MENA
Primarily a target
—
64 received·
38 initiated·
14 responses
·22 countries
This year to date, 76 new cyber operations involving MENA were added to the database: a 19% increase compared to the previous period. The number of operations is currently 3% below the long-term year-to-date average. The Intensity of cyber operations involving MENA over this year to date is declining to 3.2, compared with 3.3 in the same elapsed span of the previous year. This is above the all-time average for MENA of 2.4.
Maintained by EuRepoC research analysts · updated 05 Oct 2026
For this year to date, this region appears chiefly as a target — 64 incidents directed at it, 38 it is linked to initiating.
Source: EuRepoC Global Database as of 05 Oct 2026.
01 / 02
64 incidents · as targetCyber activity
Incidents directed at targets in MENA, and the responses they drew.
Cyber incident intensity
Mean3.3/15Moderate
Range 1.0–8.0
Drag the ends of the observed range to narrow intensities.
61 coded incidents · This year to date
Database additions by monthincidents against MENA
Bar height shows incidents added during this year to date; select a bar to filter this interval; hover for average intensity.
Most-targeted sectorswhat gets hit
SectorIncidentsIntensityResponded
Corporate Targets
3.1Moderate
3/18
Government / ministries
2.6Moderate
2/16
Unknown
2.7Moderate
1/13
Finance
3.1Moderate
1/11
Transportation
3.0Moderate
1/9
Telecommunications
3.5Moderate
2/8
Energy
4.0Moderate
2/8
Civil service / administration
3.4Moderate
2/7
Corporate Targets is the most-targeted sector — 18 of 64 incidents, 3 answered.
By originwho is behind activity against it
02 / 02
Incidents received & responses
Unknown
Israel
·Finance
Unknown Threat Actor Breached Israel's Largest Cryptocurrency Broker Bits Of Gold in August 2026
1 Aug 2026
Incident · Unattributed
1 Aug 2026
Unknown
Israel
·Finance
Unknown Threat Actor Breached Israel's Largest Cryptocurrency Broker Bits Of Gold in August 2026
Unknown
NLFRALAD+4145 countries
·Corporate Targets +1
Unknown Threat Actors Compromised Customer Data Of French Company CEVA Logistics Between 29 July and 1 August 2026
29 Jul 2026
Incident · Unattributed
29 Jul 2026
Unknown
NLFRALAD+4145 countries
·Corporate Targets +1
Unknown Threat Actors Compromised Customer Data Of French Company CEVA Logistics Between 29 July and 1 August 2026
CACZFRNZ+1216 statesjoint
LAUNDRY BEAR (Russian Federation)
International Partners Issued Joint Cybersecurity Advisory Warning of Russian State-Supported Laundry Bear's Phishing Campaign Targeting Zimbra Collaboration Suite Users on 23 July 2026
Technical disclosure
23 Jul 2026
Technical disclosure
23 Jul 2026
CACZFRNZ+1216 states
LAUNDRY BEAR (Russian Federation)
International Partners Issued Joint Cybersecurity Advisory Warning of Russian State-Supported Laundry Bear's Phishing Campaign Targeting Zimbra Collaboration Suite Users on 23 July 2026
Laundry Bear
#N/AUSATBE+2529 countries
·Government / ministries +4
Russia-Aligned Threat Actor TA488 aka LAUNDRY BEAR Stole Emails and Account Credentials from US and European Government Entities Since 22 July 2026
22 Jul 2026
Incident · Low severity
22 Jul 2026
Laundry Bear
#N/AUSATBE+2529 countries
·Government / ministries +4
Russia-Aligned Threat Actor TA488 aka LAUNDRY BEAR Stole Emails and Account Credentials from US and European Government Entities Since 22 July 2026
NLNetherlands Defence Intelligence and Security Service
one Russian intelligence and security se… (Russian Federation)
Dutch AIVD and MIVD Issued a Cybersecurity Advisory Related to Russian State Actors Compromising IP Cameras in Europe for Military Purposes , 10 July 2026
Official policy
10 Jul 2026
Official policy
10 Jul 2026
NLNetherlands Defence Intelligence and Security Service
one Russian intelligence and security se… (Russian Federation)
Dutch AIVD and MIVD Issued a Cybersecurity Advisory Related to Russian State Actors Compromising IP Cameras in Europe for Military Purposes , 10 July 2026
INC Ransom
USCOCHAE+185189 countries
·Unknown +2
INC Ransomware Group Exploited Zero-Day Vulnerability in Remote Access Gateway SonicWall SMA1000 Affecting Private and Governmental Organizations in Multiple Countries since 22 June 2026
22 Jun 2026
Incident · Low severity
22 Jun 2026
INC Ransom
USCOCHAE+185189 countries
·Unknown +2
INC Ransomware Group Exploited Zero-Day Vulnerability in Remote Access Gateway SonicWall SMA1000 Affecting Private and Governmental Organizations in Multiple Countries since 22 June 2026
USCybersecurity and Infrastructure Security Agency
Andorra
US CISA Issued an Alert on Hardening Compromised Fortinet Devices after Reports of Credential Exposures, 22 June 2026
Technical disclosure
22 Jun 2026
Technical disclosure
22 Jun 2026
USCybersecurity and Infrastructure Security Agency
Andorra
US CISA Issued an Alert on Hardening Compromised Fortinet Devices after Reports of Credential Exposures, 22 June 2026
GBUnited Kingdom’s National Cyber Security Centre
Andorra
UK National Cyber Security Centre Issued Guidance on Fortinet Firewalls and VPN Gateways Targeting on 19 June 2026
Technical disclosure
19 Jun 2026
Technical disclosure
19 Jun 2026
GBUnited Kingdom’s National Cyber Security Centre
Andorra
UK National Cyber Security Centre Issued Guidance on Fortinet Firewalls and VPN Gateways Targeting on 19 June 2026
Showing the 8 most recent of 74
Open all in advanced search