Cyberattacks in the Middle East Mostly Driven by Financially Motivated Extortion and Ransomware
In the first half of 2025, cyberattacks in the Middle East showed a significant focus on financial gain, with over half of the incidents linked to extortion and ransomware. Microsoft’s data revealed the UAE and Saudi Arabia as notable targets within the Middle East and Africa region, impacted by cybercriminal activity. Cybercriminals, often using automation, off-the-shelf tools, and AI, have expanded their reach, attacking organizations of all sizes with increased sophistication. Critical sectors such as hospitals, local governments, and research institutions face severe consequences including service disruption and data theft. Nation-state actors like China, Iran, Russia, and North Korea are also intensifying espionage and financially motivated operations, sometimes collaborating with criminal cyber ecosystems. Identity attacks surged, with password attacks comprising the majority. The solution lies in phishing-resistant multifactor authentication, which can block most identity-based breaches. Microsoft emphasizes cybersecurity as a shared priority, urging collaboration among governments and industries, and highlights the importance of modern defenses amid evolving AI threats. The report stresses the urgency for governance frameworks imposing consequences on malicious cyber activities to deter nation-state adversaries and protect economic and personal security.
