The Gulf region has become a hotbed of increasingly complex cyberattacks, with the United Arab Emirates (UAE) and Kingdom of Saudi Arabia bearing the brunt of the onslaught. In the first half of 2026, these two nations absorbed a staggering 50% of all recorded cyberattacks across the Gulf, according to threat intelligence firm Positive Technologies.
The surge in attacks is not surprising given the region’s aggressive pursuit of digital transformation. The UAE and Saudi Arabia have made significant investments in modernizing their public and private sectors, creating larger attack surfaces that attract the attention of financially motivated cybercriminals. Iran’s media organizations and telecom infrastructure are also popular targets, with many being attacked by hacktivists and politically aligned groups.
Positive Technologies used open-source intelligence (OSINT) gathered from Dark Web forums, Telegram channels, and other aggregators to track cyberattacks in the region. The firm’s analysis reveals that the majority of attacks remain unreported due to concerns over reputational harm. In fact, organizations in the UAE and Saudi Arabia experienced nearly 2,700 attacks per week in the past half-year, compared to about 2,300 attacks per week for a typical organization globally.
The most common type of attack was exploitation of information-disclosure vulnerabilities, impacting 62% of affected organizations. This is not surprising given the widespread use of outdated software and systems in the region. Remote code execution and authentication bypass also featured heavily, indicating that attackers are becoming increasingly sophisticated in their tactics.
Ransomware, botnets, and information-stealing malware have also become more prevalent in the region, with rates higher than global averages. The UAE and Saudi Arabia make up the two strongest economies in the region and were targeted with about half of all cyberattacks – 35% and 15%, respectively.
The types of attackers targeting these nations are varied. While government targets saw over a quarter of all attacks (27%), cross-sector attacks affected nearly the same proportion (23%). The exploitation of vulnerabilities has become the most popular initial access vector, accounting for 38% of all cyberattacks, and more than half of the attacks (58%) led to business disruption.
As a result, highly visible cyberattacks have given way to more hard-to-detect intrusions. Positive Technologies notes that complex, targeted cyberattacks are now replacing simple, technically straightforward attacks like DDoS and website defacements. These advanced threats focus on stealthy infiltration of critical infrastructure, establishing persistence, and data gathering.
In conclusion, the Gulf region’s digital transformation has created a lucrative target for cybercriminals. Organizations in the UAE and Saudi Arabia must prioritize cybersecurity measures to protect themselves against these increasingly complex attacks. This includes ensuring software and systems are up-to-date, implementing robust threat detection and response capabilities, and investing in employee education and awareness programs.
Ultimately, the rapid pace of digital transformation in the region demands a corresponding increase in cybersecurity vigilance. As the threat landscape continues to evolve, organizations must stay one step ahead of attackers by staying informed about emerging threats and best practices for mitigating them.
Source: Dark Reading — 2026-09-23