Verified cyberincident context · Croatia / Nacionalni CERT 2025
Croatia Nacionalni CERT 2025 cybersecurity incident and activity context
Market context — not industry-specific evidence
Croatia Nacionalni CERT report context (Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, published 2026-02-05) states that Nacionalni CERT processed 1,513 cyber incidents in 2025, a 35.9% increase compared with 2024. Incident type shares for 2025: phishing attacks 32%, unwanted messages 19%, other financially motivated fraud 18%, and attacker infrastructure 12% — these four categories are a subset of incident types and do not sum to 100%. Nacionalni CERT recorded 126,098 bots by malicious-content type in 2025, a 33.37% decrease compared with 2024. The CERTiffy system was used to check 37,191 URLs in 2025. These figures apply to Nacionalni CERT processed incidents and activities only and must not be presented as all cyber incidents in Croatia, total Croatian business incident prevalence, or industry-specific evidence.
Cyber incidents processed by Nacionalni CERT — Croatia 2025
- Cyber incidents processed by Nacionalni CERT in 2025
- 1,513
- Unit
- cyber incidents processed by Nacionalni CERT in 2025
- Period
- Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
- Scope
- Croatia Nacionalni CERT 2025 cybersecurity incident context
Includes incidents reported to Nacionalni CERT and incidents detected through Nacionalni CERT's own activities.
Nacionalni CERT 2025 processed cybersecurity incident context only. The 1,513 value refers to incidents reported to Nacionalni CERT or detected through Nacionalni CERT's own activities and must not be presented as all cyber incidents in Croatia or total Croatian business incident prevalence. Not industry-specific evidence.
Year-on-year increase in Nacionalni CERT processed incidents — Croatia 2025
- 35.9% increase in Nacionalni CERT processed cyber incidents in 2025 compared with 2024
- 35.9%
- Unit
- percent increase in cyber incidents processed by Nacionalni CERT in 2025 compared with 2024
- Period
- Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
- Scope
- Croatia Nacionalni CERT 2025 cybersecurity incident context
Nacionalni CERT 2025 processed incident year-on-year change context only. The 35.9% value is a year-on-year change for Nacionalni CERT processed incidents and must not be presented as a measure of all-Croatia cyberattack volume change or total Croatian business incident trend. Not industry-specific evidence.
Nacionalni CERT processed incident type shares — Croatia 2025
- Phishing attacks — 32% of Nacionalni CERT processed incidents in 2025
- 32%
- Unit
- percent of Nacionalni CERT processed incidents in 2025 categorised as phishing attacks
- Period
- Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
- Scope
- Croatia Nacionalni CERT 2025 cybersecurity incident context
- Unwanted messages — 19% of Nacionalni CERT processed incidents in 2025
- 19%
- Unit
- percent of Nacionalni CERT processed incidents in 2025 categorised as unwanted messages
- Period
- Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
- Scope
- Croatia Nacionalni CERT 2025 cybersecurity incident context
- Other financially motivated fraud — 18% of Nacionalni CERT processed incidents in 2025
- 18%
- Unit
- percent of Nacionalni CERT processed incidents in 2025 categorised as other financially motivated fraud
- Period
- Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
- Scope
- Croatia Nacionalni CERT 2025 cybersecurity incident context
- Attacker infrastructure — 12% of Nacionalni CERT processed incidents in 2025
- 12%
- Unit
- percent of Nacionalni CERT processed incidents in 2025 categorised as attacker infrastructure
- Period
- Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
- Scope
- Croatia Nacionalni CERT 2025 cybersecurity incident context
Nacionalni CERT 2025 processed incident type share context only. The 32%, 19%, 18%, and 12% values apply only to Nacionalni CERT processed incidents in 2025 and must not be presented as all-Croatia attack prevalence or all-business attack type prevalence. The four categories shown are a subset of incident types and do not sum to 100%. Not industry-specific evidence.
Bots recorded by malicious-content type — Croatia 2025
- Bots recorded by malicious-content type by Nacionalni CERT in 2025
- 126,098
- Unit
- bots recorded by malicious-content type by Nacionalni CERT in 2025
- Period
- Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
- Scope
- Croatia Nacionalni CERT 2025 cybersecurity incident context
Recorded bots decreased by 33.37% in 2025 compared with 2024. This refers to Nacionalni CERT bot observations by malicious-content type only and must not be presented as proof of reduced Croatian bot threat.
Nacionalni CERT 2025 recorded bot observation context only. The 126,098 value refers to bots recorded by malicious-content type and must not be presented as confirmed compromised organisations, resolved incidents, protected organisations, or proof of protection. Not total Croatian business incident prevalence and not industry-specific evidence.
URLs checked via CERTiffy — Croatia 2025
- URLs checked via the CERTiffy system by Nacionalni CERT in 2025
- 37,191
- Unit
- URLs checked via the CERTiffy system by Nacionalni CERT in 2025
- Period
- Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
- Scope
- Croatia Nacionalni CERT 2025 cybersecurity incident context
CERTiffy is a URL-checking system operated by Nacionalni CERT. The 37,191 value is a count of URL-checking activity only.
Nacionalni CERT 2025 CERTiffy URL-checking activity context only. The 37,191 value refers to URLs checked via the CERTiffy system and must not be presented as confirmed malicious websites, resolved incidents, or protected users. Not total Croatian business incident prevalence and not industry-specific evidence.
Source: Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026
Scope: Nacionalni CERT / CARNET annual report context published 2026-02-05. The 1,513 processed incidents refer only to incidents reported to Nacionalni CERT or detected through Nacionalni CERT's own activities and must not be presented as all cyber incidents in Croatia. The 32%, 19%, 18%, and 12% incident-type shares are a subset of Nacionalni CERT processed incident types and do not sum to 100%; they must not be presented as all-Croatia attack prevalence. The 35.9% is a year-on-year change for Nacionalni CERT processed incidents; must not be presented as a measure of all-Croatia cyberattack volume change. The 126,098 bot observations must not be presented as confirmed compromised organisations, resolved incidents, or proof of protection. The 33.37% bot decrease is an absolute value of a year-on-year change for recorded bots only. The 37,191 URL checks are URL-checking activity context and must not be presented as confirmed malicious websites, resolved incidents, or protected users. These figures do not measure total Croatian business incident prevalence, hidden incident prevalence, population-wide victimisation rates, all-sector incident totals, industry-specific evidence, compliance achievement, certification, or security outcomes.
Methodology: Official Nacionalni CERT / CARNET annual report context published 2026-02-05. The admitted indicators describe Nacionalni CERT 2025 processed cybersecurity incidents (total count and year-on-year change), incident-type shares, recorded bots by malicious-content type, and CERTiffy URL-checking activity. The 1,513 processed incidents refer only to incidents reported to Nacionalni CERT or detected through Nacionalni CERT's own activities and must not be presented as all cyber incidents in Croatia. The 32%, 19%, 18%, and 12% incident-type shares apply only to Nacionalni CERT processed incidents in 2025; they must not be presented as all-Croatia attack prevalence or all-business prevalence. The four category shares shown are a subset of incident types and do not sum to 100%. The 35.9% value is a year-on-year change for Nacionalni CERT processed incidents and must not be presented as a measure of all-Croatia cyberattack volume change. The 126,098 recorded bots are observations by malicious-content type and must not be presented as confirmed compromised organisations, resolved incidents, protected organisations, or proof of protection. The 33.37% bot decrease is an absolute value of a year-on-year change for recorded bots and must not be presented as proof of reduced Croatian bot threat. The 37,191 URL checks via CERTiffy are URL-checking activity and must not be presented as confirmed malicious websites, resolved incidents, or protected users. Do not present any admitted indicator as total Croatian business incident prevalence, hidden incident prevalence, population-wide victimisation rate, all-sector incident rate, all-Croatia cyberattack volume, industry-specific evidence, compliance achievement, certification, proof of security, or guaranteed protection.
Accessible data table
| Metric | Value | Source | Scope | Reporting period |
|---|---|---|---|---|
| Cyber incidents processed by Nacionalni CERT in 2025 | 1,513 cyber incidents processed by Nacionalni CERT in 2025 | Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026 | Croatia Nacionalni CERT 2025 cybersecurity incident context | Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context. |
| 35.9% increase in Nacionalni CERT processed cyber incidents in 2025 compared with 2024 | 35.9% percent increase in cyber incidents processed by Nacionalni CERT in 2025 compared with 2024 | Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026 | Croatia Nacionalni CERT 2025 cybersecurity incident context | Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context. |
| Phishing attacks — 32% of Nacionalni CERT processed incidents in 2025 | 32% percent of Nacionalni CERT processed incidents in 2025 categorised as phishing attacks | Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026 | Croatia Nacionalni CERT 2025 cybersecurity incident context | Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context. |
| Unwanted messages — 19% of Nacionalni CERT processed incidents in 2025 | 19% percent of Nacionalni CERT processed incidents in 2025 categorised as unwanted messages | Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026 | Croatia Nacionalni CERT 2025 cybersecurity incident context | Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context. |
| Other financially motivated fraud — 18% of Nacionalni CERT processed incidents in 2025 | 18% percent of Nacionalni CERT processed incidents in 2025 categorised as other financially motivated fraud | Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026 | Croatia Nacionalni CERT 2025 cybersecurity incident context | Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context. |
| Attacker infrastructure — 12% of Nacionalni CERT processed incidents in 2025 | 12% percent of Nacionalni CERT processed incidents in 2025 categorised as attacker infrastructure | Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026 | Croatia Nacionalni CERT 2025 cybersecurity incident context | Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context. |
| Bots recorded by malicious-content type by Nacionalni CERT in 2025 | 126,098 bots recorded by malicious-content type by Nacionalni CERT in 2025 | Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026 | Croatia Nacionalni CERT 2025 cybersecurity incident context | Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context. |
| URLs checked via the CERTiffy system by Nacionalni CERT in 2025 | 37,191 URLs checked via the CERTiffy system by Nacionalni CERT in 2025 | Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026 | Croatia Nacionalni CERT 2025 cybersecurity incident context | Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context. |
| Croatia Nacionalni CERT report context states that recorded bots decreased by 33.37% in 2025 compared with 2024. The value field stores 33.37 as the absolute value of the percentage decrease. This metric is admitted to records for completeness but must not be charted as a bar; it is referenced in supporting text only. Must not be presented as proof of reduced Croatian bot threat or total Croatian cybersecurity improvement. | 33.37% percent decrease in bots recorded by malicious-content type in 2025 compared with 2024 — absolute value of decrease | Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026 | Croatia Nacionalni CERT 2025 cybersecurity incident context | Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context. |
