DDoS attacks in the Middle East and North Africa continued to grow at an unprecedented rate in Q2 2026. According to our data, attack volume increased by 288% year over year, following a record 574% surge in Q1.

The quarter was also marked by the dominance of politically motivated campaigns: hacktivists accounted for 83% of all DDoS activity in the region. At the same time, threat actors relied on larger botnets, longer campaigns, and increasingly complex multi-vector techniques.
This report examines the main DDoS trends observed across MENA in Q2 2026, including the industries and countries targeted most frequently and the tactics used by threat actors.
The Big Picture
Q2 2026 saw another major escalation in DDoS activity across MENA:
- DDoS attacks in MENA increased by 288% YoY, following the record 574% rise in Q1.
- StormWall mitigated more than 85,000 attacks in the Middle East between April 1 and June 30, 2026.
- Hacktivists accounted for 83% of all attacks in the region.
- Multi-vector attacks increased by 148% YoY.
- Probing attacks increased by 122% YoY.
- The average botnet used in campaigns tripled in size, from 12,000 to 36,000 devices.
- The average campaign duration increased fivefold, from 30 to 150 minutes.
- The longest incident mitigated by StormWall lasted 9 days.
- The UAE, Saudi Arabia, and Iran were the most frequently targeted countries, accounting for 27%, 19%, and 14% of all incidents, respectively.
DDoS Attacks Increased by 288% YoY
According to StormWall’s data, the overall volume of DDoS attacks in MENA increased by 288% compared with Q2 2025. This follows a record-breaking 574% year-over-year rise in Q1 2026, meaning that DDoS activity in the region has remained at exceptionally high levels for two consecutive quarters.
The geopolitical situation remained a major factor shaping the regional threat landscape throughout Q2. Periods of heightened tensions and temporary pauses were accompanied by changes in cyber activity, with another escalation observed in early June.
The result was a second consecutive quarter of triple-digit growth in malicious traffic campaigns across MENA.
Hacktivists Behind 83% of All Attacks
Politically motivated actors were responsible for 83% of all DDoS attacks observed by StormWall in MENA during Q2. Commercial campaigns, including extortion, competitive sabotage, and other financially motivated activity, accounted for the remaining 17%.
A large share of this activity came from pro-Iranian hacktivist groups targeting government organizations and businesses in countries aligned with the US.
Iran itself also came under sustained pressure from pro-American and pro-Israeli actors. One of the most visible incidents occurred in mid-June, when a coordinated campaign against a shared interbank platform disrupted card payments, online banking, ATMs, and petrol-station transactions across the country.
The data shows that DDoS attacks in MENA are increasingly being used not only for financial gain but also as a tool for disruption and political messaging.
Multi-Vector Attacks Increased by 148% YoY
This was the second consecutive quarter in which such campaigns grew faster than almost every other category. Their increasing popularity can be partly attributed to the growing use of DDoS-for-hire platforms.
Many of these services come with preconfigured multi-vector attack modes, allowing operators with limited technical skills to launch campaigns targeting several network and application layers simultaneously.
For defenders, this creates an additional challenge: campaigns can combine multiple vectors or switch between them, making mitigation more complex.
Probing Attacks Increased by 122% YoY
These low-volume campaigns are used to test a target’s defenses, identify weak points, and determine how security systems respond before a larger operation is launched.
The growing number of such attempts suggests that attackers are increasingly treating reconnaissance as a standard part of DDoS campaigns. Rather than immediately launching a large-scale flood, threat actors can first map a target’s defenses and then direct subsequent operations at the weakest points.
Network Protection from DDoS Attacks
- Activate protection within 10 minutes
- 24/7 technical support
Botnets Tripled in Size
The average botnet observed in campaigns mitigated by StormWall in MENA increased from approximately 12,000 to 36,000 devices, tripling year over year.
The growth reflects the broader industrialization of the DDoS ecosystem. Botnets are becoming larger and increasingly available through DDoS-for-hire platforms, lowering the barrier to launching large-scale campaigns.
Larger networks of compromised devices create an additional challenge for defenders. Traffic generated by a more distributed infrastructure can be harder to filter because requests originate from a wider range of IP addresses and geographic locations.
As a result, simple blocking strategies such as geofencing become less effective against increasingly distributed operations.
Average Attack Duration Increased by 400%
The average duration of DDoS campaigns mitigated by StormWall in MENA increased from around 30 minutes to 150 minutes in Q2 2026. The longest incident mitigated by StormWall during the quarter lasted 9 days.
This represents a notable deviation from the broader global trend toward shorter campaigns. One possible explanation is the dominant role of hacktivism in the region: politically motivated operations are often designed to keep services unavailable for as long as possible, turning an outage into a visible public statement.
Most Targeted Industries
Government organizations remained the most targeted sector in MENA, accounting for 28% of all DDoS activity in Q2. Telecommunications ranked second with 21%, followed by finance at 18%.

Government organizations also recorded the highest year-over-year increase, with activity growing by 316%.

Compared with Q1 2026, several significant shifts occurred:
- The share of activity directed at the government sector increased from 21% to 28%, while volumes grew by 316% YoY.
- Telecommunications rose from 12% to 21%. Gulf carriers remained under persistent pressure throughout the quarter, as disrupting a telecom operator can create highly visible consequences for large numbers of users.
- Finance increased from 14% to 18%.
- Transportation nearly tripled, rising from 5% to 14%. With maritime and aviation infrastructure under pressure during the quarter, these sectors became increasingly attractive to threat actors.
- Oil declined from 8% to 4%.
- Healthcare and education remained among the least affected sectors, with YoY growth of 32% and 19%, respectively.
Relative Risk of DDoS by Industry
The distribution of incidents also provides an indication of the relative likelihood of an organization being targeted within the MENA region.

Note: This is a relative risk within the MENA region based only on the observed distribution of incidents. Real-world exposure also depends on factors such as an organization’s attack surface, security posture, and the interests of individual threat actors.
In Detail: Top 3 Most Attacked Verticals
Government Sector
The government sector was the most targeted vertical in MENA for the second consecutive quarter. Activity against government organizations increased by 316% year over year, the highest growth rate recorded among all industries.
TCP floods were the most common vector:

Telecommunications
Telecommunications became the second most targeted industry in MENA in Q2, accounting for 21% of all DDoS activity. The sector saw a 203% YoY increase.
Hacktivists heavily targeted carrier and ISP infrastructure using volumetric network-layer floods and UDP-based amplification techniques.

The high share of network-layer incidents reflects the focus on disrupting carrier and ISP infrastructure. Telecom providers are particularly attractive to hacktivists because an outage can affect large numbers of users and generate significant public attention.
Finance
Finance was the third most targeted sector in Q2, accounting for 18% of all attacks. DDoS activity against financial organizations increased by 148% YoY.
The sector experienced a mix of network- and application-layer campaigns, with attackers frequently targeting login pages, transaction APIs, and mobile banking endpoints.

The relatively high share of HTTP floods makes finance the most application-layer-heavy vertical among the three largest targets.
DDoS Attacks by Country
The UAE remained the most targeted country in MENA in Q2 2026, accounting for 27% of all attacks. Saudi Arabia ranked second with 19%, while Iran entered the top three with 14%.

The UAE
The UAE remained the most targeted country in MENA for the second consecutive quarter. Activity directed at the country increased by 268% year over year, while its share of regional DDoS activity rose slightly from 26% in Q1 to 27% in Q2.
Banks, government portals, and airports appeared consistently among hacktivist targets throughout the quarter.
Saudi Arabia
Saudi Arabia was the second most targeted MENA country, accounting for 19% of all attacks. The volume rose by 214% year over year, while the country’s share of regional DDoS activity climbed from 12% in Q1 to 19% in Q2.
Iran
Iran became the third most targeted MENA country, with a 14% share of all DDoS attacks. Activity against the country increased by 312% year over year, the highest growth rate recorded by StormWall in MENA during Q2.
The country faced campaigns from politically motivated actors on opposing sides of the broader regional conflict, including pro-American and pro-Israeli groups.
Israel
Israel accounted for 12% of all attacks, up from 7% in Q1. The volume increased by 306% year over year, making Israel the country with the second-highest growth rate in the region after Iran.
The country remained a prominent declared target for pro-Iranian hacktivist coalitions.
How the Country Ranking Changed
Compared with Q1 2026, the distribution of activity changed considerably:
| Country | Q1 2026 | Q2 2026 | Change |
| The UAE | 26% | 27% | = |
| Saudi Arabia | 12% | 19% | ↑ |
| Iran | — | 14% | New |
| Israel | 7% | 12% | ↑ |
| Qatar | 14% | 10% | ↓ |
| Kuwait | 12% | 8% | ↓ |
| Bahrain | 19% | 6% | ↓ |
| Jordan | 3% | 3% | = |
The UAE retained the top position, while Saudi Arabia and Israel saw their shares increase significantly. Iran entered the ranking in third place, reflecting the sharp escalation of DDoS activity against the country during the quarter.
Conclusion
DDoS activity in MENA remained at exceptionally high levels in Q2 2026, with volumes increasing by 288% year over year following the record growth seen in Q1.
The threat landscape was dominated by politically motivated campaigns, with hacktivists responsible for 83% of all attacks. At the same time, adversaries continued to increase the scale and persistence of their operations: the average botnet tripled in size, while the typical campaign lasted five times longer than a year earlier.
The growing use of multi-vector techniques and probing campaigns points to a DDoS ecosystem that is becoming both more accessible and more sophisticated. DDoS-for-hire platforms lower the technical barrier to launching complex operations, while larger botnets make traffic more distributed and harder to filter using simple blocking techniques.
“For organizations operating across MENA, the combination of high volumes, politically motivated campaigns, and increasingly distributed infrastructure creates a sustained risk. Effective protection therefore needs to handle not only large volumetric floods but also multi-vector operations, application-layer traffic surges, and prolonged incidents,” said Ramil Khantimirov, CEO and Co-Founder of StormWall.
StormWall experts recommend that businesses and government organizations operating in the region implement modern DDoS protection capable of detecting and mitigating threats across all major layers and vectors.
Author: Yulia Ilyina, Technical Expert at StormWall
DDoS Protection for Websites
- Activate protection in 10 minutes
- 24/7 technical support















