Ransomware incidents in the Gulf region have surged dramatically, with organized criminal groups increasingly targeting businesses in sectors where disruption can compel victims to pay ransoms. According to research from cybersecurity firm CloudSEK, ransomware activity escalated from 17 incidents in April 2025 to 357 in June 2026, indicating a growing focus on the region by established criminal organizations.
Shashank Shekhar, managing editor at CloudSEK, noted that the Gulf states were not traditionally primary targets for ransomware attacks. “What our data shows is that changed in 2025, and it changed fast,” he stated. Groups such as The Gentlemen have been noted for building databases of compromised network devices and repeatedly attacking Saudi businesses, while another group, Nova, has maintained a consistent focus on the Gulf over the past 17 months.
Rising Threats and Vulnerabilities
The rapid expansion of digital infrastructure in Saudi Arabia and the UAE has created more internet-facing systems vulnerable to attacks. Shekhar pointed out that unpatched firewalls and VPN gateways remain common entry points for cybercriminals. Gavin Millard, vice president of intelligence at Tenable, emphasized that the rise in ransomware is part of a broader global trend, with cybercrime operating as a borderless activity. “Attackers are often less interested in where a company is based than in finding the easiest and the most profitable victims,” he explained.
In terms of regional threats, Israel recorded the highest overall cyber-threat activity, followed by Turkey, Iran, the UAE, and Saudi Arabia. Notably, Turkey has become a hotspot for ransomware activity, particularly in its manufacturing, construction, defense, and logistics sectors. Shekhar remarked, “Israel is targeted because of who it is. Turkey is targeted because of what it has.”
Impact on Critical Infrastructure
Ransomware gangs are particularly drawn to critical infrastructure, as disruptions can have far-reaching effects on services. Millard noted that when the impact is higher, the ransom demands tend to be greater. This was underscored recently in the UAE, where Dr. Mohamed Al Kuwaiti, head of the UAE Cyber Security Council, reported that a hacker had demanded over $5 million after breaching a private company, destroying data, and attempting to leak stolen information. Authorities worked swiftly to contain the attack and prevent further data circulation.
Moreover, the UAE has seen a sharp increase in cyber threats since the outbreak of the war, with Dr. Al Kuwaiti stating that the country now faces approximately 800,000 hacking attempts daily, a significant rise from 200,000 before the conflict. The Cyber Security Council has also thwarted organized attacks on critical sectors, including aviation, energy, and education.
The Role of AI in Cybercrime
CloudSEK’s report highlights the involvement of Iranian-linked groups, as well as operations attributed to China, Israel, North Korea, and Russia. The use of artificial intelligence (AI) is emerging as a significant factor in cybercrime, with groups leveraging AI tools to enhance their attack capabilities. For instance, the Iran-linked group MuddyWater reportedly utilized Google’s Gemini to develop attack tools, while APT42 employed AI to create more convincing phishing messages aimed at Israeli targets.
Shekhar noted that AI’s impact is primarily in terms of speed and scale, enabling less-experienced hackers to develop tools and craft phishing messages more efficiently. However, he clarified that AI does not independently select targets or execute attacks without human direction. Millard echoed this sentiment, stating that while AI amplifies established methods, it does not create entirely new forms of cyberattacks.
As the landscape of cyber threats continues to evolve, experts advise businesses to adopt a pragmatic, risk-based approach to cybersecurity, focusing on vulnerabilities that are most likely to be exploited by attackers. “Compliance is not security,” Millard cautioned, emphasizing the need for a more strategic response to the growing volume of cyber threats.
For further details, visit The National.
Follow Cyber Warriors Middle East for further regional cybersecurity developments.



