UAE Accounted for 35% of Gulf Cyberattacks in First Half of 2026, Report Says.

The UAE and Saudi Arabia accounted for around half of all cyberattacks detected across the Gulf during the first six months of 2026, according to a study by cybersecurity firm Positive Technologies released at GISEC 2026. Government organisations emerged as the most heavily targeted sector during the period.
The findings indicate that financial gain was not the only motivation behind the attacks. Alongside cybercriminals seeking monetary rewards, hacktivist groups and state-linked actors were also active, with some attacks focused on disrupting operations and targeting national interests.
Researchers said the Gulf’s strong economies, sophisticated digital infrastructure and complex geopolitical environment have made the region an attractive target for a diverse range of cyber threat actors.
The first quarter accounted for 96% of all cyber incidents reported across the Gulf during the first half of 2026. According to the study, the sharp increase coincided with the conflict involving Iran, while attack volumes declined significantly as de-escalation efforts gained momentum.
The report also indicated that some countries had strengthened their cybersecurity defences. However, researchers warned that a considerable number of incidents may still remain undetected because threat actors are increasingly using sophisticated methods to evade security systems.
Why was the UAE a prime target?
The UAE recorded the largest share of cyberattacks in the region, accounting for 35% of the total. Iran followed with 17%, while Saudi Arabia represented 15%.
Positive Technologies linked the higher concentration of attacks targeting the UAE and Saudi Arabia to their rapid digital transformation and economic expansion. As more services, businesses and infrastructure become digitally connected, the potential attack surface also grows, creating additional opportunities for both financially motivated cybercriminals and state-aligned threat actors.

According to the study, government agencies were the most frequently affected sector, accounting for 27% of successful cyberattacks recorded across the Gulf. Attacks that did not focus on a particular industry represented another 23%, while industrial organisations accounted for 17%.
The report found that half of the attacks targeting industrial companies occurred in Saudi Arabia, highlighting the kingdom’s industrial sector as a significant focus for cyber threat actors during the period.
Darya Lavrova, Lead Analyst at Positive Technologies, said attackers in the region are increasingly pursuing objectives beyond financial gain. She noted that during periods of conflict, cyber campaigns may also be used to spread disinformation among the public and pursue broader disruptive objectives.
Lavrova also cautioned that state-backed threat actors are expected to continue focusing on critical infrastructure, seeking prolonged access to sensitive systems for intelligence-gathering and espionage activities.
The heavy concentration of cyber incidents in the first quarter, particularly attacks targeting industrial organisations and causing operational disruption, also illustrates the growing interconnectedness of the region’s digital economy. As industries and essential services become increasingly dependent on connected technologies, cyber incidents can potentially have wider consequences across multiple sectors.


