The Gulf's cyberattack wave: mostly claims, barely any confirmations
Since regional military escalation began in February 2026, cyberattack volume
across the Gulf has risen 15 to 25 times baseline levels. Banks,
airports and telecoms have been named in claim after claim — but
almost none of them have confirmed anything publicly. This page
separates the measurable from the merely claimed.
⚠️ Read this before anything else. This case
file covers a different kind of story than most others on this site. It isn't one breach —
it's a wave of claimed attacks tied to regional military escalation since February 2026,
and almost none of the named institutions have confirmed anything publicly.
What's measurable is the rise in attack volume; what's claimed — specific banks, specific
breaches — is, in nearly every case, unconfirmed.
What's measurable, and what's only claimed
15×
Increase in cyber-activity volume reported in the UAE after
military operations began, versus baseline.
Cybersecurity threat reporting, Feb–Mar 2026.
25×
Equivalent increase reported for Saudi Arabia over the same
period.
Cybersecurity threat reporting, Feb–Mar 2026.
600-800K
Daily breach attempts reported in the UAE during peak escalation,
up from a 90–200K baseline.
Cybersecurity threat reporting, Feb 2026.
0
Named banks, airports or telecoms that have publicly
confirmed a breach, among those cited in attack claims.
As of 08/21/2026, per available reporting.
Timeline
CONFIRMED (VOLUME)
February 2026
Regional military escalation triggers a measurable,
order-of-magnitude rise in cyberattack attempts across the Gulf — UAE, Saudi Arabia,
and Qatar all report multi-fold increases over baseline activity. This volume increase
itself is corroborated by threat-intelligence reporting; it does not by itself confirm
any specific successful breach.
CLAIMED
February 28, 2026 onward
Iran-nexus threat actors reportedly scan internet-connected
cameras across Israel, UAE, Qatar, Bahrain, Kuwait, and Cyprus for known
vulnerabilities. DDoS campaigns attributed to groups such as "DieNet Network" target
government portals, telecom providers, airports, and financial institutions across
Bahrain, Qatar, UAE, Kuwait, and Saudi Arabia.
CLAIMED
March 2026
Coordinated attack claims name Saudi Arabia's Riyad Bank and
Al Rajhi Bank, Kuwait International Airport, Bahrain's Batelco, UAE telecom operator
du, and multiple GCC government ministries. None of these institutions has publicly
confirmed a breach, according to available reporting.
CLAIMED
June 2026
A threat actor using the handle "Ddarknotevil" claims to have
stolen over 360GB from du, the UAE telecom operator, allegedly including employee
emails, network logs, device and IP details for 371,000 customers, and proprietary
telecom software. du has not publicly responded, per reporting at the time.
⚔️Why this looks so different from SFR or Bloctel
Elsewhere on this site, a claim usually gets tested against a company statement, a
regulator filing, or a wire-service report within weeks. Here, the driving force is an
active regional conflict: DDoS disruption, defacements, and hacktivist messaging serve
goals — visibility, disruption, propaganda — that don't require the same kind of proof a
financially motivated data thief needs to sell stolen records. That changes the
incentive to confirm or deny publicly, on both sides.
What it changes for you
If you hold an account with any Gulf-region bank, airline, or telecom named in these
claims, the honest answer is: there is currently no official confirmation that
your data was affected. The baseline caution that applies everywhere else on this
site still applies here — an unsolicited call or message citing your account, especially
one creating urgency, deserves the same scrutiny regardless of whether a breach behind it
is ever confirmed. See From Leak to Scam.
🔒 A high volume of attack attempts against a sector doesn't
mean your specific account is compromised — it means the baseline risk of impersonation
attempts referencing that sector is higher. Verify any account-related contact through
the institution's own official channel, never through a link or number in the message
itself. See how Medusa links channels together.
Frequently asked questions
Have Gulf banks and telecoms confirmed being breached?
Almost none have. Institutions named in attack claims have either not responded to
requests for comment or have not issued public confirmation. This page documents claims
and a measurable rise in attack volume, not confirmed breaches.
Is this the same kind of incident as SFR or Bloctel?
No. The Gulf wave mixes DDoS disruption, defacements, and hacktivist claims with
data-theft claims, driven by regional conflict. It is far less confirmed, on average,
than the France-based incidents documented elsewhere on this site.
What should someone with accounts at Gulf institutions do?
Given the low rate of official confirmation, the same baseline caution applies: treat
unsolicited contact referencing your account with suspicion, and verify through official
channels only.
📌 Last checked: August 21, 2026. This page will
be updated if any named institution issues an official confirmation. Verifiable
information to report: contact@egidio.app.
Cite this pageEgidio — The Threat Laboratory, "The Gulf's cyberattack wave: mostly claims, barely any confirmations," egidio.app/en/laboratoire/gulf-cyberattack-wave/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.