses total
DKDanish Civil Protection Agency Pro-Russian hacker groups (Russian Federation) Danish SAMSIK Issued Warning of Heightened Threat From Destructive Cyber Attacks by Russian State-Sponsored Hackers on 30 June 2026 Official policy 30 Jun 2026
Official policy 30 Jun 2026
DKDanish Civil Protection Agency Pro-Russian hacker groups (Russian Federation)
Danish SAMSIK Issued Warning of Heightened Threat From Destructive Cyber Attacks by Russian State-Sponsored Hackers on 30 June 2026
GRAL2 statesjoint Albanian and Greek Defence Ministers Held Talks on Bilateral Cooperation in National Cybersecurity, 29 June 2026 Official policy 29 Jun 2026
Official policy 29 Jun 2026
GRAL2 states
Albanian and Greek Defence Ministers Held Talks on Bilateral Cooperation in National Cybersecurity, 29 June 2026
USME2 statescoordinated A.B. (Iranian/Turkish national) Montenegrin Police Directorate and FBI Arrested Turkish-Iranian Cybercrime Suspect in Kotor, 25 June 2026 Criminal proceedings 25 Jun 2026
Criminal proceedings 25 Jun 2026
USME2 states A.B. (Iranian/Turkish national)
Montenegrin Police Directorate and FBI Arrested Turkish-Iranian Cybercrime Suspect in Kotor, 25 June 2026
USJPKR3 statescoordinated US, Japan, and ROK Interagency Delegations Convened the Trilateral Diplomatic Working Group on DPRK Cyber Threats on 25-26 June 2026 Official policy 25 Jun 2026
Official policy 25 Jun 2026
USJPKR3 states
US, Japan, and ROK Interagency Delegations Convened the Trilateral Diplomatic Working Group on DPRK Cyber Threats on 25-26 June 2026
USGBDECA+26 statesjoint Amadey Europol and International Partners Launched Operation Endgame, Disrupting SocGholish, Amadey, and StealC Malware Networks on 24 June 2026 Operational action 24 Jun 2026
Operational action 24 Jun 2026
USGBDECA+26 states Amadey
Europol and International Partners Launched Operation Endgame, Disrupting SocGholish, Amadey, and StealC Malware Networks on 24 June 2026
GBCity of London Police Scattered Spider UK Authorities Convicted Scattered Spider Members for Cyber Attack on Transport for London on 22 June 2026 Criminal proceedings 22 Jun 2026
Criminal proceedings 22 Jun 2026
GBCity of London Police Scattered Spider
UK Authorities Convicted Scattered Spider Members for Cyber Attack on Transport for London on 22 June 2026
Showing the 6 most recent of 545 Open all responses in advanced search
03 / 03

Latest analysis

All publications
How to read the ledger Every row is an incident or a response. Shape tells them apart; colour and the marks below each sigil carry the rest.
Row type
Incident — a square sigil. The connected dots below carry attribution.
Response — a round sigil. The two squares below show its anchors.
Incident types
Data theft
Disruption
Hijacking
Ransomware & extortion
Response types
Official policy
Unofficial policy
Criminal proceedings
Technical disclosure
Operational action
Reading the marks
Attribution dots (incidents) — how firmly an initiator is named; both filled and joined navy when fully attributed.
none one both
Weight squares (responses) — anchors present: left = a linked incident, right = a named actor.
0 1 2
Issuer stack — one chip is a single issuer; a stack of ISO codes marks a joint or coordinated response.
EUsingle DEFRNL+5several states

An independent, interdisciplinary research consortium providing evidence-based analysis of cyber incidents and the political and legal responses to them.

A consortium of

Heidelberg University · Stiftung Wissenschaft und Politik (SWP)

© 2026 European Repository of Cyber Incidents Evidence-based analysis of cyber incidents & responses
Search