Cyberthreats/Incidents

Cyberthreats to the Gulf states in H1 2026

Darya Lavrova

Darya Lavrova

Lead Analyst, International Analytics Group, PT Cyber Analytics

About the report

A high level of economic development, a key role in the global energy sector driven by oil and gas exports, and heavy investments in digital technologies make the Gulf states an attractive target for financially motivated cybercriminals. Additionally, the tense geopolitical climate in the region has led to increased activity from hacktivists and advanced persistent threat (APT) groups.

This report analyzes the cyberthreat landscape in the Gulf states during the first half of 2026. The countries covered include Bahrain, Iraq, Iran, Kuwait, Oman, Qatar, Saudi Arabia, and the United Arab Emirates (UAE).

Objectives of this report:

  • Describe the cyberthreat landscape in the Gulf states.

  • Provide forecasts and offer recommendations for defense and mitigation.

To map the cyberthreat landscape in the Middle East, we utilized open-source intelligence (OSINT) combined with dark web data. This included information from six major underground forums, over 20 Telegram channels, and various aggregators tracking website defacements, malware operations (including ransomware), and distributed denial-of-service (DDoS) attacks.

We estimate that most cyberattacks remain undisclosed due to reputational risks. Consequently, determining the exact number of incidents is impossible, even for incident response and threat intelligence organizations.

Our incident database is updated on a rolling basis. However, some incidents may be reported online long after the actual attack took place. Therefore, the data presented in this report is accurate as of the time of publication. For explanations of terms used in this report, please refer to the Positive Technologies glossary.

Summary

  1. The conflict surrounding Iran continues to impact the cyberthreat landscape. However, the proportion of DDoS attacks, which peaked during the acute phase of the conflict due to hacktivist activity, has noticeably declined. This decrease is partly linked to ceasefires, meaning a resumption of hostilities could trigger a new wave of DDoS attacks.

  2. The cyberthreat landscape indicates that various types of threat actors are active in the region, including financially motivated cybercriminals, hacktivists, and state-aligned groups.

  3. Countries with the strongest economies remain the primary targets for cybercriminals. The UAE and Saudi Arabia ranked among the top three most targeted countries during the reviewed period, taking first and third places and accounting for 35% and 15% of all incidents, respectively.

  4. Cybercriminal focus on Iran remains high. The country accounted for 17% of all incidents in the region, making it the second most targeted nation.

  5. The region sees a high percentage of cross-industry cyberattacks, which account for 23% of the total. This is slightly behind the leading sector, government institutions (27%), and 10 percentage points ahead of industrial organizations (17%). This trend may indicate mass-scale hacktivist campaigns or widespread scanning of regional infrastructure to build botnets.

  6. Vulnerability exploitation is the most common initial access vector, accounting for 38% of all cyberattacks. This can be attributed to the prevalence of legacy systems and weak credentials in the region, as well as the relative ease of exploiting vulnerabilities due to the availability of automated scanners and the regular publication of proof-of-concept (PoC) exploits by threat actors.

  7. The impact of cyberattacks in the region further confirms the presence of diverse threat actor categories. The combined activity of hacktivists and ransomware groups has resulted in business disruption being the most common consequence (58%). Additionally, a significant proportion of incidents (46%) resulted in data breaches, a typical outcome of cyberattacks conducted by both state-aligned actors and ransomware groups.

  8. Forecasts regarding the future cyberthreat landscape heavily depend on how the regional conflict evolves. Regardless of the scenario, we expect an increase in AI-driven cyberattacks and the emergence of new, powerful botnets.

Gulf states as a major target for cybercriminals

The Gulf states attract various types of threat actors due to their highly developed economies, advanced digital infrastructure, and complex geopolitical dynamics. 

Figure 1. Threat actors targeting Gulf states
Figure 1. Threat actors targeting Gulf states

1. The interest of financially motivated cybercriminals in the region is driven by the following factors: 

  • The substantial oil and gas export revenues of most Persian Gulf nations. Currently, Saudi Arabia ranks third globally in oil production, while Iraq, the UAE, Iran, and Kuwait are among the top 10 oil-producing countries. Additionally, Iran ranks third globally in gas production, with Qatar and Saudi Arabia also in the top 10.

  • A high likelihood of ransom payouts to ransomware groups. This is due to a high concentration of critical infrastructure facilities that significantly contribute to the GDP of the Gulf states, such as oil refineries and desalination plants. The probability of payment is elevated by the urgent need to restore compromised critical infrastructure as quickly as possible.

  • The lack of current legislation in these countries regulating how companies should respond to ransomware incidents. The likelihood of successful extortion is further compounded by the region's currently low adoption of cyberinsurance. According to an analytical report by IMARC, the Gulf cyberinsurance market was valued at $327.97 million in 2025, whereas the global market reached $16.3 billion, indicating that the Gulf accounts for a marginal share of approximately 2%.

  • The rapid digital transformation of the financial sector. This allows cybercriminals to gain direct access to financial assets by targeting digital banking systems, cryptocurrency wallets, crypto payment gateways, and similar platforms.

2. For hacktivists seeking maximum visibility for their campaigns, the geopolitical conflict surrounding Iran presents a significant point of interest. They often use real-world events during the conflict as a pretext for public statements, which are typically accompanied by highly visible yet technically simple cyberattacks, such as DDoS and website defacements.

3. The prolonged conflict surrounding Iran, which has also impacted other Gulf states, drives the reconnaissance operations of state-aligned groups. These actors aim to gather intelligence on critical infrastructure to facilitate rapid cyberattacks in the event of further escalation. Their interest is also fueled by the region's shift toward high-tech industries, including biotechnology, quantum computing, and nuclear energy. Industrial espionage can provide foreign nations with leverage for economic pressure and enable the unauthorized acquisition of emerging technologies and know-how.

The strong interest of various threat actor categories in launching cyberattacks against the Gulf states inevitably shapes the region's cyberthreat landscape.

Cyberthreat landscape in the Gulf states

Geopolitical tensions surrounding Iran have persisted for an extended period. While Q1 was marked by active hostilities, Q2 experienced a temporary truce (from April 8 to 21). This dynamic partly explains the distribution of cyberincidents over the first half of the year: the vast majority (96%) occurred in Q1, with only 4% recorded in Q2. Additionally, the following factors likely contributed to the decline in incidents during Q2:

  1. Several countries have adapted to cyberthreats and improved their defensive capabilities. For instance, UAE authorities have invested heavily in strengthening the cybersecurity posture of both public and private sectors, regularly reporting on successfully thwarted cyberattacks. In July 2026, the UAE Cybersecurity Council announced that it had prevented a series of cyberattacks targeting financial organizations. These attacks involved attempts to breach digital systems and critical technology infrastructure, sophisticated phishing campaigns, vulnerability exploitation, and malware distribution.
    Furthermore, the Abu Dhabi Emergencies, Crises and Disasters Management Centre released the "Cybersecurity Awareness Guide During Crises." This initiative helps bolster cyberdefenses not just in the UAE, but across other Gulf states as well.
  2. Hacktivist activity decreased significantly due to the de-escalation of the conflict. The lack of major geopolitical developments likely reduced this threat actor group's interest in the Gulf states. Because hacktivist campaigns are typically massive and high-volume (between H1 2025 and Q1 2026, DDoS attacks, which are a hallmark of hacktivism, accounted for 42% of all incidents), a drop in their activity led to a noticeable decrease in overall Q2 incident numbers.
  3. A significant portion of cyberattacks remains undetected due to a shift in their nature. Highly visible and technically simple cyberattacks, such as DDoS and website defacements, have been replaced by complex, targeted cyberattacks. These advanced threats focus on stealthy infiltration of critical infrastructure, establishing persistence, and data gathering. The intelligence collected during these reconnaissance operations could be used to rapidly disable critical information infrastructure (CII) in the event of further conflict escalation.

The top three most targeted Gulf states highlight the ongoing operations of both financially and politically motivated threat actors in the region. The UAE ranked first, accounting for 35% of successful cyberattacks in the region, followed by Iran (17%) and Saudi Arabia (15%). The high volume of cyberattacks targeting the UAE and Saudi Arabia is largely driven by their advanced economies and the rapid digital transformation across various industries.

Figure 2. Most targeted Gulf states in H1 2026

Breakdown by sector

The distribution of cyberthreats across sectors also indicates the simultaneous activity of various types of threat actors in the region.

Figure 3. Distribution of targeted sectors in H1 2026

Government agencies accounted for 27% of successful cyberattacks, as they attract the attention of both financially motivated cybercriminals and hacktivists. In half (50%) of the cases, cyberattacks on government institutions resulted in the disruption of core operations, which is typical for hacktivists. Meanwhile, 39% of the incidents led to confidential data leaks, suggesting the concurrent interest of politically motivated APT groups and ransomware operators.

Dark web data confirms the activity of all three types of threat actors targeting government agencies in the region:

1. Hacktivist activity. Examples of hacktivist cyberattacks include DDoS attacks on a Bahraini government portal (attributed to the Indian hacktivist group Garuda Eye), five Qatari ministries (by the Keymous+ hacktivist group), and various government institutions in Kuwait (by the 313 Team). These incidents caused temporary outages of the organizations' resources.

Figure 4. Garuda Eye group's post about the DDoS attack on the Bahraini government
Figure 4. Garuda Eye group's post about the DDoS attack on the Bahraini government
Figure 5. Keymous+ group's statement  regarding DDoS attacks on Qatari ministries
Figure 5. Keymous+ group's statement regarding DDoS attacks on Qatari ministries
Figure 6. 313 Team group's statement regarding DDoS attacks on Kuwaiti government agencies
Figure 6. 313 Team group's statement regarding DDoS attacks on Kuwaiti government agencies

2. State-aligned APT group activity. Their operations are characterized by the use of more sophisticated attack vectors. For instance, the Mobir Team (Mobir) compromised the network of a UAE government agency, disrupted its services, and gained access to internal monitoring systems. Infiltrating the organization's infrastructure allows the threat actors to establish covert persistence for intelligence gathering. It also enables them to maintain control over internal systems, allowing them to launch further destructive attacks in the event of an escalating conflict.

 3. Financially motivated cybercriminal activity. Financially driven threat actors sell network access and databases, with prices ranging from $300 to $80,000, depending on the value of the compromised resource and the volume of data. Purchased access can provide attackers with unauthorized entry into a victim organization's infrastructure, while stolen databases can be leveraged for targeted attacks against the public.

For example, root-level RCE and shell access to a firewalled Linux host belonging to a Saudi Arabian ministry were observed being sold on the dark web for $300.

Figure 7. Dark web listing selling access to a Saudi Arabian ministry
Figure 7. Dark web listing selling access to a Saudi Arabian ministry

A 1.9 GB database containing the records of Iranian military personnel is priced at $25,000. It includes sensitive details such as full names, job titles, national identification numbers, addresses, and personal photos.

Figure 8. Dark web listing selling a database of Iranian military personnel
Figure 8. Dark web listing selling a database of Iranian military personnel

For $80,000, threat actors are offering the data of members of an Iranian state-run religious institution on the dark web. The dump comprises 168 million records spanning from 1984 to 2024. The database contains a massive amount of personally identifiable information (PII). This includes personal details (first and last names, year and place of birth, ID number, national code/SSN, national ID serial number, marital status, and occupation), contact information (home and work addresses, postal codes, and landline or mobile phone numbers), passport data (passport numbers, issue and expiration dates, along with scanned copies of the passports), personal photos, banking and payment details, and information indicating whether the person is a mullah, among other data.

Figure 9. Dark web listing selling a database of members of an Iranian state-run religious institution
Figure 9. Dark web listing selling a database of members of an Iranian state-run religious institution

Thus, for the most frequently targeted category (government agencies), intelligence from both open sources and the dark web confirms the presence of all types of threat actors operating in the region.

Cross-industry cyberattacks ranked second, accounting for 23% of incidents, with 73% of these resulting in damage to national interests. This category was primarily driven by cyberattacks that compromised CCTV cameras in Bahrain, Qatar, Kuwait, and the UAE. Such activities undermine national security because they can facilitate sabotage against infrastructure and specific demographic groups within these countries. Furthermore, these attacks were not limited to a single nation but were spread across the region: 27% of successful cross-industry attacks targeted organizations in the UAE, while Bahrain, Qatar, and Kuwait each accounted for 18%.

Industrial organizations rounded out the top three, accounting for 17% of the attacks. This sector also attracts interest from both financially motivated cybercriminals and state-aligned APT groups. Half (50%) of these cyberattacks targeted industrial facilities in Saudi Arabia. For instance, a company providing drilling and production services to the oil and gas industry was compromised by a ransomware group. Another threat actor exfiltrated over 400 GB of sensitive data from a leading Saudi energy company focused on renewable energy, water supply, and power storage projects. The operations of these targeted entities are of critical national importance, which suggests that these were highly targeted cyberattacks orchestrated by sophisticated state-aligned actors.

Threat actors profit financially from cyberattacks on industrial facilities through both ransomware deployments and the sale of initial access. For example, super administrator access to the SCADA system of a major Iranian industrial and construction company is being sold for 2 BTC (approximately $128,000).

Figure 10. Dark web listing selling access to the SCADA system of an Iranian industrial and construction company
Figure 10. Dark web listing selling access to the SCADA system of an Iranian industrial and construction company

Regarding state-aligned cyberattacks on the industrial sector, we observed the activity of the Nasir Security group (suspected to be affiliated with Iran) targeting energy companies in the Gulf states (the UAE, Saudi Arabia, and Oman). The group conducts supply chain attacks by compromising companies that provide engineering, construction, and security services. It steals schematics, contracts, and risk assessment reports. This activity may be a preparatory phase for future attacks on oil pipeline infrastructure.

Cyberattack methods and targets

According to Positive Technologies, the top three cyberattack methods in the Gulf states align with global trends. However, malware deployment did not take the lead in this region (ranking second at 31%); instead, vulnerability exploitation was the most common method (38%), followed by social engineering in third place (27%).

Figure 12. Distribution of cyberattack methods targeting organizations in the Gulf states

Attacks involving vulnerability exploitation were distributed relatively evenly across the region: the UAE accounted for 22% of these attacks, while Iran, Qatar, and Kuwait each accounted for 17%, and the remaining countries made up a combined 27%. This suggests that many facilities in the Gulf states still rely on legacy SCADA systems with limited security capabilities.

Furthermore, the high percentage of cyberattacks leveraging vulnerability exploitation can be attributed to their relative ease of execution, which is driven by the following factors:

  • The rapid publication of proof-of-concept (PoC) exploits: according to 2025 data, nearly a third (28%) of recorded vulnerability exploitation incidents occurred within 24 hours of discovery. In several cases, a PoC exploit was published on GitHub or hacker forums just hours after a CVE was issued, providing less skilled threat actors with a ready-to-use toolkit.

  • The use of easily guessable or default credentials: to carry out these attacks, threat actors can employ large-scale automated brute-force techniques that do not require advanced technical skills.

  • The prevalence of "classic" web vulnerabilities: cross-site scripting (XSS) and SQL injection (SQLi) were the most common vulnerability types in CVEs based on 2025 data. Exploiting these flaws generally requires minimal effort from threat actors due to the wide availability of automated scanners and web application vulnerability discovery tools.

Half (50%) of malware-driven cyberattacks targeted the UAE and Saudi Arabia. In 80% of cases, these attacks resulted in a data breach, and in 73% of cases, they caused disruptions to core business operations. This highlights the presence of both financially and politically motivated threat actors operating in the region. Remote access tools (RATs) were the most prevalent type of malware used (43%), followed closely by ransomware (35%). While ransomware is typically associated with financially motivated cybercriminals, remote access tools can be deployed for a variety of purposes, including espionage and the theft of data.

Social engineering frequently accompanies malware-based cyberattacks, primarily serving as a mechanism for initial access into the target infrastructure. For instance, a campaign by the Dust Specter APT group targeting Iraqi officials combined phishing emails with the deployment of four distinct malware families (SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM).

As expected, cyberattack methods and targets are closely interconnected. Threat actors most frequently targeted computers, servers, and network devices (69%), which are assets commonly compromised through both malware deployment and vulnerability exploitation. Attacks on web resources (27%) typically point to vulnerability exploitation, whereas attacks targeting employees (25%) are generally carried out using social engineering techniques.

Figure 13. Distribution of cyberattack targets in the Gulf states

Of particular interest is the significant proportion of compromised IoT devices (17%), which are widely deployed across the Gulf states due to the high level of infrastructure digitalization. Cyberattacks exploiting IoT vulnerabilities are common across multiple countries in the region, as demonstrated by the previously mentioned CCTV camera compromise.

This suggests that the region has the underlying conditions for the formation of large-scale botnets. In addition to the high percentage of compromised IoT devices, this trend is supported by:

  • The fact that most attacks are not tied to a specific industry.

  • The prevalence of cyberattacks driven by vulnerability exploitation.

  • Ongoing digitalization, which drives the growth of connected smart devices. In practice, these devices often serve as the weakest link and are frequently weaponized in cyberattacks. According to 2025 data, approximately 35% of global DDoS attacks originated from IoT botnets.

Consequences of cyberattacks

The combined impact of hacktivists and ransomware groups in the region is reflected in the high proportion of core business disruptions, which accounted for 58% of all consequences. Nearly half (43%) of the attacks resulting in operational disruptions were recorded in the UAE. This can be attributed to the high degree of digital interconnectedness among companies and infrastructure facilities. According to a UAE government platform, the foundation of the nation's digital economy is hyperconnectivity, meaning the growing interconnection of people, organizations, and machines driven by the internet, mobile technologies, and IoT devices. In this environment, any operational disruption caused by a cyberattack can trigger a cascading effect on interconnected systems.

Data breaches were observed in 46% of cases, a characteristic outcome of cyberattacks conducted by both pro-government groups and ransomware gangs. One example of a politically motivated cyberattack aimed at data theft is the incident involving the Handala Hack Team, a hacktivist group allegedly linked to Iran, which targeted the website of an independent Iranian news agency. Examples of financially motivated incidents include an attack by the Payload Ransomware group on a leading medical institution in Bahrain, as well as an attack by another ransomware gang on a Kuwaiti automotive distributor.

Damage to state interests (29%) was distributed almost evenly across the various Gulf states. This suggests that these consequences were primarily driven by the actions of both hacktivists, whose cyber campaigns are often massive in scale, and financially motivated cybercriminals.

Figure 14. Distribution of cyberattack consequence categories in the Gulf states

Forecasts and recommendations

As with the rest of the Middle East, the forecast for future cyberthreats in the Gulf states is closely tied to the evolving conflict surrounding Iran. Nevertheless, several key trends can be identified that are likely to shape future cyberattacks in the region.

1. An increase in AI-driven cyberattacks. Threat actors can leverage AI in various contexts, encompassing both global trends and region-specific tactics:

  • As a monetization tool for financially motivated cybercriminals (a global trend): using deepfakes or AI bots, attackers can interact with the public, impersonating relatives, friends, colleagues, or persons of interest to extort money under various pretexts. Generative AI can also be used to create highly convincing fake websites that mimic popular online stores and to automate the generation of phishing emails.

  • As a disinformation tool during conflicts (a region-specific trend): amid the ongoing conflict, there have already been instances of fabricated photos and videos circulating online. These materials falsely depict missile and drone strikes, as well as the destruction of cities and infrastructure (notable examples include a deepfake image of an explosion at a U.S. military base in Iraq and an AI-generated video of a strike on the Burj Khalifa in Dubai).

  • As an assistant in cyberattack preparation (a global trend): as of late 2025, the Google Threat Intelligence Group (GTIG) reported that the APT attacks they analyzed utilized Gemini to support multiple stages of the attack lifecycle, including reconnaissance and target development, to facilitate initial access.

2. An increase in complex targeted attacks on critical information infrastructure (CII). The duration and scale of the conflict have exposed some of the vulnerable and critical infrastructure points across the Gulf states. The potential for future escalation drives state-aligned APT groups to breach the perimeters of critical facilities, establish stealthy persistence, and gather intelligence. This could provide a strategic advantage in the event of renewed conflict escalation.

3. The emergence of new, powerful botnets in the region. This trend is driven by the current nature of cyberattacks, which are massive in scale, target entities regardless of their industry, and involve a high proportion of IoT devices. Amid the ongoing conflict, botnets could be deployed to launch DDoS attacks aimed at destabilizing critical infrastructure and undermining public trust in government institutions, as well as to continuously harvest intelligence through compromised nodes.

4. The nature of future cyberattacks will largely depend on how the geopolitical conflict surrounding Iran unfolds. An escalation could trigger a new wave of DDoS attacks, primarily targeting government agencies. It could also lead to destructive impacts on the operations of facilities vital to the economy and daily life of the targeted country (such as desalination plants in Saudi Arabia and oil infrastructure in the UAE).

Recommendations for protecting organizations in the Gulf states from cyberthreats largely overlap with the recommendations for the broader Middle East:

  • Special attention must be given to protecting critical information infrastructure (CII) from cyberthreats, as these facilities will become priority targets if the conflict escalates.

  • Industrial facilities are a primary target for both state-aligned threat actors and financially motivated cybercriminals. Therefore, organizations must focus on early cyberthreat detection, taking into account the specific characteristics of OT/ICS network traffic.

  • To safeguard the infrastructure of major organizations and industrial facilities, defense efforts should prioritize the network perimeter and the malware delivery channels used to breach corporate networks, with email remaining the most common vector.

  • Regular security audits, reinforced by bug bounty programs, cyber exercises, and cyber stress testing, will help identify infrastructure vulnerabilities and remediate them before they can be exploited to breach the secure perimeter.