RESEARCH PREVIEW — Attention: Data Spaces may hack the planet.

MENA

Analyse
Primarily a target — 750 received· 401 initiated· 93 responses ·22 countries

Across the full record, 885 cyber operations involving MENA were added to the database. The all-time mean Intensity of cyber operations involving MENA is 2.4.

Maintained by EuRepoC research analysts · updated 05 Oct 2026
750received initiated401
For all time, this region appears chiefly as a target — 750 incidents directed at it, 401 it is linked to initiating.
Source: EuRepoC Global Database as of 05 Oct 2026.
01 / 02

Cyber activity

750 incidents · as target

Incidents directed at targets in MENA, and the responses they drew.

Cyber incident intensity
Mean2.4/15Moderate
Range 1.0–11.0

Drag the ends of the observed range to narrow intensities.

743 coded incidents · All time
Database additions by yearincidents against MENA
Bar height shows incidents added during all time; select a bar to filter this interval; hover for average intensity.
Most-targeted sectorswhat gets hit
Government / ministries is the most-targeted sector — 251 of 750 incidents, 21 answered.
By originwho is behind activity against it
Iran, Islamic Republic of 148incidents avg 2.7 · Moderate China 80incidents avg 2.5 · Moderate Russia 51incidents avg 2.7 · Moderate Turkey 26incidents avg 1.9 · Moderate Korea, Democratic People's Republic of 23incidents avg 2.3 · Moderate Palestine 22incidents avg 2.4 · Moderate United States 17incidents avg 3.0 · Moderate Israel 13incidents avg 3.2 · Moderate
Showing 8 of 52
02 / 02

Incidents received & responses

Unknown Israel ·Finance Unknown Threat Actor Breached Israel's Largest Cryptocurrency Broker Bits Of Gold in August 2026 1 Aug 2026
Incident · Unattributed 1 Aug 2026
Unknown Israel ·Finance
Unknown Threat Actor Breached Israel's Largest Cryptocurrency Broker Bits Of Gold in August 2026
Unknown NLFRALAD+4145 countries ·Corporate Targets +1 Unknown Threat Actors Compromised Customer Data Of French Company CEVA Logistics Between 29 July and 1 August 2026 29 Jul 2026
Incident · Unattributed 29 Jul 2026
Unknown NLFRALAD+4145 countries ·Corporate Targets +1
Unknown Threat Actors Compromised Customer Data Of French Company CEVA Logistics Between 29 July and 1 August 2026
CACZFRNZ+1216 statesjoint LAUNDRY BEAR (Russian Federation) International Partners Issued Joint Cybersecurity Advisory Warning of Russian State-Supported Laundry Bear's Phishing Campaign Targeting Zimbra Collaboration Suite Users on 23 July 2026 Technical disclosure 23 Jul 2026
Technical disclosure 23 Jul 2026
CACZFRNZ+1216 states LAUNDRY BEAR (Russian Federation)
International Partners Issued Joint Cybersecurity Advisory Warning of Russian State-Supported Laundry Bear's Phishing Campaign Targeting Zimbra Collaboration Suite Users on 23 July 2026
Laundry Bear #N/AUSATBE+2529 countries ·Government / ministries +4 Russia-Aligned Threat Actor TA488 aka LAUNDRY BEAR Stole Emails and Account Credentials from US and European Government Entities Since 22 July 2026 22 Jul 2026
Incident · Low severity 22 Jul 2026
Laundry Bear #N/AUSATBE+2529 countries ·Government / ministries +4
Russia-Aligned Threat Actor TA488 aka LAUNDRY BEAR Stole Emails and Account Credentials from US and European Government Entities Since 22 July 2026
NLNetherlands Defence Intelligence and Security Service one Russian intelligence and security se… (Russian Federation) Dutch AIVD and MIVD Issued a Cybersecurity Advisory Related to Russian State Actors Compromising IP Cameras in Europe for Military Purposes , 10 July 2026 Official policy 10 Jul 2026
Official policy 10 Jul 2026
NLNetherlands Defence Intelligence and Security Service one Russian intelligence and security se… (Russian Federation)
Dutch AIVD and MIVD Issued a Cybersecurity Advisory Related to Russian State Actors Compromising IP Cameras in Europe for Military Purposes , 10 July 2026
INC Ransom USCOCHAE+185189 countries ·Unknown +2 INC Ransomware Group Exploited Zero-Day Vulnerability in Remote Access Gateway SonicWall SMA1000 Affecting Private and Governmental Organizations in Multiple Countries since 22 June 2026 22 Jun 2026
Incident · Low severity 22 Jun 2026
INC Ransom USCOCHAE+185189 countries ·Unknown +2
INC Ransomware Group Exploited Zero-Day Vulnerability in Remote Access Gateway SonicWall SMA1000 Affecting Private and Governmental Organizations in Multiple Countries since 22 June 2026
USCybersecurity and Infrastructure Security Agency Andorra US CISA Issued an Alert on Hardening Compromised Fortinet Devices after Reports of Credential Exposures, 22 June 2026 Technical disclosure 22 Jun 2026
Technical disclosure 22 Jun 2026
USCybersecurity and Infrastructure Security Agency Andorra
US CISA Issued an Alert on Hardening Compromised Fortinet Devices after Reports of Credential Exposures, 22 June 2026
GBUnited Kingdom’s National Cyber Security Centre Andorra UK National Cyber Security Centre Issued Guidance on Fortinet Firewalls and VPN Gateways Targeting on 19 June 2026 Technical disclosure 19 Jun 2026
Technical disclosure 19 Jun 2026
GBUnited Kingdom’s National Cyber Security Centre Andorra
UK National Cyber Security Centre Issued Guidance on Fortinet Firewalls and VPN Gateways Targeting on 19 June 2026
Showing the 8 most recent of 812 Open all in advanced search
Search