Research published in October 2025 found that extortion and ransomware accounted for more than half of cyberattacks observed across the Middle East.
The Framing Is Usually The Other Way Round
Coverage of Middle East cyber activity is dominated by state operations: Iranian intrusion sets, regional conflict, critical infrastructure targeting. That is the material at 25-0731 and it is real.
A majority-criminal composition says something different. Organisations in the region are, on this measure, most likely to encounter the same ransomware-as-a-service ecosystem recorded at 25-1226 as organisations anywhere else.
Geopolitical exposure is additive rather than substitutive. It does not displace ordinary criminal risk; it sits on top of it.
Which Matters For How Defence Is Funded
An organisation that believes its threat is a national intelligence service will invest differently from one that believes its threat is an affiliate with purchased access. The first argues for exotic capability; the second argues for the unglamorous controls this corpus keeps finding absent — volumetric alerting at 25-0612, connected-application inventories at 25-1207, out-of-band payment verification at 25-0602.
If the majority of incidents are criminal, the second investment is the one that pays, and the framing pushes budgets toward the first.
The Usual Caution
Graded medium. This is vendor telemetry, and the classification of an attack’s motive is an interpretive act — the category-definition problem at 25-1203, where APT-classified incidents ran to nearly 4,000 in a regional dataset that never defined the term.
Built on published vendor research, listed below, subject to the telemetry caution at 26-0513. Motive classification is interpretive. Corrections: corrections@forensicpost.com.