Ransomware Activity in the Middle East Surges Over 20-Fold Amid Evolving Cyber Threats

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Ransomware activity targeting the Middle East has surged dramatically, increasing from 17 threat intelligence feeds in April 2025 to 357 in June 2026—a staggering more than 20-fold rise, according to a report by CloudSEK.

This sharp escalation in ransomware incidents is part of a broader shift in the region’s cyber threat landscape, where financially motivated cybercrime is increasingly intertwined with politically driven hacktivism, state-linked espionage, and the rapid exploitation of critical vulnerabilities.

The findings from CloudSEK’s “Middle East Cyber Threat Landscape 2025–2026” report reveal that March 2026 recorded the highest overall monthly volume of threat intelligence feeds, totaling 2,245. Israel emerged as the most targeted nation, with 7,112 feeds documented during the assessment period.

Key Findings from the Report

  1. Ransomware activity increased over 20 times: Monthly ransomware feeds peaked at 357 in June 2026, nearly ten times higher than the previous month.
  2. Israel was the most targeted country: It recorded 7,112 threat intelligence feeds, followed by Türkiye, Iran, the UAE, Saudi Arabia, and Egypt.
  3. Türkiye faced the highest ransomware targeting: This was driven by attacks on industrial, manufacturing, and logistics sectors.
  4. Hacktivism remained the largest threat category: Israel accounted for 37.8% of regional hacktivist activity.
  5. Government and financial services were the most targeted sectors: Ransomware attacks disproportionately affected facility management, industrial, infrastructure, property management, and manufacturing organizations.
  6. AI is emerging in offensive cyber operations: CloudSEK documented the use of AI tools in malware development and code obfuscation.
  7. Unpatched infrastructure remains a major entry point: Vulnerabilities in widely used technologies like Fortinet and Kubernetes were highlighted as significant risks.

Ransomware and Hacktivism: Diverging Trends

One of the report’s notable insights is the divergence between hacktivism and ransomware activities. While hacktivist activity surged during geopolitical escalations in 2025, it sharply declined from April 2026 onwards. In contrast, ransomware incidents have steadily increased, culminating in the June 2026 spike. This suggests that politically motivated hacktivists and financially driven ransomware operators operate on different cycles, rather than competing for the same attack windows.

Nova has emerged as the most prolific ransomware operator in the region, with other groups like The Gentlemen, Qilin, LockBit5, and DragonForce also implicated in campaigns targeting Middle Eastern organizations. The Gentlemen notably exploited vulnerabilities in Fortinet systems, showcasing the evolving tactics of ransomware operators.

Growing Threats in the UAE and Saudi Arabia

The UAE recorded 2,588 overall activity indicators, facing a mix of ransomware, dark-web exposure, and state-linked campaigns. Notably, the MuddyWater group targeted UAE maritime and industrial sectors with sophisticated phishing tactics and advanced malware delivery methods.

Saudi Arabia reported 1,880 activity indicators, with ransomware operators showing sustained interest in the region. The Gentlemen and Nimbus Manticore were among the groups targeting Saudi organizations during the reporting period.

CloudSEK assesses that organizations within the critical infrastructure sectors of the UAE and Saudi Arabia are among the highest-risk groups in the region, alongside Israeli government and defense entities.

As the cyber threat landscape continues to evolve, organizations in the Middle East must remain vigilant against the dual threats of ransomware and state-sponsored cyber espionage. The report emphasizes that the decline in hacktivist activity should not be misconstrued as a reduction in overall cyber risk, as ransomware remains at elevated levels.

“The defining characteristic of the Middle East cyber landscape is no longer any single threat actor or attack technique. Organizations are dealing simultaneously with geopolitical hacktivism, financially motivated ransomware, state-linked espionage, and rapid exploitation of exposed infrastructure,” said Rahul Sasi, CEO of CloudSEK.

Follow Cyber Warriors Middle East for further regional cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Radaris.com and 14 Other Domains Transferred to Plaintiffs in New Jersey Privacy Lawsuit

The consumer data broker Radaris.com has recently faced legal repercussions for allegedly violating New Jersey's privacy law, known as Daniel’s Law. This law mandates...

New MovieReaper Malware Campaign Targets Users via Compromised Torrent Trackers

New MovieReaper Malware Campaign Exploits Torrent Trackers The rise of torrent trackers as a means for distributing malicious software has been a persistent issue in...

Cisco Warns of Active Exploitation of CVE-2026-76461 SQL Injection Vulnerability in Secure Email Gateway

Critical SQL Injection Vulnerability in Cisco Secure Email GatewayOn September 14, 2026, Cisco issued a security advisory regarding CVE-2026-76461, a critical SQL injection vulnerability...

BAM-IS submarine rescue vessel A-21 Poseidón named by Navantia

On September 18, 2026, Navantia celebrated the naming ceremony of the Spanish Navy’s new Underwater Intervention Maritime Action Vessel (BAM-IS), A-21 Poseidón. The ceremony follows...