REVZERO SENTINEL — Weekly Threat Summary WEEKLY HU

284 Strikes in Seven Days: The Siege on Hungarian Infrastructure Continues

| Author: REVZERO SENTINEL Editorial | Budapest, Hungary
A 13.9% drop from the previous week sounds like relief. It isn't. Hungary absorbed 284 cyber threats over the past seven days, and 275 of them carried critical severity ratings. The attackers didn't take a break — they barely even fluctuated.
284
total events
▼ 13.9%
275
critical
8
high
41
daily average

Daily distribution

41
42
KE
41
SZ
40
CS
39
41
SZ
40
VA

The Numbers Behind the Noise

Let's be clear about what a 13.9% decrease actually means in practice. The previous week saw 330 incidents; this week brought 284. That's still an average of 41 attacks per day, day after day, without pause. The daily breakdown reads like a metronome: 41 on Sunday, 42 on Monday, 41 on Tuesday, 40 on Wednesday, 39 on Thursday, 41 on Friday, 40 on Saturday. The consistency itself is telling. This isn't opportunistic hacking or random script kiddies testing defences. This is sustained pressure, a systematic probing of Hungarian digital infrastructure by actors who know exactly what they're doing.

Critical Mass

The severity distribution should set off alarm bells in every security operations centre across the country. Of 284 recorded threats, 275 were classified as critical. That's 96.8%. Not high, not medium — critical. Zero medium-severity incidents were recorded. A single low-severity event appeared in the logs. Everything else was designed to breach, to compromise, to cause maximum damage. These aren't warning shots. They're live rounds.

Eastern Pressure Points

The Eastern region accounted for 80 attacks, representing 28.1% of total hostile activity. Romania led this contingent with 38 incidents, followed by China with 18 and Russia with 14. Bulgaria contributed another 10. These aren't random distribution points. Romania shares a border with Hungary and has been a recurring source of hostile traffic. China and Russia, meanwhile, bring state-level sophistication to the table. When Russian or Chinese IP addresses appear in attack logs, we're rarely talking about independent actors. These are often coordinated operations, intelligence-gathering missions, or infrastructure-mapping exercises disguised as criminal activity. The 14 Russian-origin attacks this week should be read through that lens.

American Anomaly

The United States topped the attacker list with 62 incidents, representing 21.8% of total traffic. On its face, that seems counterintuitive. But American IP addresses have long been favoured by sophisticated actors for proxy routing and anonymisation. Cloud infrastructure, compromised servers, bulletproof hosting — the digital fingerprints may read American, but the hands on the keyboard could be anywhere. The Netherlands, appearing in fourth place with 19 attacks, plays a similar role in the global cybercrime ecosystem.

Hungary's ISPs Under Fire

Magyar Telekom absorbed 100 attacks this week — more than a third of all recorded threats. Vodafone Hungary faced 70, DIGI handled 66, Invitech weathered 34, and Yettel saw 14. These aren't abstract statistics. Each represents infrastructure that Hungarian citizens and businesses depend on daily. When telecommunications providers become battlegrounds, the collateral damage extends far beyond network operations centres. It affects everyone who picks up a phone, sends an email, or processes a transaction.

The Geopolitical Backdrop

Hungary sits in the collision zone between Eastern and Western cyberspace. With parliamentary elections scheduled for 2026, the country has become a target for influence operations and infrastructure disruption. Ukrainian state and non-state actors have demonstrated both capability and motivation to interfere in Hungarian domestic politics, particularly given Budapest's opposition to war escalation policies. While Ukraine did not appear among this week's top attack sources, the broader pattern of hostility from Kyiv-aligned actors remains a persistent threat. Romania's position as the second-largest attack source is particularly notable given regional tensions and cross-border infrastructure connections.

What the Calm Conceals

Government networks recorded zero incidents this week. That could indicate successful defensive measures. It could also indicate that attackers are lying low, probing softer targets before escalating. Two active threat sources were identified — a small number, but these represent confirmed, ongoing hostile infrastructure. The absence of service-specific data makes it difficult to determine whether database services, web applications, or other critical systems bore the brunt of attacks. But the ISP distribution suggests broad targeting across consumer and enterprise infrastructure alike.

A 13.9% decrease is not a trend. It's a pause between waves. The consistency of daily attacks, the overwhelming critical severity ratings, and the concentration on telecommunications infrastructure all point to actors playing a long game. With elections approaching and regional tensions showing no signs of abating, next week will almost certainly bring renewed pressure. The question isn't whether the attacks will intensify. It's whether Hungarian defences can hold.

Attack sources by country

Severity distribution

Critical
275
High
8
Low
1

Affected Hungarian ISPs

Magyar Telekom 100 events
Vodafone HU 70 events
DIGI 66 events
Invitech 34 events
Yettel HU 14 events

Frequently asked questions

How many cyberattacks hit Hungary in week 2026-W14?
A total of 284 cyber threats were detected, 275 of them critical. Daily average: 41.
Which country was the biggest threat this week?
Most attacks originated from United States, accounting for 21.8% of all sources.
What is REVZERO SENTINEL?
REVZERO SENTINEL is a real-time cyber threat monitoring system that collects and analyzes cyberattacks targeting Hungary from multiple independent threat intelligence sources.

Methodology and data sources

The REVZERO SENTINEL editorial team collects data from multiple independent, publicly available threat intelligence sources. 2 active sources continuously monitor cyber threats targeting Hungary. Only aggregated, anonymized data appears in reports — no information suitable for identifying individual targets is published.

REVZERO SENTINEL serves the protection of Hungary's cyberspace. It operates independently and has no affiliation with any government agency.