Home Business News Positive Technologies: 50% of cyberattacks in the Gulf region in H1 2026...

Positive Technologies: 50% of cyberattacks in the Gulf region in H1 2026 targeted the UAE and Saudi Arabia

14

Government agencies faced 27% of all attacks, while 23% of incidents were sector-agnostic

Positive Technologies, a leader in results-driven cybersecurity, has released a research report on the cyberthreat landscape in the Gulf region for the first half of 2026. The findings reveal that alongside financially motivated threat actors, hacktivists and state-aligned threat groups played a major role in the attacks. The primary objectives of these state-aligned actors were operational disruption and damage to national interests.

The Gulf states attract a wide range of cybercriminals due to their strong economies, advanced digital infrastructure, and complex geopolitical dynamics. The conflict involving Iran in early 2026 sparked a surge in activity from hacktivists and state-aligned threat groups, which included campaigns focused on industrial espionage. 

The first quarter of 2026 accounted for a staggering 96% of all cyberincidents recorded during the first half of the year. This concentration is attributed to a massive spike in malicious activity during the peak of the conflict, followed by a decline as de-escalation efforts took hold. Additionally, some nations gradually adapted to the evolving cyberthreats and improved their defensive capabilities. However, researchers emphasize that a significant number of attacks likely remain undetected due to their increasingly sophisticated nature.

The UAE bore the brunt of the malicious activity, accounting for 35% of all attacks on the region. Iran followed in second place with 17%, while Saudi Arabia rounded out the top three at 15%. The authors of the report suggest that the high volume of cyberattacks directed at the UAE and Saudi Arabia is largely driven by their robust economic growth and rapid digital transformation. Government agencies were the most targeted sector, accounting for 27% of successful cyberattacks recorded across the Gulf region, followed by sector-agnostic attacks at 23%. The industrial sector ranked third at 17%, with half of these attacks targeting organizations in Saudi Arabia.

According to Positive Technologies, vulnerability exploitation was the primary attack vector in the region, used in 38% of incidents. This method was prevalent across nearly all the countries covered in the research, which may be attributed to the reliance on legacy SCADA systems and the relative ease of executing such attacks. Malware deployment was the second most common method (31%), followed by social engineering (27%).

The leading consequence of cyberattacks in the region, occurring in 58% of cases, was operational disruption. This impact underscores the heavy involvement of both hacktivists and ransomware groups. Nearly half (43%) of these disruptive attacks took place in the UAE. This concentration can be attributed to the high level of digital interconnectivity among businesses and critical infrastructure in the country, where a single cyberattack can easily trigger a cascading effect. Furthermore, data breaches occurred in 46% of incidents. The third most significant consequence was damage to national interests (29%), which was distributed almost evenly across the eight countries. Researchers attribute this impact primarily to hacktivist campaigns.

“Artificial intelligence will increasingly be leveraged in cyberattacks across the region. The objective of cybercriminals here is not solely financial gain, but also includes tactics such as spreading disinformation among the public during conflicts,” noted Darya Lavrova, Lead Analyst at Positive Technologies. “Furthermore, state-sponsored threat groups will seek to infiltrate critical infrastructure and establish persistence for espionage purposes. This could provide a strategic advantage in the event of an escalation. A new phase of the conflict could trigger a surge in DDoS attacks, primarily targeting government agencies and critical infrastructure. These campaigns may utilize powerful botnets, as evidenced by the current nature of the attacks: large-scale, sector-agnostic, and involving a high proportion of IoT devices.”

To enhance the cyber resilience of the Gulf states and safeguard their digital sovereignty, experts at Positive Technologies recommend prioritizing the protection of critical information infrastructure (CII) and industrial enterprises, as these will be the primary targets if geopolitical tensions escalate. It is crucial to focus on three key areas: early threat detection tailored to the OT-specific network traffic, robust network perimeter defense, and strict control over malware delivery channels into corporate environments, especially email. Additionally, organizations are strongly advised to conduct regular security audits, implement bug bounty programs, and run cyber exercises, cyber stress tests, and penetration tests that simulate real-world attack scenarios. These proactive measures help identify and remediate vulnerabilities before threat actors can exploit them.