MEFILES · Edition No. 72Today's edition · Archive · RSS
Ten files · One region · Zero illusions
All Digital Front Monitor stories → The full edition of September 25, 2026 →
Two Vendors, Two Wars

Rival security firms describe opposite Gulf cyber years, and neither is counting incidents

CloudSEK says regional ransomware accelerated through mid-2026; Positive Technologies says 96 percent of Gulf incidents in the first half of the year happened in the first quarter. Both are selling threat intelligence.

Two regional threat assessments reached the international cycle this week and told incompatible stories. Positive Technologies, in a report on eight Gulf countries — Bahrain, Iran, Iraq, Kuwait, Oman, Qatar, Saudi Arabia and the UAE — found that the first quarter of 2026 accounted for 96 percent of all incidents it recorded across the first half, a concentration its researchers tie to the peak of the regional conflict earlier in the year. The same dataset puts the UAE at 35 percent of recorded regional attacks, Iran at 17 percent and Saudi Arabia at 15 percent; government agencies absorbed 27 percent of successful attacks and industry 17 percent, with half of the industrial cases in Saudi Arabia. Attack vectors break down as vulnerability exploitation 38 percent, malware 31 percent, social engineering 27 percent, with legacy SCADA dependence named as part of the reason exploitation leads. Dark Reading carried the findings on 23 September; regional outlets had them from GISEC Global around 17 and 18 September.

CloudSEK’s regional assessment, covering a 17-month period and picked up by International Security Journal on 22 September, runs the other way. It counts monthly ransomware “threat intelligence feeds” rising from 17 in April 2025 to 357 in June 2026 — a factor of roughly 21, and by its own description nearly ten times the preceding month. Israel is the most-targeted country at 7,112 feeds and accounts for 37.8 percent of regional hacktivist activity; Turkey ranks second overall and first for ransomware, attributed partly to industrial, manufacturing and logistics targets. The report names the ransomware group The Gentlemen, described as building databases of compromised network devices and repeatedly hitting Saudi businesses, and Nova, active throughout with a Gulf focus. Anirudh Batra, a CloudSEK threat researcher, told The National on 16 September that “the Gulf states were, until recently, not a primary ransomware target,” adding of the groups involved: “These groups are not testing the market. They have committed to it.”

Assessment: The contradiction is probably not a contradiction. A “threat intelligence feed” is a CloudSEK unit, not an incident; Positive Technologies' numbers were assembled largely through open-source collection, scanning dark-web forums and attackers' Telegram channels — which measures what intruders advertise, not what they achieved. One firm counts chatter about criminal activity, the other counts boasting. Neither counts breaches. Both sell regional threat intelligence to the governments and banks their reports describe as under siege, and Positive Technologies is a Russian company under US sanctions. The reconcilable read is narrow: state-adjacent operations spiked during the spring fighting and fell away, while criminal extortion kept its own schedule. Treat any chart built on either number as a market signal.

Digital Front MonitorMEFILES tracking
96%Share of Positive Technologies' recorded H1 2026 Gulf incidents that fell in Q1
Evidence5 cited sources · Dark Reading · TechItUp Middle East · Nukta · International Security Journal and 1 more
The file27 Jul: 2 stories28 Jul: 2 stories29 Jul: 2 stories30 Jul: 2 stories31 Jul: 2 stories1 Aug: 2 stories2 Aug: 2 stories3 Aug: 2 stories4 Aug: 2 stories5 Aug: 2 stories6 Aug: 2 stories7 Aug: 2 stories8 Aug: 2 stories9 Aug: 2 stories10 Aug: 2 stories11 Aug: 2 stories13 Aug: 2 stories14 Aug: 2 stories15 Aug: 2 stories16 Aug: 2 stories17 Aug: 2 stories18 Aug: 2 stories19 Aug: 2 stories20 Aug: 2 stories21 Aug: 2 stories22 Aug: 3 stories23 Aug: 2 stories24 Aug: 3 stories25 Aug: 3 stories26 Aug: 2 stories27 Aug: 2 stories28 Aug: 2 stories29 Aug: 2 stories30 Aug: 2 stories31 Aug: 2 stories1 Sept: 2 stories2 Sept: 2 stories3 Sept: 2 stories4 Sept: 2 stories5 Sept: 2 stories6 Sept: 3 stories7 Sept: 2 stories8 Sept: 2 stories9 Sept: 2 stories10 Sept: 2 stories11 Sept: 2 stories12 Sept: 2 stories13 Sept: 2 stories14 Sept: 2 stories15 Sept: 2 stories16 Sept: 2 stories17 Sept: 2 stories18 Sept: 2 stories19 Sept: 2 stories20 Sept: 2 stories21 Sept: 2 stories22 Sept: 1 story23 Sept: 2 stories24 Sept: 2 stories25 Sept: 2 stories
Digital Front Monitor · 66 editions since 19 July 2026 · 131 stories filed · 2 in this edition · rail shows the last 60