RESEARCH PREVIEW — Attention: Data Spaces may hack the planet.

MENA

Analyse
Primarily a target — 64 received· 38 initiated· 14 responses ·22 countries

This year to date, 76 new cyber operations involving MENA were added to the database: a 19% increase compared to the previous period. The number of operations is currently 3% below the long-term year-to-date average. The Intensity of cyber operations involving MENA over this year to date is declining to 3.2, compared with 3.3 in the same elapsed span of the previous year. This is above the all-time average for MENA of 2.4.

Maintained by EuRepoC research analysts · updated 05 Oct 2026
64received initiated38
For this year to date, this region appears chiefly as a target — 64 incidents directed at it, 38 it is linked to initiating.
Source: EuRepoC Global Database as of 05 Oct 2026.
01 / 02

Cyber activity

64 incidents · as target

Incidents directed at targets in MENA, and the responses they drew.

Cyber incident intensity
Mean3.3/15Moderate
Range 1.0–8.0

Drag the ends of the observed range to narrow intensities.

61 coded incidents · This year to date
Database additions by monthincidents against MENA
Bar height shows incidents added during this year to date; select a bar to filter this interval; hover for average intensity.
Most-targeted sectorswhat gets hit
Corporate Targets is the most-targeted sector — 18 of 64 incidents, 3 answered.
02 / 02

Incidents received & responses

Unknown Israel ·Finance Unknown Threat Actor Breached Israel's Largest Cryptocurrency Broker Bits Of Gold in August 2026 1 Aug 2026
Incident · Unattributed 1 Aug 2026
Unknown Israel ·Finance
Unknown Threat Actor Breached Israel's Largest Cryptocurrency Broker Bits Of Gold in August 2026
Unknown NLFRALAD+4145 countries ·Corporate Targets +1 Unknown Threat Actors Compromised Customer Data Of French Company CEVA Logistics Between 29 July and 1 August 2026 29 Jul 2026
Incident · Unattributed 29 Jul 2026
Unknown NLFRALAD+4145 countries ·Corporate Targets +1
Unknown Threat Actors Compromised Customer Data Of French Company CEVA Logistics Between 29 July and 1 August 2026
CACZFRNZ+1216 statesjoint LAUNDRY BEAR (Russian Federation) International Partners Issued Joint Cybersecurity Advisory Warning of Russian State-Supported Laundry Bear's Phishing Campaign Targeting Zimbra Collaboration Suite Users on 23 July 2026 Technical disclosure 23 Jul 2026
Technical disclosure 23 Jul 2026
CACZFRNZ+1216 states LAUNDRY BEAR (Russian Federation)
International Partners Issued Joint Cybersecurity Advisory Warning of Russian State-Supported Laundry Bear's Phishing Campaign Targeting Zimbra Collaboration Suite Users on 23 July 2026
Laundry Bear #N/AUSATBE+2529 countries ·Government / ministries +4 Russia-Aligned Threat Actor TA488 aka LAUNDRY BEAR Stole Emails and Account Credentials from US and European Government Entities Since 22 July 2026 22 Jul 2026
Incident · Low severity 22 Jul 2026
Laundry Bear #N/AUSATBE+2529 countries ·Government / ministries +4
Russia-Aligned Threat Actor TA488 aka LAUNDRY BEAR Stole Emails and Account Credentials from US and European Government Entities Since 22 July 2026
NLNetherlands Defence Intelligence and Security Service one Russian intelligence and security se… (Russian Federation) Dutch AIVD and MIVD Issued a Cybersecurity Advisory Related to Russian State Actors Compromising IP Cameras in Europe for Military Purposes , 10 July 2026 Official policy 10 Jul 2026
Official policy 10 Jul 2026
NLNetherlands Defence Intelligence and Security Service one Russian intelligence and security se… (Russian Federation)
Dutch AIVD and MIVD Issued a Cybersecurity Advisory Related to Russian State Actors Compromising IP Cameras in Europe for Military Purposes , 10 July 2026
INC Ransom USCOCHAE+185189 countries ·Unknown +2 INC Ransomware Group Exploited Zero-Day Vulnerability in Remote Access Gateway SonicWall SMA1000 Affecting Private and Governmental Organizations in Multiple Countries since 22 June 2026 22 Jun 2026
Incident · Low severity 22 Jun 2026
INC Ransom USCOCHAE+185189 countries ·Unknown +2
INC Ransomware Group Exploited Zero-Day Vulnerability in Remote Access Gateway SonicWall SMA1000 Affecting Private and Governmental Organizations in Multiple Countries since 22 June 2026
USCybersecurity and Infrastructure Security Agency Andorra US CISA Issued an Alert on Hardening Compromised Fortinet Devices after Reports of Credential Exposures, 22 June 2026 Technical disclosure 22 Jun 2026
Technical disclosure 22 Jun 2026
USCybersecurity and Infrastructure Security Agency Andorra
US CISA Issued an Alert on Hardening Compromised Fortinet Devices after Reports of Credential Exposures, 22 June 2026
GBUnited Kingdom’s National Cyber Security Centre Andorra UK National Cyber Security Centre Issued Guidance on Fortinet Firewalls and VPN Gateways Targeting on 19 June 2026 Technical disclosure 19 Jun 2026
Technical disclosure 19 Jun 2026
GBUnited Kingdom’s National Cyber Security Centre Andorra
UK National Cyber Security Centre Issued Guidance on Fortinet Firewalls and VPN Gateways Targeting on 19 June 2026
Showing the 8 most recent of 74 Open all in advanced search
Search