Techitup Middle East
Cybersecurity

Positive Technologies: 50% of Gulf Cyberattacks in H1 2026 Targeted UAE and Saudi

⏱️ 3 min read

Positive Technologies has released a research report on the cyberthreat landscape in the Gulf region for H1 2026. The report covers eight countries in the region: Bahrain, Iran, Iraq, Kuwait, Oman, Qatar, Saudi Arabia, and the United Arab Emirates. The findings reveal that alongside financially motivated threat actors, hacktivists and state-aligned threat groups played a major role in the attacks. The primary objectives of these state-aligned actors were operational disruption and damage to national interests.

According to Positive Technologies, Gulf states attract a wide range of cybercriminals due to their strong economies and advanced digital infrastructure.

UAE and Saudi Arabia Cyberattacks in H1 2026: Positive Technologies Research

The first quarter of 2026 accounted for a staggering 96% of all cyberincidents recorded during the first half of the year, finds the research. Some nations gradually adapted to the evolving cyberthreats and improved their defensive capabilities. However, researchers emphasize that a significant number of attacks likely remain undetected due to their increasingly sophisticated nature.

Positive Technologies’ research finds, UAE accounted for 35% of all cyberattacks in the region, followed by Iran with 17%, and Saudi Arabia at 15%. The authors of the report suggest that the high volume of cyberattacks directed at the UAE and Saudi Arabia is largely driven by their robust economic growth and rapid digital transformation. Government agencies were the most targeted sector, accounting for 27% of successful cyberattacks recorded across the Gulf region, followed by sector-agnostic attacks at 23%. The industrial sector ranked third at 17%, with half of these attacks targeting organizations in Saudi Arabia.

According to Positive Technologies, vulnerability exploitation was the primary attack vector in the region, used in 38% of incidents. This method was prevalent across nearly all the countries covered in the research, which may be attributed to the reliance on legacy SCADA systems and the relative ease of executing such attacks. Malware deployment was the second most common method (31%), followed by social engineering (27%).

The leading consequence of cyberattacks in the region, occurring in 58% of cases, was operational disruption, says Positive Technologies. This impact underscores the heavy involvement of both hacktivists and ransomware groups. Nearly half (43%) of these disruptive attacks took place in the UAE. This concentration can be attributed to the high level of digital interconnectivity among businesses and critical infrastructure in the country, where a single cyberattack can easily trigger a cascading effect.

Furthermore, data breaches occurred in 46% of incidents. The third most significant consequence was damage to national interests (29%), which was distributed almost evenly across the eight countries. Researchers attribute this impact primarily to hacktivist campaigns.

“Artificial intelligence will increasingly be leveraged in cyberattacks across the region. The objective of cybercriminals here is not solely financial gain, but also includes tactics such as spreading disinformation among the public during conflicts,” noted Darya Lavrova, Lead Analyst at Positive Technologies. “Furthermore, state-sponsored threat groups will seek to infiltrate critical infrastructure and establish persistence for espionage purposes. This could provide a strategic advantage in the event of an escalation. A new phase of the conflict could trigger a surge in DDoS attacks, primarily targeting government agencies and critical infrastructure. These campaigns may utilize powerful botnets, as evidenced by the current nature of the attacks: large-scale, sector-agnostic, and involving a high proportion of IoT devices.”


Related posts