A high level of economic development, a key role in the global energy sector driven by oil and gas exports, and heavy investments in digital technologies make the Gulf states an attractive target for financially motivated cybercriminals. Additionally, the tense geopolitical climate in the region has led to increased activity from hacktivists and advanced persistent threat (APT) groups.
This report analyzes the cyberthreat landscape in the Gulf states during the first half of 2026. The countries covered include Bahrain, Iraq, Iran, Kuwait, Oman, Qatar, Saudi Arabia, and the United Arab Emirates (UAE).
Objectives of this report:
Describe the cyberthreat landscape in the Gulf states.
Provide forecasts and offer recommendations for defense and mitigation.
To map the cyberthreat landscape in the Middle East, we utilized open-source intelligence (OSINT) combined with dark web data. This included information from six major underground forums, over 20 Telegram channels, and various aggregators tracking website defacements, malware operations (including ransomware), and distributed denial-of-service (DDoS) attacks.
We estimate that most cyberattacks remain undisclosed due to reputational risks. Consequently, determining the exact number of incidents is impossible, even for incident response and threat intelligence organizations.
Our incident database is updated on a rolling basis. However, some incidents may be reported online long after the actual attack took place. Therefore, the data presented in this report is accurate as of the time of publication. For explanations of terms used in this report, please refer to the Positive Technologies glossary.








