A wave of ransomware attacks is battering Gulf businesses and critical infrastructure, as criminal groups shift focus to the Middle East and leverage AI to amplify their reach. New data reveals a dramatic spike in incidents and exposes the vulnerabilities putting entire sectors at risk.
When a hacker demanded more than $5 million from a UAE company after wiping its data and threatening to leak stolen files, it sent a clear message: the Gulf has become a major target for ransomware gangs. Authorities moved quickly to contain the breach, but this was just one of many attacks now hitting the region's digital infrastructure.
CloudSEK's latest research shows a sharp rise in ransomware incidents across the Middle East, jumping from 17 in April 2025 to 357 by June 2026. The Gulf, once a secondary target, is now in the sights of established criminal groups drawn by rapid digital growth and uneven security. The Agenzia per la Cybersicurezza Nazionale (ACN) points to outdated network hardware and irregular firmware updates in key sectors like energy and logistics, leaving many organizations open to attacks on old VPN gateways and firewall devices. ACN has repeatedly urged companies to update firmware and operating systems, especially for older versions of FortiOS, Cisco IOS XE, and SonicWall.
Strategic targets and new criminal tactics
Groups such as The Gentlemen and Nova have focused on Saudi and Emirati businesses, often exploiting unpatched firewalls and VPNs. "These groups are not testing the market. They have committed to it," said Shashank Shekhar of CloudSEK. Their approach is direct: attack sectors where disruption causes the most damage-energy, logistics-and force victims to pay or face major operational problems. In several cases, attackers have used vulnerabilities like CVE-2023-27997 (Fortinet) and CVE-2024-3400 (Palo Alto Networks) to break in, highlighting the need for fast patching and network segmentation in line with European NIS2 rules.
Turkey has become a hotspot for ransomware, with its manufacturing and defense industries facing repeated attacks. Israel, meanwhile, sees the highest overall cyber-threat activity, much of it politically driven. "Israel is targeted because of who it is. Turkey is targeted because of what it has," Shekhar said. Nearly 38% of all hacktivist activity in the region is aimed at Israeli targets, according to threat intelligence data.
AI and the spread of attacks
Artificial intelligence is making these threats worse. Iran-linked MuddyWater has used Google's Gemini to build attack tools, while APT42 uses AI to create convincing phishing messages in several languages. This means even inexperienced hackers can now run complex campaigns, giving defenders less time to react and increasing the number of attackers. Italian regulators, including Garante Privacy, warn that AI-driven malware can slip past traditional detection, pushing organizations to adopt behavioral analytics and zero-trust security. The EU's Cyber Resilience Act, set to take effect in 2027, will require stronger security-by-design for connected devices and critical infrastructure, raising compliance standards across the region.
Il recente aumento delle attività ransomware nel Golfo Persico evidenzia la necessità di una risposta coordinata tra operatori di infrastrutture critiche e autorità nazionali. L'adozione di standard minimi di sicurezza, come richiesto dal NIS2 e dalle direttive ACN, è fondamentale per ridurre la superficie di attacco e garantire la resilienza digitale.Agenzia per la Cybersicurezza Nazionale (ACN)Comunicazione ufficialeFonte
Gavin Millard of Tenable notes that AI is not creating new types of cybercrime, but it is making old ones more powerful. "AI-enabled attacks aren't novel, and they're not indefensible. They're just amplified in scale." The barrier to entry has dropped, making it "far easier for a lone wolf to have the skills and capabilities of a state-based actor."
Critical infrastructure under attack
Critical infrastructure is now a main target. Disrupting aviation, energy, or financial services can affect entire populations, drive up ransom demands, and pressure governments and companies to negotiate. The UAE Cyber Security Council reports daily hacking attempts have jumped to 800,000 since the start of regional conflict, up from 200,000 before. In August, authorities stopped coordinated attacks on aviation, energy, and education, and contained advanced attempts against the financial sector. The recent temporary shutdown of the Saudi East-West Pipeline after cyberattacks, confirmed by the Saudi Ministry of Energy, shows the real impact on operational technology (OT) systems, where older SCADA setups often lack modern protection and network isolation. The GCC has condemned these attacks as a "dangerous escalation" and called for tighter cross-border controls to stop the use of third-party infrastructure for launching cyber operations.
The bigger problem may be the steady toll of frequent, smaller attacks. Mohamed Belarbi of Cypherleak points to local outages, business disruption, and rising recovery costs that quietly weaken resilience over time.
State and organized crime overlap
CloudSEK's data shows a complicated threat environment. While Iranian-linked groups are active, operations tied to China, Israel, North Korea, and Russia are also present. China-linked actors have used network equipment flaws to access government and telecom targets for intelligence. Hacktivist activity remains focused on Israel, making up nearly 38% of such incidents in the region. The United States has responded with new sanctions on networks and individuals accused of supporting Iranian proxy groups, adding to the hybrid conflict in the Middle East. Details are available in the Reuters sanctions report.
For Gulf businesses, the message is blunt: compliance checklists are not enough. "No one can deal with the volume of issues that are being highlighted by these models. You have to take a more pragmatic, risk-based, threat-based approach," Millard said. The focus needs to move from theoretical vulnerabilities to the real entry points attackers are using now.
As ransomware groups ramp up their campaigns and AI lowers the technical bar, the Middle East faces a new level of cyber risk. The old approach of perimeter defense and box-ticking compliance no longer works. The Gulf's digital growth has made it a tempting target, and unless organizations act on real threat intelligence and respond quickly, the region will remain open to both experienced syndicates and AI-powered amateurs. The recent reported earlier rise in stealthy malware shows how fast attackers adapt, leaving defenders with little room for error.