UAE Organisations Record 47% Year-on-Year Rise in Cyber Attacks in September as Global Attacks Jump 48%

Check Point Research, the threat intelligence arm of Check Point® Software Technologies Ltd., today released its Global Threat Intelligence insights for September 2026, revealing that organisations worldwide experienced an average of 2,803 cyber attacks per week, representing a 16% increase month on month and a 48% increase year on year. September’s data shows cyber pressure rising across multiple fronts: weekly attack volumes increased sharply, phishing became more prevalent, GenAI use continued to expand alongside sensitive-data exposure, and ransomware remained well above last year’s level.
In the UAE, organisations experienced an average of 2,521 cyber attacks per week in September 2026, marking a 47% increase year on year. The increase is broadly in line with the global trend, highlighting the sustained cyber pressure facing organisations in the country.
“September’s data shows cyber risk increasing in both volume and breadth,” said Omer Dembinsky, Data Research Manager at Check Point Research. “With attacks rising across every region, phishing becoming more frequent, ransomware remaining elevated and GenAI use expanding alongside sensitive-data exposure, security teams cannot rely on fragmented defences. They need prevention-first protection that combines visibility, control and automation across network, cloud, endpoint, email and AI usage to stop threats before they disrupt operations or expose sensitive information.”
Education Faces the Highest Attack Volume as the Academic Year Begins
Education remained the most targeted sector globally, averaging 6,656 weekly attacks per organisation, up 59% year on year and 24% from August. The increase coincided with the start of the academic year, when students, faculty, parents and other users reconnect to institutional networks. Telecommunications ranked second with 3,483 weekly attacks per organisation, up 29% year on year, followed by Government with 3,443, up 37%. The figures show sustained pressure on sectors with broad user bases, essential services and complex digital environments.
Latin America Tops Regional Attack Volumes as Europe Posts the Fastest Growth
Latin America recorded the highest regional attack volume in September, averaging 3,813 weekly attacks per organisation, up 35% year on year. Africa ranked second at 3,701 weekly attacks, followed by APAC at 3,593. Europe experienced the highest rate of growth, with attacks increasing 61% compared with September 2025, while North America rose 50%. Although Europe’s overall volume remained below that of the leading regions, it recorded the fastest growth of any region, signalling a rapidly intensifying threat environment.
GenAI Risk Expands Alongside Enterprise Use
Globally, one in every 39 enterprise GenAI prompts posed a high risk of sensitive data leakage, affecting 89% of organisations that regularly use GenAI tools. A further 14% of prompts contained potentially sensitive information. The average user generated 131 GenAI prompts during the month, a significant increase from August, while each organisation used an average of eight tools. Rising prompt volumes and a broader toolset make it increasingly important to understand what information employees share, where it is processed and which controls apply.
The exposure spanned core business information. Network and IT Infrastructure data appeared in GenAI prompts at 71% of organisations, followed by Financial Data at 70%, Legal and Regulatory data at 68%, Employee and HR data at 62%, and personally identifiable information at 60%. These percentages reflect the share of organisations where each category was observed, not the share of prompts, highlighting how everyday GenAI use can expose operational, financial, legal and personal information without adequate governance.
Business Services recorded the highest high-risk GenAI prompt exposure rate at 4.9%, or one in every 20 prompts, followed by Financial Services at 4.1% and Healthcare and Medical at 3.5%. Latin America had the highest regional rate at 4%, or one in every 25 prompts, above the global average of 2.5%. These differences reinforce the need for sector-specific AI governance, particularly in data-rich industries where employees routinely handle sensitive, regulated or proprietary information.
Phishing Activity Rises as Malicious Links Dominate Email-Based Threats
Email remained a key attack vector worldwide, with one in every 91 emails, or 1.1%, classified as phishing in September, up from one in every 112, or 0.89%, in August. Among phishing emails, 81% contained links and 11% contained attachments, confirming malicious links as the primary delivery method. North America recorded the highest regional phishing rate at 1.26%, or one in 79 emails. By industry, Associations and Nonprofits saw the highest rate at 2.17%, followed by Construction and Engineering at 2.05% and Real Estate, Rentals and Leasing at 1.38%.
Ransomware Victim Numbers Surge, with Business Services Bearing the Brunt
A total of 824 ransomware attacks were reported globally in September, representing a 53% increase compared with September 2025. Business Services was the most targeted industry, accounting for 31.3% of reported victims, followed by Consumer Goods and Services at 15.2% and Industrial Manufacturing at 11.0%. North America was the most affected region, accounting for 46% of reported incidents, followed by Europe at 25% and APAC at 17%. The concentration in Business Services reflects attackers’ continued focus on organisations that hold data or system access on behalf of multiple clients, where a single incident can create wider downstream disruption.
The Gentlemen Leads the Ransomware Rankings
The Gentlemen was the most prevalent ransomware group in September, responsible for 13% of published attacks. Qilin followed with 9%, while Akira accounted for 5%. On top of the leading three actors, 80 further extortion groups reported ransomware attacks last month, illustrating how the threat landscape remains fluid, with established actors maintaining pressure while fast-growing operations can quickly gain prominence.
For enterprises, September’s figures reinforce the importance of reducing exposure before it becomes business impact. A prevention-first approach, supported by AI-powered protection, shared intelligence and consistent governance, can help teams identify and block threats across networks, cloud environments, digital workspaces and AI systems while reducing complexity and securing AI adoption with greater confidence.



