THE United Arab Emirates and Saudi Arabia accounted for 50% of cyberattacks recorded across the Gulf in the first half of 2026, according to an open-source intelligence analysis by Positive Technologies. Including Iran, the three countries represented 67% of attacks identified through Dark Web forums, Telegram channels and tracking services for website defacements, malware and distributed denial-of-service (DDoS) activity.
Positive Technologies said most incidents probably go unreported because organisations fear reputational damage. Check Point data cited in the report found that organisations in the UAE and Saudi Arabia faced nearly 2,700 attacks per week over the past six months, compared with about 2,300 for a typical organisation worldwide.
The region is seeing more complex, less visible intrusions, with vulnerability exploitation the leading initial access route at 38% of attacks. Information-disclosure exploits affected 62% of targeted organisations, while remote code execution and authentication bypass attacks were also prominent. More than half of incidents, 58%, caused business disruption; government targets accounted for 27% and cross-sector attacks for 23%.
Positive Technologies said DDoS attacks and website defacements were increasingly being replaced by stealthy campaigns seeking persistence and data. Check Point also reported higher-than-global-average levels of ransomware, botnets and information-stealing malware. Researchers warned that AI tools can accelerate vulnerability discovery, network mapping and malicious-code development, increasing the risk to legacy systems, industrial automation and internet-connected devices. Positive Technologies recommended reducing attack surfaces and moving away from outdated infrastructure and IoT equipment.