Global English
Technology

Ransomware Attacks Surge Across the Gulf as Organised Cyber Criminals Target Middle East Businesses

The NationalSeptember 16, 2026 at 03:36 AM1 views
Ransomware Attacks Surge Across the Gulf as Organised Cyber Criminals Target Middle East Businesses

Disclaimer

This story, titled "Ransomware activity rises across Middle East as criminal groups attack Gulf" First published on The National and was retrieved from its original source on September 16, 2026.

Our site bears no responsibility for its content. You can review the details of this story at its original source.

Ransomware activity across the Middle East has experienced a sharp surge, with organised criminal networks increasingly targeting Gulf businesses and sectors where operational disruption forces victims to pay, according to recent research. Data compiled by cybersecurity firm CloudSEK reveals that tracked ransomware incidents jumped from 17 in April 2025 to 357 in June of this year, highlighting a swift shift in focus toward the region by established criminal enterprises.

“The Gulf states were, until recently, not a primary ransomware target,” said Shashank Shekhar, managing editor at CloudSEK, in an interview with The National. “What our data shows is that changed in 2025, and it changed fast.” Criminal syndicates such as The Gentlemen have compiled databases of compromised network devices to repeatedly assault Saudi businesses, while Nova maintained a focus on the Gulf throughout the entire 17-month reporting window, he added. “These groups are not testing the market. They have committed to it,” Mr Shekhar stated.

The expansion of digital infrastructure throughout Saudi Arabia and the UAE has enlarged the pool of internet-accessible systems available to malicious actors, while unpatched firewalls and virtual private network gateways remain frequent entry points, he explained. Gavin Millard, vice president of intelligence at cybersecurity organisation Tenable, noted that the escalation of ransomware forms part of a broader global pattern. “Cyber crime and the tactics they use really is a borderless activity when it comes to things like ransomware,” Mr Millard told The National, pointing out that attackers often prioritize finding “the easiest and the most profitable victims” over geographical locations.

Israel and Turkey face distinct threat landscapes according to CloudSEK metrics, which recorded the highest overall cyber-threat activity in Israel, followed by Turkey, Iran, the UAE, and Saudi Arabia. These metrics represent threat-intelligence indicators rather than confirmed, successful breaches. Mr Shekhar noted that 37.8 per cent of regional hacktivist actions targeted Israel, alongside persistent Iranian state-backed intelligence operations. Meanwhile, Turkey recorded the region's highest volume of ransomware activity, drawing criminals to its manufacturing, construction, defence, and logistics sectors. “Israel is targeted because of who it is. Turkey is targeted because of what it has,” Mr Shekhar observed.

Critical infrastructure remains especially appealing to ransomware gangs because disruptions affect vital services alongside computer networks. “When the impact is higher, the ransom can also be higher,” Mr Millard explained. “People are going to pay more to restore infrastructure that is population-impacting than just business-impacting.” The severe financial risks were underscored in the UAE when Dr Mohamed Al Kuwaiti, head of the UAE Cyber Security Council, disclosed that a hacker demanded over $5 million after claiming to breach a private enterprise, destroying data and attempting to leak stolen files. UAE authorities collaborated with the affected company to contain the incident and restrict data circulation, Dr Al Kuwaiti confirmed.

Mohamed Belarbi, founder and chief executive of Cypherleak, warned last week that the greater threat lies in accumulated, relatively inexpensive attacks causing localized disruptions and recovery expenses, rather than a single catastrophic shutdown. The UAE has documented a dramatic escalation in cyber threats since the conflict began, with Dr Al Kuwaiti reporting in April that the nation faces approximately 800,000 daily hacking attempts compared to roughly 200,000 prior to hostilities. The council also reported successfully thwarting coordinated operations targeting the nation's aviation, energy, and education sectors in August, following the containment of sophisticated financial sector attacks in July.

While Iranian-linked networks feature prominently in the CloudSEK findings, researchers also tracked operations tied to China and Israel, alongside North Korean and Russia-aligned activities. China-linked entities exploited network equipment vulnerabilities to breach government, telecommunications, and healthcare entities for intelligence gathering, according to Mr Shekhar. “What we see is a genuinely complex picture,” he said, noting that state-sponsored actors pursue varied objectives while international cyber criminals target the region for financial gain.

Artificial intelligence is introducing new dynamics to the threat landscape. CloudSEK reported that the Iran-linked group MuddyWater utilized Google's Gemini to assist in developing attack tools, while APT42 deployed AI to generate convincing phishing campaigns targeting Israeli journalists, defence personnel, and academics. Mr Shekhar pointed out that AI's immediate utility lies primarily in speed and scale, allowing less-experienced operators to build tools and enabling attackers to rapidly craft persuasive phishing messages across multiple languages. However, he emphasized that AI is not autonomously selecting targets or executing attacks without human guidance.

Mr Millard concurred that artificial intelligence amplifies established methodologies rather than inventing entirely novel attack vectors. “AI-enabled attacks aren't novel, and they're not indefensible,” he said. “They're just amplified in scale.” He added that AI lowers technical barriers, allowing a lone actor to achieve the operational capabilities of a state-sponsored group by automating tasks from vulnerability identification to victim selection. To counter these threats, businesses must adopt pragmatic, risk-based strategies. “Compliance is not security,” Mr Millard concluded. “No one can deal with the volume of issues that are being highlighted by these models. You have to take a more pragmatic, risk-based, threat-based approach.”

Share this article: