
UAE Takes 35% of Gulf Cyberattacks in First Half of 2026
The UAE and Saudi Arabia together absorbed half of all recorded cyberattacks across the Gulf region during the first half of 2026, according to a study by information security research company Positive Technologies.
The UAE emerged as the most targeted country in the region, drawing 35 per cent of all recorded attacks. Iran followed at 17 per cent, while Saudi Arabia accounted for 15 per cent. The vast majority of this activity was concentrated early in the year, with the first quarter accounting for 96 per cent of all cyber incidents recorded in the six-month period. Researchers noted that this sharp spike aligned with peak regional conflict tensions, with state actors accelerating directives against government and state organisations.
Government agencies bore the brunt of the threat, accounting for 27 per cent of successful attacks across the region. Sector-agnostic targets followed at 23 per cent, and the industrial sector ranked third at 17 per cent, half of which hit organisations inside Saudi Arabia.
Alexey Lukatsky, Chief Evangelist Officer at Positive Technologies, spoke on the sidelines of Gisec Global about the persistent targeting of local infrastructure, noting that companies across IT, telecommunications, and banking faced heavy pressure.
Attackers leaned on three primary tactics over the period. Vulnerability exploitation in software and hardware led the field at 38 per cent of incidents, driven by legacy Supervisory Control and Data Acquisition (SCADA) systems and ease of execution. Malware deployment accounted for 31 per cent, accelerated increasingly by artificial intelligence. Social engineering rounded out the top methods at 27 per cent, executed primarily through email, WhatsApp, and other messaging apps.
Positive Technologies’ findings highlight a volatile start to the year for local digital infrastructure, leaving IT and security teams across the region on high alert.



