Iranian-linked cyberattacks have surged 8x across the Middle East
Middle East DDoS attacks jumped in March, with many GCC nations among key targets as cyber risks intensify
16 April, 2026
TT
16
Iranian-linked cyberattacks surged sharply across the Middle East last month, with distributed denial-of-service (DDoS) incidents rising eightfold during the month, according to cybersecurity firm StormWall.
The data reflects a significant escalation in cyber activity following heightened geopolitical tensions from 28 February, when a joint US-Israeli military operation targeting Iran triggered a wider regional response.
StormWall said that between March 1 and March 20, the number of DDoS attacks recorded across its regional clients increased 8x compared to the same period in February, marking one of the sharpest spikes on record.
“The volume of DDoS traffic currently hitting the Middle East is unlike anything we’ve seen before — even during past periods of geopolitical tension,” said Ramil Khantimirov, the CEO and co-founder of StormWall.
“This is a highly organised, targeted, and growing campaign that will likely continue to escalate.”
UAE among key targets
The attacks were concentrated across a handful of countries, with:
- Israel accounting for 36 per cent of incidents
- The UAE at 21 per cent
- Bahrain at 14 per cent
StormWall said the campaign initially focused on Israeli government and telecom infrastructure, before expanding to other Gulf states.
The most affected sectors included public sector entities, banking and telecommunications: industries seen as both operationally critical and symbolically important.
“If you have digital infrastructure in the region that isn’t properly protected, now is the time to act,” Khantimirov said.
“Over the coming months, we’re likely to see more attacks — and more powerful ones.”
Broader cyber risks emerging
Separate analysis from predictive cyber threat intelligence platform CloudSEK suggests the cyber threat may extend beyond short-term disruption.
The firm said in a new report this month that it too has seen an uptick in Iranian-linked cyber attacks.
CloudSEK is therefore urging organisations, especially those operating in the GCC and Middle East — and adjacent sectors supporting regional infrastructure — to take immediate defensive steps, including:
- Patching exposed internet-facing systems linked to known exploited vulnerabilities
- Auditing exchange, VPN, and web-facing infrastructure for compromise
- Hunting for webshells, suspicious tunneling tools, and malware indicators
- Rotating privileged credentials and auditing administrative access
- Reviewing aviation, energy, telecom, logistics, and industrial environments for abnormal activity
- Blocking known indicators of compromise and validating detection coverage against the malware families referenced in the report
The financial impact of cyber attacks are significant. The average cyber breach in the Middle East costs roughly $7m–$7.5m, placing the region among the most expensive globally for organisations hit by attacks, according to IBM Security data.
Globally, cybercrime is now estimated to cost around $10.5tn annually, a figure that continues to climb as state-linked and organised attacks accelerate, based on industry estimates from Cybersecurity Ventures and other market research.






















