Rival security firms describe opposite Gulf cyber years, and neither is counting incidents
CloudSEK says regional ransomware accelerated through mid-2026; Positive Technologies says 96 percent of Gulf incidents in the first half of the year happened in the first quarter. Both are selling threat intelligence.
Two regional threat assessments reached the international cycle this week and told incompatible stories. Positive Technologies, in a report on eight Gulf countries — Bahrain, Iran, Iraq, Kuwait, Oman, Qatar, Saudi Arabia and the UAE — found that the first quarter of 2026 accounted for 96 percent of all incidents it recorded across the first half, a concentration its researchers tie to the peak of the regional conflict earlier in the year. The same dataset puts the UAE at 35 percent of recorded regional attacks, Iran at 17 percent and Saudi Arabia at 15 percent; government agencies absorbed 27 percent of successful attacks and industry 17 percent, with half of the industrial cases in Saudi Arabia. Attack vectors break down as vulnerability exploitation 38 percent, malware 31 percent, social engineering 27 percent, with legacy SCADA dependence named as part of the reason exploitation leads. Dark Reading carried the findings on 23 September; regional outlets had them from GISEC Global around 17 and 18 September.
CloudSEK’s regional assessment, covering a 17-month period and picked up by International Security Journal on 22 September, runs the other way. It counts monthly ransomware “threat intelligence feeds” rising from 17 in April 2025 to 357 in June 2026 — a factor of roughly 21, and by its own description nearly ten times the preceding month. Israel is the most-targeted country at 7,112 feeds and accounts for 37.8 percent of regional hacktivist activity; Turkey ranks second overall and first for ransomware, attributed partly to industrial, manufacturing and logistics targets. The report names the ransomware group The Gentlemen, described as building databases of compromised network devices and repeatedly hitting Saudi businesses, and Nova, active throughout with a Gulf focus. Anirudh Batra, a CloudSEK threat researcher, told The National on 16 September that “the Gulf states were, until recently, not a primary ransomware target,” adding of the groups involved: “These groups are not testing the market. They have committed to it.”
Assessment: The contradiction is probably not a contradiction. A “threat intelligence feed” is a CloudSEK unit, not an incident; Positive Technologies' numbers were assembled largely through open-source collection, scanning dark-web forums and attackers' Telegram channels — which measures what intruders advertise, not what they achieved. One firm counts chatter about criminal activity, the other counts boasting. Neither counts breaches. Both sell regional threat intelligence to the governments and banks their reports describe as under siege, and Positive Technologies is a Russian company under US sanctions. The reconcilable read is narrow: state-adjacent operations spiked during the spring fighting and fell away, while criminal extortion kept its own schedule. Treat any chart built on either number as a market signal.