Middle East faces new cyber reality: attackers logging in, not breaking in


The Middle East’s heightened geopolitical tensions are continuing to shape cyber activity across the region, as organisations face a combination of state-aligned operations, financially motivated threats and hacktivism.

Against this backdrop, governments and businesses across the UAE and wider region are also rapidly expanding their digital footprints through cloud adoption, artificial intelligence (AI) and increasingly connected infrastructure, creating new opportunities for attackers.

Roland Daccache, director of sales engineering for MENA at CrowdStrike, said the company has observed activity linked to both nation-state-aligned threat actors and hacktivist groups over the past year, including reconnaissance and distributed denial-of-service (DDoS) attacks.

“Much of the publicly claimed activity to date appears intended to disrupt, shape perception and signal capability alongside broader regional tensions, rather than demonstrate verified operational impact,” he said.

This distinction is particularly important during periods of geopolitical instability, when hacktivist groups can use exaggerated or unverified claims to generate attention and create the perception of widespread disruption.

At the same time, the techniques used by more sophisticated attackers are becoming harder for traditional security systems to identify. CrowdStrike’s 2026 Global threat report found that 82% of detections observed by the company in 2025 were malware-free, reflecting a wider shift towards attacks that exploit legitimate credentials and tools rather than deploying conventional malicious software.

“Adversaries are able to move at increasing speed across environments without triggering detections as they’ve shifted from breaking in to logging in,” said Daccache.

Attackers are increasingly using stolen credentials, social engineering and legitimate administrative tools to impersonate trusted users. This can allow them to operate inside corporate environments without generating the types of indicators that traditional malware-focused security products were designed to detect.

The speed at which intrusions can develop is adding further pressure on security teams. CrowdStrike has reported attacker breakout times – the period between an initial compromise and lateral movement into other systems – as little as 27 seconds.

For organisations in the Middle East, where governments and businesses are investing heavily in digital services and AI, such timescales leave increasingly little room for manual investigation after an alert has been generated.

Daccache said human-led threat hunting therefore remains an important component of detecting activity that automated systems may overlook. “Threat hunters play a critical role in stopping sophisticated adversaries by unifying AI-powered threat intelligence and tracking 24/7 hands-on-keyboard activity from malicious adversaries across industries and geographies,” he added.

The approach is based on proactively looking for attacker behaviour across endpoints, identities and cloud environments, rather than waiting for a predefined security alert.

CrowdStrike is also extending this model to organisations that use security technologies from other vendors. Its Falcon OverWatch for Defender service, for example, provides managed threat hunting for organisations running Microsoft Defender without requiring them to replace their existing endpoint protection.

According to Daccache, the service draws on intelligence from CrowdStrike’s Counter Adversary Operations team, which tracks more than 280 nation-state, cyber crime and hacktivist groups. Threat hunters combine this intelligence with automated detection technologies and behavioural analysis to look for activity associated with known adversary techniques, including threats that may not match established indicators of compromise.

The need for broader visibility is becoming increasingly significant as UAE organisations adopt AI across sectors, including government, financial services, energy and smart city infrastructure.

While AI is creating opportunities for organisations, it is also introducing another layer of infrastructure that security teams must monitor and protect. The challenge is compounded by the increasingly interconnected nature of corporate technology environments, where identities, cloud services, SaaS applications and endpoints can no longer be treated as separate security domains.

“Today, stopping breaches requires defending beyond endpoints, to identities, cloud environments and increasingly AI systems as a new, exposed attack surface,” said Daccache.

For organisations with limited internal security resources, managed detection and response services are also becoming an increasingly prominent part of the security landscape, particularly as the speed of attacks makes round-the-clock monitoring difficult to maintain internally.

Data sovereignty, meanwhile, remains an important consideration for governments and regulated industries in the Gulf. CrowdStrike has expanded its regional cloud deployment capabilities in the UAE, giving customers additional options to host data locally while remaining connected to the company’s wider threat intelligence infrastructure.

The broader challenge for organisations across the region will be adapting security operations to an environment in which attackers increasingly resemble legitimate users and can move through compromised infrastructure in seconds.

As traditional distinctions between endpoint, identity and cloud security continue to erode, organisations will need to focus not only on generating more alerts, but on identifying the behaviour and intent behind activity across their technology environments.

For the UAE and the wider Middle East, where digital transformation is advancing alongside an increasingly volatile geopolitical environment, the ability to detect those signals early could determine whether an intrusion is contained or develops into a wider breach.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *