Transparent Edge, a Spanish cybersecurity and web performance company, has published the first edition of its Report on Cyber ​​Threats and Attacks on the Web Vector, a semiannual analysis based on its own data from a network that supports more than 20,000 sites and applications. The study, corresponding to the period between January and June of this year, concludes that attacks blocked by WAF have grown by 31.6% compared to the same semester of the previous year, with an increase of close to 38% in the density of malicious traffic for every million requests served.

“This means that the traffic that passes through the network today concentrates more attack attempts than a year ago. And the attackers have become more efficient: they automate more, test more and learn faster,” explained Natividad Gutiérrez, Head of Data Science at Transparent Edge.

On February 16, the night of #OpSpain

Although the progression of attacks grows almost linearly throughout the semester, there is a date on which a great deal of malicious activity is concentrated. On Monday, February 16, Transparent Edge blocked 2.24 million attacks in 24 hours, 3.7 times the daily median for the period.

The day coincided with the coordinated denial of service campaign #OpSpain, attributed to the pro-Russian group NoName057(16) and supported by groups such as Z-Pentest Alliance, Dark Storm Team and Server Killers. Threat intelligence sources that monitor the group’s own Telegram channel provide precise figures of the episode with more than 8,000 attack entries against one and a half hundred unique domains. The date also coincided with the official proclamation of candidacies for the elections to the Cortes of Castilla y León.

Media and public sector account for 75% of attacks

The report confirms that media and public administrations account for more than 75% of the attacks blocked on the network. But the most significant data appears below, in hitherto secondary sectors: technology and telecommunications multiplies its blocked attacks almost tenfold compared to the first half of 2025, manufacturing and industrial services doubles them (+136%) and health and pharmaceuticals almost doubles its figures (+95%).

Attackers have become more efficient: they automate more, test more and learn faster

In the words of the head of Data Science at Transparent Edge, “what makes the difference this semester is that the B2B sectors (technology, manufacturing and health) are growing in pressure much faster than the traditional ones. It is the clearest sign that the threat map is being redrawn in real time.”

Attack predictions for the second half

Applying the seasonal pattern observed in 2025 to the baseline for the first half of 2026, Transparent Edge’s projection estimates that August could double the annual average of attacks and October could multiply it by 1.73. The first half baseline is already 32% above the equivalent months of last year. The company recommends security teams reinforce guards in August and in the second half of October, and anticipate hacktivist campaigns coinciding with geopolitical and electoral milestones.

The complete report, with the methodology, month-by-month evolution, analysis by sector and the projections section, is available for download on the Transparent Edge website.