Identity Based Cyberattacks in the GCC: What the 2026 Data Says to Fix First

Nearly 9 in 10 incidents investigated by Unit 42 in 2025 involved an identity weakness, and 65% of initial access started with an identity based technique rather than malware. For organizations regulated under SAMA, NCA, DESC/ISR or CBK CORF, that shifts the priority from patching software to governing who and what can log in.
What is an identity based attack?
It’s an intrusion that relies on stolen credentials, hijacked sessions, MFA bypass or over permissioned accounts to gain and expand access, instead of exploiting a software flaw. The attacker doesn’t break in. They log in.
How common are identity based attacks right now?
Identity weaknesses played a material role in almost 90% of the incidents Unit 42 investigated in 2025, and 65% of initial access came through an identity based route [1]. The breakdown:
- Identity related social engineering: 33% (phishing 22%, other social engineering 11%)
- Credential misuse and brute force: 21% (compromised credentials 13%, brute force 8%)
- Identity policy and insider risk: 11% (IAM misconfiguration 3%, insider misuse 8%)
Why does this matter more for GCC organizations specifically?
Banks under SAMA’s Cyber Security Framework, entities under the NCA Essential Cybersecurity Controls, Dubai government bodies under DESC/ISR and Kuwaiti banks under CBK CORF are all audited on access control domains already. A stolen credential creates the same regulatory exposure as an unpatched server, and GCC’s fast move into cloud and SaaS banking has widened the number of identities attackers can target.
What are the biggest identity gaps attackers exploit?
- Standard MFA that can be phished or bypassed through session hijacking
- Service accounts and API keys that never get rotated
- Admin access left standing long after a project ends
- Cloud roles with far more permission than the job requires. Unit 42 found 99% of cloud identities reviewed carried excessive permissions, some unused for over 60 days [1]
How can GCC organizations close these gaps?
- Move privileged and admin accounts to phishing resistant MFA (FIDO2 or passkeys)
- Inventory every machine identity and service account, then rotate credentials on a fixed schedule
- Shorten session lifetimes and apply conditional access based on device and location risk
- Remove standing admin rights and require time bound, approved elevation instead
- Run identity focused penetration testing alongside your regular assessment cycle
Where does this sit inside an existing ISO 27001 or CBK CORF program?
It doesn’t require a new program. Identity controls already map to the access control domain in ISO 27001 and the identity and access domain in CBK CORF. What changes is where the budget and attention go this year.
DTS Solution runs identity focused assessments through vCISO Advisory and GRC Managed Services, and monitors identity signals continuously through HawkEye CSOC. Reach us at [email protected].