Skip to content
RegionMiddle East and North Africa

MediumII Cyber Warfare & Critical Infrastructure16 September 2026, Wednesday

CloudSEK: ransomware in the Middle East has risen more than twentyfold, with 357 records seen in June

According to a regional threat report published on 16 September, Israel is the most targeted country with 7,112 records; Türkiye leads the region in ransomware targeting.

ABU DHABI

According to the Middle East threat landscape report published by the cyber intelligence firm CloudSEK on 16 September 2026, ransomware activity targeting the region rose more than twentyfold, from 17 threat intelligence records in April 2025 to 357 records in June 2026; June was about ten times higher than the previous month. The month with the heaviest total threat activity was March 2026, with 2,245 records. The report covers the 17-month period between April 2025 and 31 August 2026. In the country ranking, Israel is far ahead with 7,112 records, followed by Türkiye, Iran, the United Arab Emirates and Saudi Arabia. There were 2,588 activity indicators recorded for the UAE and 1,880 for Saudi Arabia; 37.8% of regional hacktivist activity targeted Israel.

According to The National, Türkiye ranked first in the region for ransomware targeting, with manufacturing, construction, defence and logistics the sectors that stood out. The report identified Nova, which operates with a Gulf focus, as the most prolific ransomware operator; The Gentlemen, which has repeatedly attacked Saudi businesses, along with Qilin, LockBit5 and DragonForce, were also associated with regional victims. On the state-linked espionage side, MuddyWater, Charming Kitten/APT35, APT42, Nimbus Manticore and OilRig were listed; MuddyWater was reported to have used Google's Gemini model in developing attack tools and APT42 to have used artificial intelligence in generating phishing messages. The nine vulnerabilities examined had an average CVSS score of 9.2. In the UAE on Tuesday, an attacker claimed to have breached a private company and demanded a ransom of more than 5 million dollars; daily hacking attempts in the country have risen from about 200,000 before the war to about 800,000. CloudSEK assessed the regional threat level as elevated to high.

Talay assessment

Bottom line

The report makes measurable the way the shooting war in the region has turned into a parallel and lasting front in cyberspace: financially motivated ransomware, political hacktivism and state-linked espionage converge on the same targets. Türkiye leading the region in ransomware shows that attackers see industrial and logistics networks away from the front line as easier targets. The most likely path is for activity to remain high while the conflict continues.

Likely effects

  • Turkish industry and logisticsNegativeWeeks

    The targeting of manufacturing, construction, defence and logistics companies creates the risk of production stoppages and ransom costs; the likelihood of disruption to export delivery schedules rises.

  • Gulf energy and transport assetsNegativeWeeks

    Daily attack attempts in the UAE rising from 200,000 to 800,000 shows that the risk of disruption on the digital side of port and energy operations has multiplied compared with before the war.

  • AI use in attacksNegative1–6 months

    MuddyWater and APT42 using generative artificial intelligence in tool development and phishing lowers the cost of preparing an attack and so increases the number of targets.

Possibilities, ranked

  1. 1
    Entrenchment at a high level55%

    While the conflict continues, the monthly record count stays in three figures and the targeting of Türkiye and the Gulf persists.

    Watch: Monthly ransomware records running above 357 through the autumn

  2. 2
    Visible disruption to critical infrastructure25%

    A publicly reported operational stoppage occurs at a port, airport or energy operator.

    Watch: A statement by a Gulf port or pipeline operator of a stoppage caused by a cyber incident

  3. 3
    Retreat through defensive investment20%

    Mandatory measures from national cyber agencies take effect and the volume of activity falls back in stages.

    Watch: UAE and Saudi regulators announcing new mandatory reporting and patching rules

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Monthly ransomware records 357
  • UAE daily attack attempts 800,000
  • Records targeting Israel 7,112

Sources

  1. The National — Ransomware activity rises across Middle East as criminal groups attack Gulf
  2. Arabian Reseller — Middle East ransomware activity surges more than 20x: CloudSEK