Washington faces Gulf cyber test after UAE and Saudi take half of attacks

Positive Technologies said the UAE and Saudi Arabia accounted for 50% of Gulf cyberattacks in the first half of 2026.

Lauren Collins ·

Washington faces Gulf cyber test after UAE and Saudi take half of attacks

Washington faces Gulf cyber test after UAE and Saudi take half of attacks

Washington faced a new Gulf cyber-policy test on Friday after Positive Technologies said the UAE and Saudi Arabia accounted for 50% of reported Gulf cyberattacks in the first half of 2026. The concentration puts two major US security partners at the center of a threat picture increasingly shaped by AI-powered malware and phishing through email, WhatsApp and other messaging apps, according to the company’s chief.

For President Trump's administration, the immediate question is whether cyber cooperation with Gulf partners remains a set of bilateral channels or becomes a more formal defense architecture. The reported tactics matter because they target the human layer of government, energy, banking and telecom systems rather than only the hardened networks that traditional cyber defenses are built to monitor.

The UAE and Saudi Arabia sit at the intersection of three Washington priorities: energy security, defense cooperation and regional stability. A cyber incident that disrupts oil operations, payment systems, ports or government services in either country would not remain a local technical problem for long; it would feed into markets, diplomatic crisis management and US military coordination in the Gulf.

Positive Technologies’ reported finding is a concentration measure, not a full threat map. The available summary does not state the sample size, the victim sectors, the attack success rate or whether the dataset counts attempted intrusions, detected campaigns or confirmed breaches. Those gaps matter for US policy because a high share of recorded attacks can reflect heavier targeting, better detection, broader reporting or some combination of the three.

Positive Technologies

The tactics described by the company’s chief fit a problem US agencies have been warning about across allied networks: attackers use automation to write better lures, adapt malware and scale social engineering. In practical terms, a phishing message sent over WhatsApp to a ministry aide or an energy contractor can become a national-security incident if it opens a path into credentials, cloud accounts or operational systems.

Washington already treats cyber defense as part of strategic competition in the Middle East, even when the public language is technical. The White House sets the policy line, the State Department manages diplomatic channels, the Pentagon handles defense cooperation, and Congress can condition assistance or fund new joint programs. The National Security Council usually becomes the place where those pieces are aligned when a threat crosses agencies.

A formal Gulf cybersecurity compact would be the most visible next step, but it would also be the hardest. It would require common alerting standards, agreed rules for sharing indicators of compromise, joint incident-response drills, and limits on how sensitive US-derived intelligence can be distributed among regional partners. The political challenge is that cyber cooperation depends on trust, and trust is thinner when intelligence, surveillance tools and regional rivalries overlap.

The case for a compact is strongest if the Positive Technologies data is backed by additional government or industry reporting.

If the UAE and Saudi Arabia are absorbing half of recorded Gulf attacks, then a US effort focused only on ad hoc information sharing would leave two of the region’s biggest targets dependent on uneven defenses. If later data shows the figure reflects reporting bias rather than a true targeting shift, Washington would have less reason to build a new formal mechanism around this single report.

For the UAE, the risk profile is tied to its role as a finance, logistics and technology hub. That makes identity systems, cloud platforms, ports, airlines and banks high-value targets. For Saudi Arabia, the stakes include state services, energy infrastructure and the large-scale economic projects attached to its diversification plans. In both cases, attackers do not need to shut down a national network to create leverage; stealing credentials, disrupting vendors or exposing sensitive data can be enough.

The industry effect would reach beyond cybersecurity vendors. Banks would need faster fraud controls, telecom operators would face pressure to harden messaging channels, and energy companies would have to test whether corporate IT defenses are properly separated from operational technology. Insurers would also reassess pricing if AI-enabled phishing and malware campaigns increase claims tied to business interruption or data theft.

The macro channel is indirect but real. Gulf energy exports, sovereign investment flows and dollar-linked financial systems give cyber incidents in the UAE and Saudi Arabia a wider transmission path than attacks on smaller markets. A prolonged disruption to energy logistics or payments would be the kind of event that pulls Treasury, State, the Pentagon and allied governments into the same room.

By December 31, 2026, the falsifiable test is whether Washington moves from general cyber partnership language to a public Gulf cybersecurity framework with UAE and Saudi participation, including shared threat intelligence, joint exercises and incident-response milestones. If that happens, the macro effect would be lower perceived operational risk around Gulf energy and finance, the company-level effect would be stronger demand for detection and response services, and the sector effect would be faster standards alignment across banks, telecoms and energy firms. If no compact, annex or measurable drill schedule emerges by then, the report will have produced warning without architecture, leaving Gulf cyber defense dependent on bilateral habits and uneven private-sector resilience.

More stories