International

Why is the Middle East losing so much money to cybercrime?

Hoang Bach September 4, 2024 11:15

Saudi Arabia and the UAE top a United Nations agency's global cybersecurity ranking. However, they also lose millions of dollars annually to cybercrime – and that number continues to rise.

70123489_1004.jpeg
Cyberattacks are on the rise in Gulf states, and cybercriminals are becoming increasingly sophisticated. Photo: PA

Why did this happen?

According to DW, cybercrime causes trillions of dollars in damage to governments and businesses every year, but the extent of the damage is not uniform across countries.

According to research funded by IBM, focusing on data breaches in 16 countries, in 2023, cybercrime in the Middle East caused an average loss of more than $8 million (equivalent to €7.2 million) per incident. The same study also found Saudi Arabia and the UAE to be the second-largest contributors to the world in terms of financial losses.

The cost of cybercrime in the UAE and Saudi Arabia has been rising for years. In 2018, the same annual study showed that the average cost of a cyberattack there was just $5.31 million.

DW argues that it's important to consider this increase in the context of the growing e-commerce sector and increasing internet usage, which has led to more local people using the internet than ever before. However, according to relevant ministries in Saudi Arabia and the UAE, they need to be well protected.

The International Telecommunication Union (ITU), a specialized agency of the United Nations, regularly publishes rankings of global cybersecurity capabilities, and in the most recent ranking from 2020, Saudi Arabia and the UAE topped the list.

However, experts argue that the rankings are based on information provided by the countries themselves, and although cybersecurity is increasingly valued in the region, there may still be a gap between the policies that Gulf states advocate and their actual effectiveness.

Screenshot 2024-09-04 at 10.11.04
The average cost of a data breach in the Middle East ranks second globally. Photo: DW

"The UAE, Saudi Arabia, and Qatar are doing very well in digitizing public services and also have thriving small and medium-sized enterprises," said Joyce Hakmeh, deputy director of the International Security program at Chatham House in the UK and an expert on cybersecurity policy.

"But as is often the case – and this is not unique to the Gulf region, but is happening all over the world – the digital transformation is happening so rapidly that it can affect the proper implementation of cybersecurity measures," he added.

"The Middle East is a hotspot for data breaches, primarily due to the fact that the digitization process is happening faster than the cybersecurity infrastructure can keep up," asserted Mohammed Soliman, director of the Strategic Technologies and Cybersecurity program at the Middle East Institute in Washington.

Extorting the world's richest people.

70123474_906.jpg
Illustrative photo: PA

The vast majority of cyberattacks worldwide are financially motivated, according to the American company Verizon in its 2024 Data Breach Investigations Report. And this is also true in the Middle East. According to Verizon, in the Middle East, Europe, and North Africa, 94% of cyberattacks are financially motivated, compared to only 6% that are politically motivated.

One of the most common methods used to extort money from organizations is the use of ransomware, a type of malware that encrypts or locks data until a ransom is paid.

Saudi Arabia and the UAE are home to some of the world's wealthiest institutions, including sovereign wealth funds and oil companies. According to a report by British cybersecurity firm Sophos, the companies most likely to be attacked by ransomware are those with the highest revenues.

70123462_906.jpg
In 2021, leaked data from a contractor working with Saudi Arabia's oil giant, Aramco, was offered to be sold to the company for $50 million. (Photo: PA)

Following a 2024 survey of 5,000 industry professionals, primarily in Europe, Sophos found that less than half of organizations with revenues under $10 million were attacked by ransomware. But this number rose to 67% when their revenues exceeded $5 billion annually.

Wealthier companies are also more likely to pay the full ransom, according to an anonymous Sophos survey. More than half of companies attacked by ransomware paid the ransom. But organizations with revenues over $5 billion typically pay the full amount demanded, while others may negotiate a lower price.

Other research suggests that the percentage of UAE companies deciding to pay the full ransom may be even higher, with a survey by a cybersecurity firm finding that around 84% of them agreed to pay the extortionists.

Cybercrime is rampant. But according to experts, what places Gulf states at the top of the list for the most costly incidents and losses can be explained by a combination of high-value targets, the rapid increase in digitalization and a lack of cybersecurity measures, along with the increasing sophistication of threat actors.

Hoang Bach