Saudi Arabia (SA) Threat Intelligence

SA

Saudi Arabia has 5,793 malicious IP addresses with 80,934 abuse reports. Top threat categories include suspicious activity, severe abuse, moderate threat, high threat, ssh bruteforce. Top attacking networks: Saudi Telecom Company JSC (2,012 IPs), Saudi Telecom Company JSC (906 IPs), Etihad Etisalat, a joint stock company (787 IPs). Data collected since 2024-03-13, last activity 2026-04-05.

Threat Assessment: Saudi Arabia exhibits moderate cyber threat activity, with a notable number of malicious IPs across multiple attack categories. The dominant attack types are suspicious activity, severe abuse, moderate threat. The majority of threats originate from networks operated by Saudi Telecom Company JSC and Saudi Telecom Company JSC.

Total Reports
80,934
Unique IPs
5,793
First Seen
2024-03-13
Last Activity
2026-04-05

Top Threat Categories

Suspicious Activity 4,829
Severe Abuse 1,003
Moderate Threat 356
High Threat 167
Ssh Bruteforce 26

Top Attacking Networks

AS25019 Saudi Telecom Company JSC
2,012 IPs
AS39891 Saudi Telecom Company JSC
906 IPs
AS35819 Etihad Etisalat, a joint stock company
787 IPs

Most Reported IPs in Saudi Arabia

8.213.42.221 207 reports
80.225.77.44 205 reports
8.213.26.239 205 reports
8.213.19.148 205 reports
185.51.206.75 204 reports

Access this data via API

Get Saudi Arabia threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/SA

View full API documentation

See how we classify and verify threats →

Check any IP from Saudi Arabia

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS25019 Intelligence AS39891 Intelligence AS35819 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...