Urgent.News

What's breaking now, across thousands of outlets.

Tech

Ransomware activity rises across Middle East as criminal groups attack Gulf

Ransomware activity across the Middle East has risen sharply, with organised criminal groups increasingly taking aim at Gulf businesses and sectors where disruption can put greater pressure on victims to pay, according to new research. Ransomware activity tracked by cybersecurity company CloudSEK rose from 17 incidents in April 2025 to 357 in June this year, with the company saying the increase…

Ransomware activity rises across Middle East as criminal groups attack Gulf

Ransomware attacks in the Middle East have surged recently, targeting Gulf businesses and sectors, according to a new study by cybersecurity firm CloudSEK. From April to June 2025, CloudSEK recorded the number of ransomware incidents skyrocket from 17 to 357. Shashank Shekhar, CloudSEK's managing editor, explained that the Middle East was previously not a primary target for ransomware, but this changed rapidly in 2025.

Groups such as The Gentlemen and Nova have been actively targeting Saudi businesses and other Gulf companies. Established criminal groups are now focusing on the region, taking advantage of the growing digital infrastructure and common vulnerabilities like unpatched firewalls and VPN gateways as entry points. Experts noted that ransomware is a borderless activity, with attackers prioritizing the easiest and most profitable victims rather than their location.

Israel and Turkey faced distinct threats; Israel faced targeted attacks due to its nature, while Turkey attracted ransomware groups due to its industrial sectors. Critical infrastructure is especially attractive, as disruptions can lead to higher ransoms required for service restoration. A recent incident in the UAE saw a hacker demand over $5 million after claiming to breach a private company, destroy data, and attempt to leak stolen information.

UAE authorities collaborated with the company to neutralize the attack. The UAE saw a significant rise in cyber threats since the war began, with over 800,000 hacking attempts per day as of April. Iranian-linked groups, along with China, Israel, North Korea, and Russia, were involved in various cyber operations, with AI tools amplifying established methods and lowering the entry barrier for new hackers.

Written by urgent.news from The National Business's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at thenationalnews.com →

More in Tech

Amazon Cognito

🔐 Aakash Meets Cognito: Exploring Amazon Cognito for Secure Authentication Introduction Authentication is an important part of almost every modern web and mobile application.

  • Amazon Cognito simplifies user authentication for web and mobile apps.
  • Consists of User Pools for sign-up/sign-in and Identity Pools for temporary AWS credentials.
  • Supports multi-factor authentication and external identity provider integration.

Trace Callers Before the Diff: A Blast-Radius Card for Shared OSS Helpers

The following labeled scenario opens this walkthrough and does not name a public repository or vendor team. A contributor proposed a timeout fix against a shared helper that twelve command modules…

  • BLASTRADIUS.md serves as merge gate for shared helpers
  • Harvest symbol names before edits, classify call sites
  • Python script creates reusable blast-radius inventory

More from Wednesday 16 September →