Radware puts Israel first among hacktivist targets, but the attackers are mostly pro-Russian
One in six claimed hacktivist attacks in the first half of 2026 named Israel. Eighty-five percent of all claims came from the pro-Russia collective, not from Iran-aligned groups.
Radware’s H1 2026 Global Threat Report, published Wednesday, found Israel absorbed 16% of claimed hacktivist campaigns worldwide, with 784 recorded attack claims. The United States was second at 8%, the United Kingdom third. That is a widening lead: Radware’s full-year 2025 report, published 19 February, put Israel at 12.2% against 9.4% for the United States and 8.9% for Ukraine. “The most significant finding is not merely that Israel once again ranks first, but that the gap between it and the other countries continues to widen,” said Ron Meyran, vice president of cyber intelligence at Radware. “The digital arena has become an inseparable part of every military conflict, and the campaign against Iran demonstrated how quickly dozens of groups can mobilize.” Radware is headquartered in Tel Aviv.
The more useful finding is the attribution underneath the target list. Radware reports that most hacktivist groups active in the first half were from the pro-Russia, anti-Western collective, which claimed 85% of attacks, with NoName057 alone accounting for almost 40%. In 2025 the same group logged 4,692 claims out of roughly 16,000 total, which Radware called the most prolific hacktivist record in the history of the category. The report also notes claims hit a record low in the opening months of 2026 before spiking during the war between the United States, Israel and Iran. The unit throughout is the claimed attack, largely self-reported on Telegram in real time.
Assessment: Nobody has published a matching count of verified disruptions, and until someone does, a rising Israel share may measure claiming behaviour as much as attack volume. Telegram-announced DDoS is cheap to run and cheaper to assert; the incentive structure rewards volume of posts, not effect. Hold this against the desk’s lead story, where a claimed telecoms hit met a carrier denial and an absent water incident. Both items describe the same economy: the assertion is the product. The uncomfortable corollary from a retired federal law enforcement official quoted by BankInfoSecurity last month is that Iranian-linked infrastructure attacks have arrived without the information operations doctrine says should accompany them. Either the monitoring is missing them, or the doctrine changed, or the attacks are not what they are claimed to be.