Ransomware Surge in the Middle East Reaches 17-Month High, Driven by Hybrid Cyber Threats
Ransomware attacks in the Middle East have skyrocketed to their highest levels in 17 months, increasing over twenty-fold between April 2025 and June 2026, according to a report by TahawulTech. The region’s cyber threat landscape has grown increasingly complex, blending financially motivated cybercrime with politically driven hacktivism, state-sponsored espionage, and the rapid exploitation of critical vulnerabilities.
CloudSEK’s analysis highlights a multifaceted threat environment, where organizations face simultaneous high-volume disruptive attacks, ransomware, and espionage operations. Ransomware incidents surged from just 17 in April 2025 to a peak of 357 in June 2026. While hacktivism was previously dominant, it declined sharply after March 2026. Israel emerged as the most targeted country overall, though Türkiye experienced the highest concentration of ransomware attacks, particularly in industrial, manufacturing, and logistics sectors. Government and financial services were the most affected industries across the region.
New threats include the weaponization of AI in offensive cyber operations. Groups like MuddyWater have leveraged Google’s Gemini for code obfuscation, while Nimbus Manticore has demonstrated AI-assisted malware development. Unpatched internet-facing infrastructure including vulnerabilities in Fortinet, Ivanti, and Kubernetes remains a primary attack vector. The UAE and Saudi Arabia are facing escalating ransomware and espionage pressure, with critical infrastructure, Israeli government entities, and Turkish industrial organizations identified as high-risk targets.
Fortinet cybersecurity rating report: https://www.rankiteo.com/company/fortinet
"id": "FOR1789745539",
"linkid": "fortinet",
"type": "Vulnerability",
"date": "4/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['government',
'financial services',
'industrial',
'manufacturing',
'logistics'],
'location': ['Middle East',
'Israel',
'Türkiye',
'UAE',
'Saudi Arabia'],
'type': ['government',
'financial services',
'industrial',
'manufacturing',
'logistics']}],
'attack_vector': ['unpatched internet-facing infrastructure',
'vulnerabilities in Fortinet',
'vulnerabilities in Ivanti',
'vulnerabilities in Kubernetes',
'AI-assisted malware development'],
'description': 'Ransomware attacks in the Middle East have skyrocketed to '
'their highest levels in 17 months, increasing over '
'twenty-fold between April 2025 and June 2026. The region’s '
'cyber threat landscape has grown increasingly complex, '
'blending financially motivated cybercrime with politically '
'driven hacktivism, state-sponsored espionage, and the rapid '
'exploitation of critical vulnerabilities. CloudSEK’s analysis '
'highlights a multifaceted threat environment, where '
'organizations face simultaneous high-volume disruptive '
'attacks, ransomware, and espionage operations. New threats '
'include the weaponization of AI in offensive cyber '
'operations, with groups like MuddyWater leveraging Google’s '
'Gemini for code obfuscation and Nimbus Manticore '
'demonstrating AI-assisted malware development. Unpatched '
'internet-facing infrastructure remains a primary attack '
'vector.',
'impact': {'operational_impact': 'high-volume disruptive attacks'},
'motivation': ['financial gain', 'political', 'espionage'],
'post_incident_analysis': {'root_causes': ['unpatched internet-facing '
'infrastructure',
'AI-assisted malware development']},
'references': [{'source': 'TahawulTech'}, {'source': 'CloudSEK'}],
'threat_actor': ['MuddyWater',
'Nimbus Manticore',
'state-sponsored groups',
'hacktivist groups'],
'title': 'Ransomware Surge in the Middle East Reaches 17-Month High, Driven '
'by Hybrid Cyber Threats',
'type': ['ransomware', 'espionage', 'hacktivism'],
'vulnerability_exploited': ['Fortinet vulnerabilities',
'Ivanti vulnerabilities',
'Kubernetes vulnerabilities']}