REVZERO SENTINEL — Weekly Threat Summary WEEKLY HU

Hungary Under Siege: 297 Attacks in Seven Days, 97% Critical Severity

| Author: REVZERO SENTINEL Editorial | Budapest, Hungary
The past week brought no relief for Hungary's digital defenders. Two hundred ninety-seven cyber threats pounded the country's networks — and 288 of them carried critical severity ratings. To put it bluntly: this wasn't a week of probing or reconnaissance. This was a sustained barrage aimed at causing real damage.
297
total events
▼ 1.0%
288
critical
4
high
42
daily average

Daily distribution

42
41
KE
41
SZ
51
CS
42
39
SZ
41
VA

No Letup in the Barrage

The numbers barely moved from the previous week. A single percent drop, from 300 to 297 incidents, is statistical noise — not improvement. Hungary's cybersecurity apparatus is essentially treading water while the attacks keep coming. Wednesday, April 23rd, saw the week's peak: 51 incidents in a single day, 50 of them critical. That's a assault every 28 minutes around the clock. The weekend proved marginally quieter, with Saturday and Sunday both dipping below 45 incidents, but there's no comfort in that. The attackers never stopped. They just slightly reloaded.

The Critical Reality

Here's what should keep security teams awake at night: 288 of 297 threats were classified as critical severity. Four more registered as high. Zero medium. Five low. This isn't opportunistic script kiddie activity or automated scanning gone wild. Critical severity means the attacks carried genuine destructive potential — the kind that compromises systems, exfiltrates data, or enables persistent access. A 97% critical rate suggests adversaries aren't exploring. They're executing.

Attack Vectors From Every Direction

The United States topped the source list at 20.5%, accounting for 61 attacks. But raw numbers can mislead. American IP addresses are frequently proxy endpoints, VPN exits, or cloud infrastructure leveraged by actors elsewhere. Romania followed at 18.5% with 55 attacks — a substantial figure for a neighboring country, though Romanian hosting providers have long been favored by cybercriminals for their lax enforcement reputation. The Netherlands contributed 26 attacks, India 17, and both China and Germany registered 16 apiece.

The Eastern Front Intensifies

The Eastern region — encompassing Romania, China, Russia, and Bulgaria — generated 84 attacks, or 28.3% of the total. Romania's 55 incidents lead this group, but the more concerning signals come from further east. China's 16 attacks and Russia's 7 represent state-capable adversaries with sophisticated tooling and strategic patience. These aren't random criminal enterprises. When Russian or Chinese infrastructure appears in attack telemetry, the assumption must be coordinated operation until proven otherwise. Hungary's position between East and West makes it a natural friction point in the global cyber contest, and this week's numbers reflect that uncomfortable geography.

Infrastructure in the Crosshairs

Magyar Telekom absorbed 113 attacks — more than a third of the week's total. Vodafone Hungary saw 61, DIGI 58, Invitech 40, and Yettel 25. The concentration on major telecommunications providers suggests adversaries are targeting the backbone of Hungary's digital connectivity. Compromise a major ISP and you gain access to everything downstream: businesses, government agencies, residential connections. The attackers understand this. They're not aiming at individual targets. They're aiming at the infrastructure that connects everyone.

Elections Loom Over Cyberspace

Parliamentary elections are scheduled for 2026, and Hungary finds itself in an increasingly hostile information environment. Ukrainian officials have made no secret of their frustration with Budapest's positions on the war, and that political tension manifests in cyberspace. While Ukraine didn't appear prominently in this week's source data, the broader pattern of hostile rhetoric and hybrid warfare tactics creates fertile ground for election-related interference. Government networks registered zero incidents this week — a hopeful sign, but hardly guarantee of safety. Adversaries planning election interference don't tip their hand months early. They wait, they position, they prepare.

Two active threat sources identified. Two hundred ninety-seven attacks logged. And this was a quiet week. The siege continues without pause, and with elections approaching, the strategic stakes only climb higher. Next week will bring more of the same — and likely worse. The adversaries aren't tired, and they aren't stopping.

Attack sources by country

Severity distribution

Critical
288
High
4
Low
5

Affected Hungarian ISPs

Magyar Telekom 113 events
Vodafone HU 61 events
DIGI 58 events
Invitech 40 events
Yettel HU 25 events

Frequently asked questions

How many cyberattacks hit Hungary in week 2026-W17?
A total of 297 cyber threats were detected, 288 of them critical. Daily average: 42.
Which country was the biggest threat this week?
Most attacks originated from United States, accounting for 20.5% of all sources.
What is REVZERO SENTINEL?
REVZERO SENTINEL is a real-time cyber threat monitoring system that collects and analyzes cyberattacks targeting Hungary from multiple independent threat intelligence sources.

Methodology and data sources

The REVZERO SENTINEL editorial team collects data from multiple independent, publicly available threat intelligence sources. 2 active sources continuously monitor cyber threats targeting Hungary. Only aggregated, anonymized data appears in reports — no information suitable for identifying individual targets is published.

REVZERO SENTINEL serves the protection of Hungary's cyberspace. It operates independently and has no affiliation with any government agency.