A Gulf threat report built from Telegram posts lands three months after its data closes
Positive Technologies says the UAE and Saudi Arabia absorbed half of all recorded Gulf cyberattacks in the first half of 2026. The number worth arguing about is the one showing 96 percent of the half-year’s incidents fell in a single quarter.
The report, picked up by regional trade press around 21 September and amplified by Dark Reading on or about 23 September, covers eight countries — Bahrain, Iran, Iraq, Kuwait, Oman, Qatar, Saudi Arabia and the UAE — for January through June 2026. By Positive Technologies' count, the UAE and Saudi Arabia together accounted for 50 percent of recorded attacks; broken out, the UAE took 35 percent, Iran 17 percent and Saudi Arabia 15 percent, or 67 percent between them. Government agencies were the most-hit sector at 27 percent of successful attacks, followed by sector-agnostic targeting at 23 percent and industrial at 17 percent, with half of the industrial cases falling on Saudi organisations. Vulnerability exploitation was the leading vector at 38 percent of incidents. Darya Lavrova, the firm’s lead analyst, told Dark Reading that periods of heightened conflict contribute most to overall incident volume, largely through hacktivists and politically aligned groups.
Two things qualify all of it. First, the methodology: this is open-source intelligence — dark web forums, Telegram channels used by attacker groups, and aggregators tracking defacements, malware and DDoS. It is not incident-response telemetry, and it counts claims as much as compromises. Lavrova herself told Dark Reading that most attacks likely go unreported for reputational reasons. Second, the publisher: Positive Technologies is a Russian vendor under US sanctions, which does not make the arithmetic wrong but does make the sourcing a fact readers are entitled to. The same Dark Reading piece carries a separate figure from Check Point Software, which put UAE and Saudi organisations at roughly 2,700 attacks per week over the past half-year against about 2,300 for a typical organisation globally — a gap of roughly 17 percent, not an order of magnitude.
The internal distribution is the part nobody has stress-tested. Positive Technologies places 96 percent of all first-half incidents in the first quarter alone. Read naively that describes a collapse in attacks after March. Read against the methodology it may describe something narrower: a quarter in which hacktivist and politically aligned channels were posting loudly, followed by one in which they were not. The distinction is not academic. A curve built from claimed activity will track the visibility of the claimants, not the damage to the targets, and the only way to settle it is a second dataset — Check Point’s underlying series, or figures from Saudi Arabia’s National Cybersecurity Authority, the UAE Cybersecurity Council or another national CERT — showing whether the same period looks that lopsided in non-OSINT telemetry.
Assessment: A vendor report whose data closed on 30 June arriving in the trade press in late September is itself a distribution event, and worth treating as one. The numbers are consistent across two outlets, which establishes that the report exists and says what it says — not that the counts are right. Watch for the 96 percent figure detaching from its methodology over the next fortnight and reappearing as evidence that Gulf attacks fell sharply after the spring. That reading is available to anyone who wants it, on both sides of the Gulf, and nothing in the underlying method supports it. Keep this separate from the 16 September ransomware reporting; they are different datasets and will be conflated.