Desk live·
ForensicPost
Nation-state/Analysis/File 25-1021

Extortion Drove More Than Half of Middle East Cyberattacks in 2025

Research published in October 2025 found extortion and ransomware driving more than half of Middle East cyberattacks. In a region defined by state conflict, the majority of activity was criminal.

Constructed geometry · not a chart of case data
TargetMiddle East organisations
ActorMultiple
D. Kennedy11 min readConfidence: medium2 sources reviewed

Research published in October 2025 found that extortion and ransomware accounted for more than half of cyberattacks observed across the Middle East.

The Framing Is Usually The Other Way Round

Coverage of Middle East cyber activity is dominated by state operations: Iranian intrusion sets, regional conflict, critical infrastructure targeting. That is the material at 25-0731 and it is real.

A majority-criminal composition says something different. Organisations in the region are, on this measure, most likely to encounter the same ransomware-as-a-service ecosystem recorded at 25-1226 as organisations anywhere else.

Geopolitical exposure is additive rather than substitutive. It does not displace ordinary criminal risk; it sits on top of it.

Which Matters For How Defence Is Funded

An organisation that believes its threat is a national intelligence service will invest differently from one that believes its threat is an affiliate with purchased access. The first argues for exotic capability; the second argues for the unglamorous controls this corpus keeps finding absent — volumetric alerting at 25-0612, connected-application inventories at 25-1207, out-of-band payment verification at 25-0602.

If the majority of incidents are criminal, the second investment is the one that pays, and the framing pushes budgets toward the first.

The Usual Caution

Graded medium. This is vendor telemetry, and the classification of an attack’s motive is an interpretive act — the category-definition problem at 25-1203, where APT-classified incidents ran to nearly 4,000 in a regional dataset that never defined the term.

This is an analysis file

Built on published vendor research, listed below, subject to the telemetry caution at 26-0513. Motive classification is interpretive. Corrections: corrections@forensicpost.com.

Sources
  1. Middle East: extortion and ransomware drive over half of cyberattacksMicrosoft
  2. Middle East ransomware threats: banking and oil under siegeCyble
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary