UAE and Saudi Arabia Account for Half of Gulf Cyberattacks in First Half of 2026

The UAE and Saudi Arabia together accounted for half of all cyberattacks recorded across the Gulf region during the first half of 2026, according to a study by information security research company Positive Technologies.

The UAE was the most targeted country, representing 35 per cent of all attacks recorded in the region. Iran followed with 17 per cent, while Saudi Arabia accounted for 15 per cent, the report said.

Cyber incidents were heavily concentrated in the first quarter of the year, which represented 96 per cent of all attacks recorded during the first six months. Researchers linked the sharp increase to heightened malicious activity during the peak of regional conflict.

Government and state organisations were among the key targets, with researchers reporting increased activity from state-backed actors following the escalation of regional tensions earlier in the year.

Alexey Lukatsky, Chief Evangelist Officer at Positive Technologies, told Khaleej Times on the sidelines of Gisec Global that the UAE and Saudi Arabia attracted significant attention because of the large number of organisations operating across sectors such as information technology, telecommunications and banking.

The report found that government agencies were the most frequently targeted sector across the Gulf, accounting for 27 per cent of successful cyberattacks.

Sector-agnostic attacks, which can affect organisations across different industries, represented 23 per cent of incidents. The industrial sector ranked third at 17 per cent, with organisations in Saudi Arabia accounting for half of the attacks against industrial targets.

Researchers identified three major methods used by cybercriminals and other threat actors in the region: exploiting software and hardware vulnerabilities, deploying malware and conducting social engineering attacks.

Vulnerability exploitation was the most common attack method, accounting for 38 per cent of incidents recorded in the study.

Positive Technologies said the technique was widespread across almost all countries included in its research. The company linked the high prevalence partly to the continued use of legacy Supervisory Control and Data Acquisition systems, commonly known as SCADA, as well as the relative ease with which some vulnerabilities can be exploited.

Malware was the second most common attack method, accounting for 31 per cent of incidents. Social engineering ranked third at 27 per cent.

Lukatsky said malware activity has also been accelerated by the use of artificial intelligence, adding to concerns about the changing nature of cyber threats.

Social engineering attacks can involve phishing through email, WhatsApp and other messaging platforms, allowing attackers to target employees and individuals directly.

The findings highlight the continued exposure of governments, financial institutions, telecommunications companies and industrial organisations to cyber threats as regional tensions and digital dependence increase. The concentration of attacks in the first quarter also points to the potential for geopolitical events to trigger sharp increases in malicious online activity.

Leave a Reply