While military operations between Israel and Iran have temporarily stopped after a ceasefire was reached, the conflict in the digital realm not only continues but is also escalating. According to the latest data from Israel’s National Cyber Directorate, the number of hostile cyber incidents has increased dramatically in just one year, confirming that cyberspace is now one of the most important fronts in modern geopolitical confrontations.

The director general of the Israeli National Cyber Directorate, Yossi Karadi, revealed in an interview with the German newspaper Die Welt that in June 2026 alone, approximately 4,800 hostile cyber incidents were recorded, compared to approximately 1,600 in the same month in 2025.This increase corresponds to an almost threefold increase in incidents, which demonstrates the ongoing tension in the digital war between the two countries.
Cyberspace knows no truces
Karadi was particularly clear in his statements, pointing out that unlike military operations on the battlefield, cyber attacks never stop.
"Unlike conventional warfare, there is no truce in cyberspace," he said, emphasizing that even when military conflicts, hacker groups continue to operate daily, seeking new entry points into government and private networks.
This specific finding reflects the new reality of modern conflicts, where cyberattacks are a permanent tool of pressure, espionage, and economic damage.
See also: Iran: Surveillance cameras targeted by Israel
Targeting critical infrastructure and small businesses in Israel
According to the Israeli cybersecurity agency, the attacks are not limited to government agencies or military installations. Cybercriminals have critical infrastructure, large public organizations, businesses, and thousands of private users.
Of particular concern is the fact that several attacks have targeted small and medium-sized businesses, such as law firms and accounting firms. These organizations handle sensitive personal and financial data, but often lack the sophisticated cybersecurity systems found in large banks or utilities.
Experts point out that smaller businesses are now one of the most attractive targets for organized hacking groups, as the chances of a successful breach are significantly higher.

Critical infrastructure remains protected
Despite the huge number of incidents, Karadi clarified that so far no successful breach of the most critical national infrastructure has been achieved.
As he stated, security services have managed to repel attacks targeting vital networks, such as energy facilities, telecommunications systems and other critical state infrastructure.
However, he avoided appearing reassuring, emphasizing that cyber defense is an ongoing process and that no system can be considered completely secure against a constantly evolving adversary.
Iran: A more organized adversary
Another element that is causing concern to the Israeli authorities is the qualitative upgrading of the groups carrying out the attacks.
According to the head of the agency, several of the groups linked to Iran now display much better coordination, a higher level of technical knowledge , and greater operational organization than in previous years.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Israel claims to have 'hit' Iran's cyberwarfare headquarters
As he explained, in the past most attacks came from scattered groups that operated relatively independently. However, today there is a greater degree of cooperation and better coordination, which makes detecting and dealing with them much more difficult.
Not every incident is a major attack
Although the number of 4,800 cyber incidents is impressive, experts clarify that not all of them correspond to serious breaches.
A significant percentage concerns automated network scans, login attempts, phishing, low-intensity attacks, and vulnerability testing that are performed daily on almost every connected information system.
This does not diminish the importance of the data. On the contrary, it demonstrates that cyberattacks are now a constant pressure for organizations, which are called upon to manage thousands of suspicious actions every month.
See also: US-Israel and Iran exchange cyberattacks

Cyberwar is taking on a global dimension
The confrontation between Israel and Iran is no longer limited to the Middle East. In recent years, Western security services have repeatedly warned that groups linked to Iran have expanded their activities, targeting organizations and businesses in various countries.
At the same time, many cyberattacks are not only aimed at causing financial damage, but also at gathering information, espionage, spreading disinformation or even disrupting critical services.
The continuous increase in incidents confirms that cyberwar is evolving into one of the most important factors in modern geopolitics. The battles may temporarily stop on the ground, but in digital networks the attacks continue unabated, with increasingly sophisticated techniques and better organized groups turning cyberspace into a permanent battlefield.
