Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Cloudflare’s 2026 Project Galileo report shows that media organizations were the most frequently targeted category among the civil-society groups it protects. Journalism outlets represented 22.7% of Project Galileo participants but accounted for 40.5% of malicious traffic. Journalists working in exile faced an even higher risk: Cloudflare says nearly 5% of requests to journalism-in-exile websites were malicious, almost four times the rate for journalism organizations overall.

That does not prove that every newsroom worldwide is experiencing a universal increase in attacks. The findings come from Cloudflare’s network telemetry for organizations protected through Project Galileo, not a global census. The strongest conclusion is narrower and more useful: journalism organizations in this protected population are disproportionately exposed to sustained DDoS attacks, website-exploitation attempts, phishing and, in some countries, government-directed Internet disruption.

What Cloudflare measured

Project Galileo is Cloudflare’s free cybersecurity program for eligible public-interest organizations, including journalism outlets, human-rights groups, civil-society organizations and democracy advocates. Cloudflare’s 2026 report covers more than 3,400 domains belonging to organizations in 120 countries.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The figures reflect traffic that reached or passed through Cloudflare’s network. They are not a count of all attacks against journalists. The sample is shaped by which organizations qualify for, apply to and receive Project Galileo protection. Cloudflare also processes more than 20% of global Internet traffic, but that does not make this report a worldwide survey of newsrooms.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

There is another important distinction: a malicious request blocked by Cloudflare is evidence of hostile activity, not proof of a successful breach. A blocked request may represent probing, automated abuse or an attempted attack that never reached the target application. The report’s numbers should therefore be read as observed and mitigated attack traffic, not confirmed intrusions or stolen data.

The headline disparity

Media organizations received 40.5% of the malicious traffic recorded across the Project Galileo population while accounting for just 22.7% of participating organizations. Cloudflare says it blocked a malicious request probing a media organization approximately every seven seconds, on average.

The report also says that civil-society organizations faced website-vulnerability exploitation attempts at a rate more than seven times higher than other Cloudflare customers. Nearly 10% of email processed for civil-society organizations contained potential phishing material. Almost one-third of malicious emails bypassed standard authentication checks but were detected by more advanced phishing-detection tools.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These statistics describe Cloudflare-processed traffic and email. They should not be converted into claims that 40.5% of media organizations were breached, or that journalists everywhere face the same attack rate.

Four different threats are involved

1. Application-layer DDoS attacks

Application-layer distributed denial-of-service attacks were the largest category in the report. Cloudflare recorded 31.43 billion such malicious requests out of 38.5 billion malicious requests overall, or 81.7%.

These attacks send large volumes of apparently valid requests to pages, applications or APIs. Their goal is to exhaust server, database or application resources and make a site slow or unavailable. Unlike a data breach, a DDoS attack is primarily an availability attack. It may not steal information or compromise a newsroom’s internal systems.

Availability is nevertheless central to journalism. Taking a small outlet offline can prevent readers from accessing an investigation, interrupt donations, block a tip form, disrupt advertising or subscription revenue and make it harder for reporters to communicate with sources.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Cloudflare says most application-layer attacks against its broader customer base ended within 10 minutes, while the largest attacks against civil-society organizations often lasted much longer—sometimes days or weeks. A prolonged campaign can turn a technical outage into a form of operational pressure, even when no account or database is compromised.

2. Website-vulnerability exploitation

Cloudflare says media groups accounted for 40.5% of the 7.1 billion vulnerability-exploitation attempts it mitigated, despite representing 22.7% of Project Galileo participants.

These attempts probe outdated, misconfigured or vulnerable software for a route into a website or connected system. Targets can include a content-management system, plugins, themes, APIs, administrative interfaces, staging servers and exposed services.

The difference from DDoS matters. A DDoS campaign tries to disrupt availability; exploitation attempts may seek unauthorized access, data theft, persistence, defacement or movement into other systems. A newsroom can remain online and appear normal while attackers probe its CMS or administrator login.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Phishing and account takeover

Phishing attacks target people and identities rather than only public infrastructure. For journalists, a convincing message can lead to the theft of email or cloud credentials, installation of malware, creation of malicious forwarding rules or takeover of an account used to impersonate an editor or reporter.

A compromised account can expose confidential source communications, unpublished drafts, calendars, contact lists and internal discussions. Attackers may also use a trusted mailbox to send convincing messages to colleagues, sources or partner organizations.

Cloudflare’s email statistics apply to email it processed for covered civil-society organizations. They are not a measurement of all phishing aimed at journalists globally.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

4. Internet shutdowns and blocking

Cyberattacks are not the only way journalism can be disrupted online. Cloudflare identified 183 Internet disruptions, with public reporting attributing 85 to government action. The report connects disruptions with elections, protests and other politically sensitive periods.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Shutdowns, throttling and blocking can overlap with hostile cyber activity. An outlet may face a DDoS campaign while its website is blocked domestically, or may need to keep operating for readers in a country where authorities are restricting access. The technical effects can look similar to an outage even when the cause is censorship or network interference.

Why journalists are attractive targets

Journalism combines several characteristics that make it strategically important to attackers:

  • Political sensitivity: Investigations can embarrass governments, armed groups, corporations or powerful individuals.
  • Audience reach: Disrupting a prominent outlet can prevent large audiences from seeing information at a politically important moment.
  • Valuable communications: Email and cloud accounts can reveal sources, unpublished material, editorial plans and contact networks.
  • Operational pressure: Harassment, outages and repeated attacks can raise costs and exhaust a small newsroom.
  • Criminal opportunity: Public websites, old plugins and poorly protected accounts can be exploited opportunistically, without a political motive.

Cloudflare warns that successful intrusions can expose confidential-source identities or activists’ locations, potentially enabling surveillance, prosecution or targeted violence. That risk is serious, but individual incidents should not automatically be attributed to a government or political actor. Attack traffic can be proxied, distributed through compromised infrastructure or deliberately designed to obscure its origin.

Why outlets in exile face special exposure

Journalists in exile often continue serving audiences inside the country they left. Their websites may be one of the few remaining channels for independent information, particularly when domestic authorities block their reporting.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare says nearly 5% of requests to journalism-in-exile websites were malicious—almost four times the rate for journalism organizations overall. Exiled outlets may be especially visible, politically consequential and vulnerable because their staff operate across jurisdictions with limited legal protection. Their public website may also be their main distribution channel, making availability attacks unusually effective.

The report highlights elTOQUE, a Cuban outlet operated by journalists in exile, and The Moscow Times, which operates from exile after being designated “undesirable” in Russia. Cloudflare’s figures show how attacks against these organizations can target not only infrastructure but also the public’s ability to access reporting.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Three examples from the report

elTOQUE

Cloudflare says a December 2025 attack against elTOQUE involved nearly 426.8 million malicious requests and peaked at 108,167 requests per second. The site was also blocked in Cuba during the same month.

elTOQUE believed the attack was connected to its currency-comparison tool. That is the outlet’s reported belief, not an independently established attribution in Cloudflare’s report. The case illustrates how a targeted feature can become a pressure point when a newsroom provides information that authorities or other actors would prefer to suppress.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Moscow Times

Cloudflare describes a July 2025 DDoS attack against The Moscow Times involving approximately 123.4 million malicious requests, with a peak of 319,000 requests per second. The incident demonstrates the scale that an availability attack can reach without establishing that attackers successfully accessed internal systems.

China Digital Times

Cloudflare says China Digital Times, a U.S.-based outlet, introduced a security rule that blocked nearly 21,000 suspicious requests in one day. This example shows the value of defensive controls that stop targeted probing before it becomes a visible outage. It also highlights a trade-off: aggressive rules can accidentally block legitimate readers, search crawlers, accessibility tools or sources using privacy networks.

What the report does—and does not—prove

The report supports a strong claim about disproportionate targeting within Project Galileo’s protected population. It does not establish that every journalist or newsroom is experiencing a year-over-year surge, nor does it prove that governments directed the attacks.

  • Selection bias: Project Galileo protects organizations already identified as vulnerable or important by Cloudflare and its partners.
  • Partial visibility: Cloudflare sees traffic handled by its network, not attacks occurring entirely elsewhere.
  • Mitigation is not compromise: Blocked requests and alerts are different from confirmed unauthorized access.
  • Attribution is difficult: Attackers can use proxies, spoofed infrastructure and botnets.
  • Campaigns overlap: One operation may involve DDoS, vulnerability probing, phishing, harassment and censorship.

The practical conclusion is not that every cyberattack on a journalist has the same motive. It is that online availability, account security and source protection have become part of press-freedom infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What small newsrooms should do

No CDN or security vendor replaces basic security practice. A small newsroom should build layered defenses around its public website, identities, devices, sources and recovery process.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Protect the public website

  • Place the site behind a reputable reverse proxy or CDN with DDoS mitigation.
  • Enable a web application firewall and rate limits for logins, searches, comments and APIs.
  • Patch the CMS, plugins, themes, libraries and server software promptly.
  • Remove unused plugins, administrator accounts and exposed services.
  • Protect hosting, DNS, registrar, CMS, email and publishing accounts with multifactor authentication.
  • Maintain offline or separately hosted backups. Backups connected to the same identity system as production may be encrypted or deleted by the same attacker.
  • Monitor DNS changes, administrator logins, origin-IP exposure and unusual traffic.

A common deployment mistake is to put a site behind a mitigation service while leaving the origin server’s IP address publicly exposed. Attackers can then bypass the proxy and attack the origin directly. DNS and registrar access also need stronger protection than a password alone.

Secure email and identities

  • Use phishing-resistant MFA, such as security keys or passkeys, where possible.
  • Configure SPF, DKIM and DMARC for newsroom domains.
  • Separate public tip-line accounts from internal editorial accounts.
  • Review mailbox forwarding rules and third-party OAuth access regularly.
  • Use a password manager and unique credentials for every service.
  • Verify urgent payment, password-reset or document-sharing requests through a second channel.
  • Document account recovery so the newsroom does not depend on one person’s phone or inbox.

MFA significantly reduces many credential attacks, but it is not absolute protection. Attackers may steal an active session cookie, compromise a trusted partner or target the endpoint on which a journalist is already signed in.

Protect sources and sensitive material

  • Collect and retain as little identifying information as the work requires.
  • Do not store source identities in ordinary shared drives or long email threads unless necessary.
  • Encrypt sensitive files and devices.
  • Establish a secure channel for source communications and train staff to use it correctly.
  • Set retention and deletion rules for drafts, contact details and metadata.
  • Assume a compromised journalist account could expose contact graphs, calendars and unpublished work—not only message contents.

A secure tip line is only as strong as the devices and operational habits of the journalists and sources using it. Encryption cannot eliminate metadata, endpoint compromise or coercion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prepare an incident playbook

Before an incident, decide who can take the website offline, preserve evidence, rotate credentials and notify outside organizations. The plan should cover:

  1. Website outage or sustained DDoS.
  2. Suspected CMS compromise.
  3. Stolen email credentials or suspicious forwarding rules.
  4. Malware on a reporter’s device.
  5. Doxxing, harassment or threats.
  6. Possible source exposure.
  7. Government blocking or regional Internet shutdown.

Specify where emergency communications will move if email is compromised, how evidence will be preserved, which backups are trusted and when to contact legal counsel, a national computer emergency response team, law enforcement, funders or a digital-security nonprofit.

Free support for eligible organizations

Eligible public-interest organizations can apply for Project Galileo, which Cloudflare describes as free protection for vulnerable journalism, civil-society, human-rights and democracy organizations. The program includes services such as DDoS mitigation, DNS, SSL, CDN, WAF and selected access and security tools, subject to eligibility and approval requirements.

Project Galileo is not an automatic entitlement for every independent newsroom, and it does not replace patching, endpoint security, email protection, backups or source-protection procedures. Organizations that are not eligible may consider a basic CDN and DDoS service, but should check current feature limits and ensure that the deployment does not expose the origin server or create a single point of failure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare also announced free Bot Management and AI Crawl Control for participating Project Galileo journalists and nonprofits. Those tools can help manage automated traffic and content-access policies, but they do not solve account takeover, malware, CMS compromise or confidential-source risks.

Bottom line

Cloudflare’s 2026 data does not prove a universal global surge affecting every journalist. It does show that, among the organizations protected through Project Galileo, journalism outlets were disproportionately targeted: 40.5% of malicious traffic against 22.7% of participants, with journalists in exile facing nearly four times the malicious-traffic rate of journalism organizations overall.

The threat is broader than DDoS. Long-running availability attacks, CMS exploitation, phishing, account takeover and Internet shutdowns can reinforce one another. For newsrooms, cybersecurity is therefore not merely an IT expense. It is part of keeping reporting available, protecting sources and preserving the ability to publish when powerful actors would prefer silence.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.