tech
uae
saudi-arabia
jordan
cyber-security
fintech

The Middle East Conflict is Driving Cyber Spillover Beyond the Region

The Middle East conflict has driven a sharp rise in politically motivated cyber activity spilling beyond the region, with major increases in attacks on UAE infrastructure and a surge of DDoS, crowdsourced botnets and supply‑chain disruption affecting banks and global firms.

SM
StartupsMENA EditorialCovering the MENA startup ecosystem
2 views
Share:
The Middle East Conflict is Driving Cyber Spillover Beyond the Region

Ongoing conflict in the Middle East has driven a sharp rise in cyber activity that is spilling beyond the region and affecting organisations worldwide, industry figures warn. In early April 2026 UAE cybersecurity chief Mohamed Al Kuwaiti reported that attacks on the country’s digital infrastructure had tripled from 200,000 to 600,000 since the start of the war. Over the same period, cyber-attacks on critical infrastructure across North America, Europe and parts of Asia‑Pacific surged by 245%, and high‑profile regional targets such as Riyadh Bank, Jordan Commercial Bank and First Abu Dhabi Commercial Bank were among those hit. Commercial firms including medical technology company Stryker have also suffered destructive incidents aimed at disrupting supply chains.

"This shift marks a turning point," wrote Travis DeForge, director of cybersecurity at Abacus, highlighting that what began as a regionally concentrated campaign is now "evolving into a broader, less predictable threat environment, where politically-motivated disruption can ripple across borders, industries and supply chains."

The evolving threat profile reflects a move away from profit-driven ransomware to politically-motivated disruption. DeForge points to the growing use of crowdsourced botnets, website disruption and high-volume distributed denial of service (DDoS) attacks by aligned hacktivist groups. These groups, often described as having deniability rather than being formal state-directed units, are being mobilised through information operations that encourage volunteer-driven online action. The result is a higher likelihood of grey‑zone activity — disinformation, denial of service and other tactics that can tangibly affect organisations far from the conflict zone.

Risk vectors and sector exposure

DeForge warns a wide spectrum of organisations are at risk: financial services, healthcare, government, transport and media, plus critical service providers in cloud, telecoms and payments. Supply chain exposure is a particular concern. The Verizon Data Breach Investigations Report (DBIR) 2025 found that more than three in 10 data breaches now involve a third party — a 100% increase year‑over‑year — underscoring how shared infrastructure and global providers can amplify spillover effects.

  • Targets identified: Riyadh Bank, Jordan Commercial Bank, First Abu Dhabi Commercial Bank, and global firms such as Stryker.
  • Quantified surge: UAE attacks rose from 200,000 to 600,000; critical‑infrastructure attacks in Western/APAC regions up 245%.
  • Attack modalities: hacktivist-driven DDoS, crowdsourced botnets, information operations and supply‑chain compromise.

Preparing for impact, not just prevention, is the central thrust of DeForge’s prescription. Organisations are urged to prioritise resilience and rapid response alongside traditional defences. Recommended measures include endpoint and cloud managed detection and response (MDR), phishing‑resistant multi‑factor authentication (MFA), Zero Trust architectures, AI‑enabled email security and hardened help desk protocols. DeForge emphasises the need for an effective incident response plan that details detection, containment and recovery procedures, and that is exercised regularly through tabletop drills with cybersecurity partners.

He also recommends a two‑pronged approach to third‑party risk: internal entitlement reviews enforcing least‑privilege and time‑boxed access, and an external supplier‑assessment framework incorporating posture scoring, continuous monitoring telemetry and contractual breach‑notification clauses. "In response, organizations need to have the right tools, teams and techniques in their armoury to stay resilient and respond rapidly to threats," DeForge writes, framing resilience as both an operational and reputational imperative as the conflict-driven cyber threat landscape continues to expand.

Related Startups

Related Founders

Stay in the loop

Join our weekly newsletter and get the latest MENA startup news, funding rounds, and insights delivered straight to your inbox.