News Middle East17 Sep 2026

Middle East ransomware activity surges over 20X as cyber threats converge

| 17 Sep 2026

Ransomware activity targeting the Middle East surged to its highest level during a 17-month period assessed by CloudSEK, jumping from 17 threat intelligence feeds in April 2025 to 357 in June 2026 - more than a 20-fold increase.

The sharp ransomware escalation is part of a wider shift in the region’s cyber threat landscape, where financially motivated cybercrime is increasingly operating alongside politically driven hacktivism, state-linked espionage, destructive attacks and rapid exploitation of critical vulnerabilities.

CloudSEK’s new “Middle East Cyber Threat Landscape 2025–2026” report analyses threat activity across ransomware, hacktivism, dark web sources, adversary intelligence, malware and vulnerability intelligence between April 2025 and August 2026. The report recorded its highest overall monthly volume in March 2026, with 2,245 threat intelligence feeds. 

The findings point to what CloudSEK describes as an increasingly “structurally complex” threat environment, in which organisations must defend simultaneously against high-volume disruptive attacks, financially motivated ransomware and quieter, longer-dwell espionage operations.

Key findings

  • Ransomware rose more than 20X: Monthly ransomware feeds increased from 17 in April 2025 to a peak of 357 in June 2026. The June spike was also nearly 10 times the previous month.

  • Israel was the most targeted country overall, recording 7,112 threat intelligence feeds. Turkiye ranked second overall, while Iran, the UAE, Saudi Arabia and Egypt were also heavily targeted.

  • Turkiye faced the highest ransomware targeting in the region, driven partly by attacks against industrial, manufacturing and logistics organisations.

  • Hacktivism remained the largest threat category by volume, with Israel accounting for 37.8% of regional hacktivist activity.

  • Government and financial services were the most targeted sectors overall, while ransomware disproportionately affected facility management, industrial, infrastructure, property management and manufacturing organisations.

  • AI is beginning to appear in offensive threat operations. CloudSEK documented MuddyWater using Google's Gemini model for PowerShell code obfuscation and found evidence of AI-assisted malware development by IRGC-linked Nimbus Manticore/UNC1549.

  • Unpatched internet-facing infrastructure remains a major entry point. Fortinet, Ivanti, React, Kubernetes and other widely deployed technologies featured prominently among vulnerabilities relevant to attacks against organisations operating in the region.

Lower hacktivist noise should not be mistaken for lower cyber risk

Despite a decline in hacktivism after March 2026, CloudSEK warns organisations against interpreting reduced public-facing cyber disruption as an improvement in the overall threat environment. 

“The defining characteristic of the Middle East cyber landscape is no longer any single threat actor or attack technique. Organisations are dealing simultaneously with geopolitical hacktivism, financially motivated ransomware, state-linked espionage and rapid exploitation of exposed infrastructure. The ransomware surge is particularly significant because it continued even as hacktivist activity declined. Less visible cyber noise should not be mistaken for lower risk,” said Mr Rahul Sasi, CEO, CloudSEK.

CloudSEK is an AI-native predictive cyber intelligence platform that identifies attack paths and initial access vectors before they are exploited. The platform combines digital risk protection, cyber threat intelligence, external attack surface monitoring, AI attack surface monitoring and third-party risk intelligence to help organisations detect how attackers can gain access and disrupt attack paths before execution.


 

| Print
CAPTCHA image
Enter the code shown above in the box below.

Note that your comment may be edited or removed in the future, and that your comment may appear alongside the original article on websites other than this one.

 

Recent Comments

There are no comments submitted yet. Do you have an interesting opinion? Then be the first to post a comment.