In the first half of 2025, the UAE and Saudi Arabia featured prominently in global cyber-attack rankings, as financially-motivated threats—including ransomware and extortion—surpassed espionage for organisations across the region.
In its sixth annual Microsoft Digital Defense Report, covering the period July 2024 through June 2025, Microsoft reveals a striking shift in the nature of cyber-threats confronting businesses and governments alike. Among the main findings: more than 52 % of cyber-incidents with known motives were driven by financial gain via extortion or ransomware, while attacks motivated purely by espionage made up only about 4 %.
In the Middle East and Africa region during the first half of 2025, the United Arab Emirates ranked 9th globally and 2nd in the region for the frequency of customers impacted by cyber activity, accounting for approximately 11.7 % of the affected customers in that region. Meanwhile the Kingdom of Saudi Arabia ranked 23rd globally and 5th in the region, accounting for roughly 5.6 % of impacted customers.
Microsoft also reports that its security systems process more than 100 trillion signals daily, block about 4.5 million new malware attempts each day, analyse 38 million identity-risk detections, and screen 5 billion emails for malware or phishing. Advances in automation and availability of off-the-shelf tools mean that even low-skill actors now operate at scale; the rise of AI is further accelerating attacks—from phishing to ransomware.
The trend is clear: criminals seeking profit now dominate the cyber-landscape. Critical services—hospitals, local governments, transportation—are prime targets because they have limited incident-response capabilities and must often restore operations rapidly. Meanwhile, nation-state actors remain active, but are fewer in number and more narrowly focused, often blending espionage with financial motives and sometimes leveraging the cybercriminal ecosystem.
For identity-based attacks, more than 97 % are password attacks, and identity attacks in the first half of 2025 surged by 32 %. Implementation of phishing-resistant multifactor authentication (MFA) can block over 99 % of identity-based attacks.
The regional data underscores how the Middle East is firmly embedded within the global cyber-threat ecosystem. The UAE’s 11.7 % share of impacted customers in the region and Saudi Arabia’s 5.6 % share demonstrate the concentration of risk in leading Gulf states. That is consistent with the broader global picture: financially-motivated cybercrime is flourishing.
With over half of known-motive attacks driven by extortion/ransomware (52 %), the shift away from pure espionage (4 %) means the threat model for businesses and public services is changing. Rather than purely secretive state-spying, organisations large and small must deal with high-volume, profit-driven adversaries that exploit automation, AI and commoditised tooling.
The targeting of critical public services means societal risk is high. A successful ransomware attack on a hospital can delay emergency care, disrupt transportation systems, cancel school classes, or halt local government operations. The destructive potential is real and multiplying.
On a macro level, this change implies that cyber-risk is not just an information-technology issue but a strategic business and national security issue. For the region, with its rapid digitisation, high internet penetration and large ambitious public projects (smart cities, digital government), the stakes are higher.
Taking identity risk: the fact that over 97 % of identity attacks are password-based means that human credentials remain the weakest link. The surge of 32 % in identity attacks in H1 2025 shows that the problem is accelerating.

Finally, as AI is being used by both attackers (to automate phishing, create synthetic media) and defenders (to detect threats), the balance of power may be shifting. However, defenders must adopt AI and modern strategies quickly or risk falling behind.
What it Means for Businesses / Individuals
For businesses in the Middle East and beyond:
- Treat cybersecurity as a strategic business priority, not just an IT function. The fact that critical services are being targeted means board-level attention and investment are essential.
- Assume attacks will happen: build resilience in operations, not just prevention. Ransomware-resilient backups, segmented networks, incident-response plans matter.
- For identity and access management: deploy phishing-resistant MFA (which blocks over 99 % of identity-based attacks). Also monitor credential leaks, password reuse, privileged access.
- Use threat intelligence and real-time telemetry: as Microsoft processes 100 trillion signals a day, small organisations should use managed services or partner with specialists to gain visibility.
- Secure supply chains and critical sectors: because adversaries now leverage even smaller companies as pivot points, small- and medium-enterprises cannot assume they are too small to be targeted.
- For individuals: use strong unique passwords or passkeys, enable MFA everywhere you can, be aware of phishing attempts (especially those using synthetic media or deepfakes).
- Businesses operating in or from the Middle East should consider the heightened regional risk: the UAE’s 11.7 % share of affected customers suggests that digital ecosystems here are under pressure and must build stronger defences.
The cyber-threat landscape in the Middle East is evolving rapidly—driven less by state espionage and more by financially-motivated ransomware and extortion. Leading states like the UAE and Saudi Arabia are among the global top-affected, which emphasises that no organisation, large or small, is outside the risk perimeter. The surge in identity attacks, the weaponisation of AI, and the targeting of critical public services all point to a future where cyber-resilience must become embedded in both business strategy and everyday individual behaviour. Legacy defences are no longer enough: organisations must modernise, collaborate, and treat cybersecurity as a continuous, adaptive process.
Read more: Middle East: Extortion and ransomware drive over half of cyberattacks – Source EMEA
