News Security

Middle East Ransomware Surges 20X as Cyber Threats Converge

CloudSEK

CloudSEK report finds ransomware rising even as hacktivism declines, while AI-assisted attacks and exposed infrastructure add new pressure on regional organisations

Ransomware activity targeting organisations across the Middle East has increased more than 20-fold, highlighting a rapidly changing cyber threat environment in which financially motivated attacks are converging with hacktivism, state-linked espionage and emerging AI-assisted operations.

CloudSEK’s Middle East Cyber Threat Landscape 2025–2026 recorded ransomware feeds rising from 17 in April 2025 to 357 in June 2026—the highest level during the 17-month period analysed. Overall threat activity peaked earlier, reaching 2,245 intelligence feeds in March 2026.

The report points to an important shift in regional cyber risk. Hacktivism, which remained the largest threat category by volume, declined sharply after March 2026, while ransomware continued its upward trajectory. CloudSEK’s analysis suggests the two threat types are operating on different cycles, meaning lower hacktivist activity does not necessarily indicate a reduction in overall cyber risk.

“The defining characteristic of the Middle East cyber landscape is no longer any single threat actor or attack technique. Organisations are dealing simultaneously with geopolitical hacktivism, financially motivated ransomware, state-linked espionage and rapid exploitation of exposed infrastructure.” — Rahul Sasi, CEO, CloudSEK

The UAE recorded 2,588 cyber threat activity indicators during the assessment period, while Saudi Arabia recorded 1,880. CloudSEK documented activity against UAE maritime and industrial organisations and continued ransomware and underground-market interest targeting Saudi organisations. The company assesses critical infrastructure in both countries among the region’s higher-risk groups.

AI is also beginning to feature directly in offensive operations. CloudSEK documented MuddyWater using Google’s Gemini model for PowerShell code obfuscation and identified evidence of AI-assisted malware development associated with Nimbus Manticore/UNC1549.

Meanwhile, internet-facing infrastructure remains a major attack path. VPNs, firewalls and SSL gateways featured prominently, with vulnerabilities affecting Fortinet, Ivanti and other widely deployed technologies adding exposure.

For security leaders, the changing pattern requires a broader defence model spanning vulnerability management, phishing-resistant authentication, network segmentation, immutable backups, identity controls and continuous threat intelligence.

The report’s central warning is that cyber risk is becoming less defined by individual attack categories and more by their simultaneous operation across the region’s digital infrastructure.

Related posts

Casino Lookalikes Hide a Deeper Cyber Threat

Enterprise IT World MEA

Kodak Alaris Targets Distributed Capture With N2000 Series

Enterprise IT World MEA

Nozomi Networks Puts Proactive OT Cyber Resilience in Focus

Enterprise IT World MEA

Leave a Comment