news.mlab.sh
Back to the feed
threat-intel

UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks

High
Summary

The United Arab Emirates and Saudi Arabia are experiencing a significant surge in cyberattacks, absorbing 50% of all Gulf region attacks in the first half of 2026. Driven by digital transformation and geopolitical tensions, these attacks are becoming increasingly complex and stealthy, with a focus on exploiting vulnerabilities and data gathering. AI-powered tools are accelerating the development of these advanced threats, posing a growing risk to both public and private sectors in the region.

The United Arab Emirates and Kingdom of Saudi Arabia are currently absorbing a disproportionate amount of cyberattacks within the Gulf region, accounting for 50% of all incidents recorded in the first half of 2026. This increase is largely attributed to the rapid digital transformation occurring within both nations’ public and private sectors, creating a larger attack surface for cybercriminals.

Positive Technologies, a threat intelligence firm, uses open-source intelligence (OSINT) – gathering information from Dark Web forums, Telegram channels, and threat trackers – to identify these attacks. The firm’s analysis reveals that organizations in the UAE and Saudi Arabia are experiencing nearly 2,700 attacks per week, significantly higher than the global average of approximately 2,300 attacks per week.

The most common attack type is exploitation of information-disclosure vulnerabilities, impacting 62% of affected organizations. Other prevalent attack vectors include remote code execution and authentication bypass. Furthermore, the region is witnessing elevated rates of ransomware, botnets, and information-stealing malware compared to global averages.

Attacks are becoming increasingly sophisticated and difficult to detect, moving away from simple techniques like DDoS and website defacements. Instead, attackers are focusing on stealthy infiltration of critical infrastructure, establishing persistent access, and gathering sensitive data. The conflict between the US, Israel, and Iran continues to fuel many of these attacks, but financially motivated cybercriminals are also targeting infrastructure.

Dream Group’s Shalev Hulio notes that targeting is driven by factors beyond GDP, suggesting that attackers may target nations based on their ability to pay or the decisions being made within them. The Middle East’s pursuit of AI build-outs is also creating new vulnerabilities, as attackers can leverage AI tools to quickly scan source code and generate malicious code, accelerating the development of exploits.

To mitigate these risks, both public and private sectors should prioritize reducing their attack surface by moving away from legacy systems and IoT devices. The increasing use of IoT devices, particularly in industrial automation, significantly expands the attack surface and adds extra risk. The threat landscape is shifting, and proactive measures are crucial to protect critical infrastructure and government agencies.

Read the full article at Dark Reading