REVZERO SENTINEL — Weekly Threat Summary WEEKLY HU

Hungary Under Steady Siege: 290 Critical-Grade Attacks in One Week

| Author: REVZERO SENTINEL Editorial | Budapest, Hungary
A coordinated offensive. That's what the past seven days look like from the vantage point of Hungary's cyber defenders. The numbers don't lie: 290 threats detected between March 16 and 22, with a staggering 280 classified as critical severity. The 9.9% drop from the previous week offers cold comfort when nearly every single attack that penetrated detection was rated at the highest threat level.
290
total events
▼ 9.9%
280
critical
8
high
41
daily average

Daily distribution

41
42
KE
40
SZ
41
CS
42
42
SZ
42
VA

A Siege by the Numbers

The daily pattern tells its own story. Monday through Sunday, the assault never wavered — 41, 42, 40, 41, 42, 42, 42. Day after day, the same relentless rhythm. No spikes, no lulls, no breaks. This isn't opportunistic scanning by bored teenagers. This is sustained, calculated pressure. Someone is probing Hungarian infrastructure with clockwork precision, testing defenses, mapping vulnerabilities, waiting for an opening. The consistency is itself a warning sign. Random attacks fluctuate. Campaigns don't.

The Eastern Front

Twenty-three percent of all detected threats — 67 attacks — originated from what we'll call the Eastern axis: Romania, China, and Russia. China's 21 attacks bear the hallmarks of state-coordinated activity. These aren't lone hackers operating from Shanghai basements. The Chinese state has invested heavily in cyber-offensive capabilities, and APT groups with Beijing's blessing have targeted European infrastructure for years. Hungary's position as an EU member state with close ties to Beijing makes it both a target and a pathway.

Russia's 10 attacks, while smaller in volume, carry their own weight. Moscow's cyber forces have demonstrated their capabilities from Estonia to Ukraine, and Hungary sits squarely in the crosshairs of great power competition. The fact that Romanian sources account for 36 attacks — the second-largest single-country source after the United States — raises uncomfortable questions. Romania is a NATO ally, an EU partner. But compromised Romanian servers are a known vector for attacks on neighboring states. The border between Hungary and Romania isn't just a line on a map — it's a seam in the cyber domain that adversaries know how to exploit.

American Attack Infrastructure

The United States tops the list with 52 attacks, representing nearly 18% of all detected threats. Before anyone jumps to conclusions about Washington's intentions, consider this: American cloud providers, VPN services, and proxy networks are the preferred infrastructure for cybercriminals worldwide. Bulletproof hosting, rented servers, anonymizing services — they all point back to U.S. IP addresses on paper. The attackers aren't necessarily American. They're just using American infrastructure to hide.

Critical Infrastructure in the Crosshairs

Magyar Telekom absorbed 111 attacks this week — more than a third of all detected threats. Vodafone Hungary caught 79, DIGI 49, Invitech 39. These aren't random targets. They're the arteries of Hungary's digital nervous system. Compromise any one of them, and the ripple effects spread across businesses, government services, and ordinary citizens who depend on connectivity for everything from banking to healthcare. The concentration of attacks against telecommunications infrastructure suggests deliberate targeting. Whoever is behind this campaign understands that the fastest way to destabilize a modern society is through its networks.

The Election Shadow

Parliamentary elections loom. Hungary votes in 2026, and the timing is hardly coincidental. Electoral periods are prime season for cyber operations — information warfare, infrastructure disruption, data theft. The fact that no government networks appear in this week's incident data could mean one of two things: either government systems successfully repelled all attacks, or the real operations haven't been detected yet. Neither interpretation is particularly reassuring. Ukrainian state and non-state actors have made no secret of their interest in Hungarian political outcomes. Kyiv's hostility toward Budapest over the war in Ukraine has translated into overt rhetoric and, increasingly, covert digital operations. Ukraine's absence from this week's top attacker list doesn't indicate safety — it indicates sophistication. The most dangerous adversaries know how to cover their tracks.

Two Active Threat Sources

The system identified only two active threat sources this week. Two. Against 290 total attacks. That ratio should terrify anyone responsible for Hungarian cyber defense. It means that a handful of actors — possibly just two coordinated groups — generated nearly three hundred high-severity incidents in seven days. These aren't scattered attempts. They're campaigns. Organized, resourced, and persistent.

The 9.9% weekly decrease is statistical noise, not a trend. The threat level remains at siege proportions. With elections approaching and geopolitical tensions showing no signs of easing, the coming weeks will likely bring more sophisticated operations — not fewer. The adversaries probing Hungarian networks this week were testing defenses. Next week, they may decide they've found a way through.

Attack sources by country

Severity distribution

Critical
280
High
8
Low
2

Affected Hungarian ISPs

Magyar Telekom 111 events
Vodafone HU 79 events
DIGI 49 events
Invitech 39 events
Yettel HU 12 events

Frequently asked questions

How many cyberattacks hit Hungary in week 2026-W12?
A total of 290 cyber threats were detected, 280 of them critical. Daily average: 41.
Which country was the biggest threat this week?
Most attacks originated from United States, accounting for 17.9% of all sources.
What is REVZERO SENTINEL?
REVZERO SENTINEL is a real-time cyber threat monitoring system that collects and analyzes cyberattacks targeting Hungary from multiple independent threat intelligence sources.

Methodology and data sources

The REVZERO SENTINEL editorial team collects data from multiple independent, publicly available threat intelligence sources. 2 active sources continuously monitor cyber threats targeting Hungary. Only aggregated, anonymized data appears in reports — no information suitable for identifying individual targets is published.

REVZERO SENTINEL serves the protection of Hungary's cyberspace. It operates independently and has no affiliation with any government agency.