Reporting describes financial institutions across Saudi Arabia, the UAE and Qatar experiencing ransomware disruptions during 2025, with attackers exfiltrating financial records and threatening public leaks if demands were not met.
The Pattern Is The Global One
Exfiltration with a publication threat, rather than encryption for a decryption key, is the shift this desk recorded at 25-1204 for manufacturing: better encryption prevention does not reduce attacker revenue, it changes what the attacker sells.
Banks are unusually well defended against encryption — resilient architecture, tested recovery, regulatory pressure on continuity. They are not correspondingly protected against exfiltration, which resembles normal traffic and is harder to prevent than to detect.
What Is Missing Is What The Corpus Can Normally Rely On
For US and EU financial institutions this database has supervisory reporting, affected counts, cost figures and a near-census of incidents — the argument at 25-0616 that finance is the best-measured commercial sector.
Here there are no named institutions, no affected counts, no supervisory filings and no confirmed outcomes. The sector that is best measured in one jurisdiction is thinly recorded in another, which is a statement about supervisory publication rather than about the banks.
Graded Low
Vendor research describing a pattern without named institutions, dates or verified outcomes. This desk records it as an indication that the pattern exists in the region and as nothing more.
Compiled from published vendor research, listed below. No institutions are named and no outcomes are established. Corrections: corrections@forensicpost.com.