Egidio
Case file · August 21, 2026

The Gulf's cyberattack wave: mostly claims, barely any confirmations

Since regional military escalation began in February 2026, cyberattack volume across the Gulf has risen 15 to 25 times baseline levels. Banks, airports and telecoms have been named in claim after claim — but almost none of them have confirmed anything publicly. This page separates the measurable from the merely claimed.

⚠️ Read this before anything else. This case file covers a different kind of story than most others on this site. It isn't one breach — it's a wave of claimed attacks tied to regional military escalation since February 2026, and almost none of the named institutions have confirmed anything publicly. What's measurable is the rise in attack volume; what's claimed — specific banks, specific breaches — is, in nearly every case, unconfirmed.

What's measurable, and what's only claimed

15×
Increase in cyber-activity volume reported in the UAE after military operations began, versus baseline.
Cybersecurity threat reporting, Feb–Mar 2026.
25×
Equivalent increase reported for Saudi Arabia over the same period.
Cybersecurity threat reporting, Feb–Mar 2026.
600-800K
Daily breach attempts reported in the UAE during peak escalation, up from a 90–200K baseline.
Cybersecurity threat reporting, Feb 2026.
0
Named banks, airports or telecoms that have publicly confirmed a breach, among those cited in attack claims.
As of 08/21/2026, per available reporting.

Timeline

CONFIRMED (VOLUME)
February 2026
Regional military escalation triggers a measurable, order-of-magnitude rise in cyberattack attempts across the Gulf — UAE, Saudi Arabia, and Qatar all report multi-fold increases over baseline activity. This volume increase itself is corroborated by threat-intelligence reporting; it does not by itself confirm any specific successful breach.
CLAIMED
February 28, 2026 onward
Iran-nexus threat actors reportedly scan internet-connected cameras across Israel, UAE, Qatar, Bahrain, Kuwait, and Cyprus for known vulnerabilities. DDoS campaigns attributed to groups such as "DieNet Network" target government portals, telecom providers, airports, and financial institutions across Bahrain, Qatar, UAE, Kuwait, and Saudi Arabia.
CLAIMED
March 2026
Coordinated attack claims name Saudi Arabia's Riyad Bank and Al Rajhi Bank, Kuwait International Airport, Bahrain's Batelco, UAE telecom operator du, and multiple GCC government ministries. None of these institutions has publicly confirmed a breach, according to available reporting.
CLAIMED
June 2026
A threat actor using the handle "Ddarknotevil" claims to have stolen over 360GB from du, the UAE telecom operator, allegedly including employee emails, network logs, device and IP details for 371,000 customers, and proprietary telecom software. du has not publicly responded, per reporting at the time.

⚔️Why this looks so different from SFR or Bloctel

Elsewhere on this site, a claim usually gets tested against a company statement, a regulator filing, or a wire-service report within weeks. Here, the driving force is an active regional conflict: DDoS disruption, defacements, and hacktivist messaging serve goals — visibility, disruption, propaganda — that don't require the same kind of proof a financially motivated data thief needs to sell stolen records. That changes the incentive to confirm or deny publicly, on both sides.

What it changes for you

If you hold an account with any Gulf-region bank, airline, or telecom named in these claims, the honest answer is: there is currently no official confirmation that your data was affected. The baseline caution that applies everywhere else on this site still applies here — an unsolicited call or message citing your account, especially one creating urgency, deserves the same scrutiny regardless of whether a breach behind it is ever confirmed. See From Leak to Scam.

🔒 A high volume of attack attempts against a sector doesn't mean your specific account is compromised — it means the baseline risk of impersonation attempts referencing that sector is higher. Verify any account-related contact through the institution's own official channel, never through a link or number in the message itself. See how Medusa links channels together.

Frequently asked questions

Have Gulf banks and telecoms confirmed being breached?

Almost none have. Institutions named in attack claims have either not responded to requests for comment or have not issued public confirmation. This page documents claims and a measurable rise in attack volume, not confirmed breaches.

Is this the same kind of incident as SFR or Bloctel?

No. The Gulf wave mixes DDoS disruption, defacements, and hacktivist claims with data-theft claims, driven by regional conflict. It is far less confirmed, on average, than the France-based incidents documented elsewhere on this site.

What should someone with accounts at Gulf institutions do?

Given the low rate of official confirmation, the same baseline caution applies: treat unsolicited contact referencing your account with suspicion, and verify through official channels only.

📌 Last checked: August 21, 2026. This page will be updated if any named institution issues an official confirmation. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio — The Threat Laboratory, "The Gulf's cyberattack wave: mostly claims, barely any confirmations," egidio.app/en/laboratoire/gulf-cyberattack-wave/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.