AI-generated deepfakes, social media disinformation, and IoT-based attacks are among evolving cyber threats facing MENA organizations
Last Update: Monday, April 1, 2019 : 14:14 (+4GMT)
Dubai, United Arab Emirates, 1 April 2019: As technology development and deployment continues throughout the Middle East and North Africa (MENA) region, cyber threats are also evolving, moving beyond attacks such as phishing, denial-of-service, and credential compromise to encompass new threats that are challenging companies and organizations. To combat these threats, entities need to shift cybersecurity approaches away from simply focusing on security compliance to developing a holistic culture of proactive security across the broader enterprise, according to Booz Allen Hamilton. The 2019 MENA Cyber Threat Outlook Report highlights key threat trends that organizations in the region need to be aware of to help prevent cybersecurity incidents, avoid reputational damage and financial losses stemming from breaches, and stay security-conscious in an ever-shifting threat environment.
Ziad Nasrallah, Principal at Booz Allen Hamilton, said: “The region’s cyber defenders increasingly must anticipate and plan for cyber attacks resulting from emerging technologies such as artificial intelligence. Understanding industry best practices and internal mitigation strategies is invaluable to combating cyber attacks. This includes proactive planning, integrating intelligence-driven threat detection, securing networks and databases, and conducting regular vulnerability scans.”
Jay Townsend, Principal at Booz Allen Hamilton, added: “Even small cyber incidents can cause major economic and reputational damage. MENA organizations should consider more advanced defense measures, including moving away from traditional security operations center constructs, and instead, investing in a
Cyber Fusion Center (CFC). The CFC model is threat-focused, driven by a real-time threat intelligence process that informs detection and hunting activities and facilitates rapid tactical coordination. Rather than be completely reliant on tools, CFCs leverage cutting-edge technologies to further strengthen the human element through the automation and orchestration of cybersecurity processes. Moreover, it fosters a culture of collaboration, continuous testing, and learning across teams both inside and outside the Center.”
Booz Allen Hamilton outlines the following cyber threat trends and recommendations for proactive defense:
1. Stay a step ahead in the AI game
Artificial Intelligence (AI) technology is increasingly deployed by threat actors in cyber operations, such as using AI-augmented malware to evade antivirus detection software or automate brute force attacks. However, one of the most prevalent emerging AI-driven cyber threats is the use of videos, dubbed “deepfakes,” that exploit AI systems to create believable, but fake, videos depicting individuals saying or doing things that never occurred. These videos can be used to spread false and misleading information, discredit or damage the reputation of brands and organizations, and more. As cybersecurity and IT teams are the first points-of-contact for suspicious content, teams must monitor the threat environment and be trained to proactively identify and escalate threats in partnership with enterprise risk management teams. Additionally, it is crucial for organizations to engage leadership in trainings to practice managing reputational risks associated with fallout from attacks of this nature.
2. Be aware of ecommerce risks
As Booz Allen and others have often observed, mobile apps, digital payments, and ecommerce platforms are expanding rapidly in the MENA region. In parallel, cybercriminal organizations are constantly looking for new ways to monetize the theft of sensitive information belonging to private sector companies and customers. In April 2018, Careem, a popular regional ride-hailing service, announced that unknown threat actors accessed customer data, which affected an estimated 14 million users. The successful attack is just the latest in a growing list of cyber attacks that demonstrates not only cybercriminals’ sophistication but also a growing interest in targeting and breaching organizations in the MENA region. It is important to ensure that databases are properly secured and encrypted, with regular vulnerability and compliance scanning, and properly configured intrusion prevention and detection technology to protect payment management systems and data repositories.
3. Invest in strengthening critical infrastructure
Attacks against critical national infrastructure (CNI) entities are attractive to state-sponsored attackers because of the physical, social, and economic damage they can cause. Additionally, industry tradecraft secrets and intellectual capital held by companies operating in CNI sectors are lucrative targets for both state-sponsored actors and cybercriminals. Hackers have targeted oil and gas facilities in the region, most notably in the Triton and Shamoon attacks, while cyber espionage incidents are also increasing – evidenced by cyber breaches at dams and water facilities in the United States. Implementing secure architectures with multi-level segmentation for information and operational technology systems (IT and OT) alongside Network Security Monitoring can improve defenses as threat actors enhance their attack capabilities. In the Triton attack, malware targeted Safety Instrumented Systems at one of the largest oil and gas firms in the MENA region, allowing attackers to load malicious code onto infected systems. Monitoring could have provided early attack detection and well-defined architectures would have limited attackers’ ability to move throughout the company’s infrastructure.
4. Prepare for increasing disinformation on social media
The widespread and growing popularity of social media applications in the region is creating a fertile environment for disinformation. Both state-sponsored and cybercriminal entities are refining and deploying tactics, techniques, and procedures to manipulate public opinion, influence decision-making processes, and damage companies. These attacks range from orchestrating targeted breaches followed by public data leaks to employing troll armies to push disinformation on social media. While media narratives about the threat have focused heavily on Russia’s use of disinformation, countries and groups around the world are rapidly developing similar tools that can easily be turned against companies and other entities. People, organizations, and governments must remain acutely attuned to the reputational damage and financial consequences of such attacks – as well as the speed with which such incidents can spread beyond control.
5. Be vigilant of the risks associated with IoT
As the Internet-of-Things (IoT) environment expands due to increasing device connectivity and deployment, the growing IoT attack surface means threats both exploiting and targeting the sector are escalating in parallel. Weaknesses in wireless routers, such as weak passwords and lax security controls makes routers a prime entry point into IT infrastructure that threat actors can exploit to infect IoT device networks. Openings in IoT networks vulnerable to cyber intrusions include smart televisions, internet-connected cameras, printers, kitchen appliances, and electronic home assistant devices, among others. Such attacks have already been used to establish botnets – indeed in 2018, the Andromeda botnet used social media to spread malware to more than a million new devices per month throughout the Middle East and Europe. Guarding against IoT-focused attacks requires strong password policies, strict adherence to security practices such as updating software and implementing patches, and regular vulnerability and compliance scans of enterprise networks.
Previous Article
LG prepares to show how AI will benefit homes in MEA
Next Article
FRENCH TECH TOUR from April 1 to 3, 2019 In the United Arab Emira...
Most Viewed – Last 30 Days
- Five ways Emirates is helping customers travel with greater confidence... [2063-Views]
- UAE International Investment Council Holds Second Board Meeting, Appointing Ke... [1631-Views]
- Sheikh Zayed Falcon Release Programme releases 2,400+ falcons in the wild sinc... [1595-Views]
- MS Dhoni Joins Malabar Gold & Diamonds as Brand Ambassador, Strengthening the ... [1406-Views]
- Fertiglobe More Than Doubles Adjusted EBITDA in Q2 2026, Proposes H1 2026 Divi... [1134-Views]
- e& UAE launches Business Pro AI bundled with Microsoft Copilot at no additiona... [1134-Views]
- e& UAE leads industry transition to 5G-native IoT with successful testing of R... [1072-Views]
- How to Choose the Right Medical Insurance in Dubai Based On Your Lifestyle?... [1012-Views]
- Held under the patronage of His Highness Sheikh Hamdan bin Zayed Al Nahyan Ab... [958-Views]
- Tadej Pogacar Chases Tour de France–Vuelta a Espana Double... [921-Views]
- Beautyworld Dubai's 30th Edition Brings Global BeautyIcons Together This Octob... [903-Views]
- Qualcomm Announces Third Quarter Fiscal 2026 Results... [801-Views]
- TCL Extends its Global Leadership from Television to Air Conditioning with Lau... [795-Views]
- To enhance quality of sports services Ministry of Sports organises the first ... [787-Views]
- Dubai Summer Surprises Launches First Back-To-School Carnival at Palm Jumeirah... [782-Views]
- e& reports 11.6% increase in consolidated revenue to AED 38.1 billion in H1 20... [768-Views]
- The Fellowship Just Got a Glam Upgrade with SHEGLAM X The Lord of the Rings™... [726-Views]
- Danube Properties Announces Handover of 11 Projects In Dubai Over Next 12 Mont... [725-Views]
- Dubai Summer Surprises to reward 10 lucky shoppers with Modesh Scholarships wo... [721-Views]
- LG EMPOWERS DESIGNERS AND VIDEOGRAPHERS WITH NEW ULTRAFINE EVO 6K MONITOR... [706-Views]





