
Executive Intelligence Snapshot
Uways Qarani’s recent claims about the publication of a database belonging to Saudi Arabia’s General Intelligence Presidency (GIP) reinforces the assessment that the cyber-geopolitical risk surrounding Riyadh is increasing, although the authenticity, provenance and completeness of the alleged database remain unverified.
The cyber campaign coincides with a deterioration in the security environment in the Arabian Peninsula, marked by renewed Saudi-Houthi confrontation, attacks against Saudi interests and Turkey and Pakistan’s decision to implement their commitments under the August Mecca Joint Defence Agreement through the deployment of military capabilities to Saudi Arabia.
Uways Qarani’s cyber activity or information campaign fits with the broader regional confrontation involving Saudi Arabia, the Houthis and Iran, as well as the continuing strategic tensions between Iran and the United States.
Background Information
Uways Qarani, written in Arabic as أُوَيْس ٱلْقَرَنِيّ, emerged publicly in August 2026 and presents itself as a hacktivist organisation aligned with Ansar Allah, the Houthi movement in Yemen. The name refers to Uways ibn ʿĀmir al-Qaranī, a seventh-century Muslim figure associated with Ali ibn Abi Talib and the Battle of Siffin. Both Sunni and Shi’a communities venerate Uways al-Qaranī, and the adoption of his name provides the group with a historical and religious reference compatible with its declared “resistance” narrative.
The group has publicly described itself as part of the so-called Cyber Defense Organization of Ansar Allah and has claimed previous activity involving phishing, media compromises and attacks against critical infrastructure. Its communications subsequently expanded towards operational technology, including claimed capabilities involving Modbus, PLCs and industrial-control systems. These claims indicate an apparent interest in OT (Operational Technology) e ICS (Industrial Control Systems) environments, but the publication of tools, screenshots or demonstrations does not independently establish successful compromise of operational systems.
Uways Qarani has increasingly directed its messaging towards Saudi Arabia. In August 2026, the group threatened Saudi critical infrastructure, networks and sensitive facilities. On 5 October 2026, the group claimed the revealing Saudi GIP database, marking a significant escalation in the political value of its messaging. Uways Qarani states that it obtained and published a database containing sensitive information concerning personnel, organisational structures, operational stations and ongoing cases within the Saudi foreign intelligence service.
An examination of the data made available by the group indicates that, in addition to material purporting to describe the organisational structure of the Saudi GIP, the dataset contains names attributed to directors or employees associated with different countries and geographical areas of responsibility and also images of alleged Saudi intelligence officers’ passports. The material also appears to associate individuals with contact information and organisational functions. However, it is not currently possible to independently corroborate the identity, employment status or contact details of these individuals. Consequently, the presence of names and contact information within the material should not, at this stage, be interpreted as confirmation that the individuals are current GIP personnel or that the information originates from a genuine GIP database.
The same evidentiary limitation applies to the alleged database. The existence of a publication or download link demonstrates that Uways Qarani attempted to disseminate material presented as a GIP database; it does not establish that the underlying information was obtained through a compromise of Saudi intelligence infrastructure. The dataset could potentially contain genuine information, fabricated material, recycled information obtained from other sources, or a combination of these elements. The alleged compromise should therefore currently be classified as unverified.
The timing of the claim is nevertheless significant. Saudi Arabia is experiencing an increasingly complex security environment as the confrontation with the Houthis intensifies. Saudi-backed Yemeni forces have launched a major counteroffensive against Houthi-held territory, including areas around the strategically important Bab al-Mandab, while Houthi forces have continued to threaten Saudi interests and infrastructure.
The regional dimension has simultaneously expanded. On 5 October 2026, Saudi Arabia, Turkey and Pakistan agreed to implement their collective-defence commitments under the Mecca Joint Defence Agreement and to facilitate the deployment of military forces and capabilities to Saudi Arabia. The decision follows an increase in attacks against the Kingdom and represents a significant development in the regional security architecture.
The Saudi-Houthi confrontation must also be understood within the wider strategic competition involving Iran and the United States. Tehran’s support for the Houthis has made Yemen an important component of the regional security environment, although the Houthis retain their own political and military interests and should not automatically be treated as an Iranian-controlled organisation. The escalation therefore creates a multi-layered security environment in which kinetic operations, proxy activity, cyber operations and information warfare can reinforce one another.

Analysis
The available evidence supports treating Uways Qarani primarily as an emerging hacktivist persona/group with an anti-Saudi narrative, rather than as a confirmed Houthi or Iranian cyber organisation. Its public communications deliberately associate the group with Ansar Allah and present cyber activity against Saudi targets as part of a wider resistance campaign. However, there is currently insufficient independent evidence to establish operational control, tasking or command-and-control by the Houthis.
The same caution applies to the alleged relationship with Handala. The existence of a common political narrative does not demonstrate an operational relationship. Consequently, the available evidence does not confirm that Uways Qarani as an Iranian proxy or as a Handala subordinate. The possibility remains relevant, particularly given the broader Iranian cyber ecosystem, but it requires technical, organisational or intelligence corroboration.
The more significant intelligence assessment concerns the strategic function of the campaign. Uways Qarani appears to be attempting to establish itself as a credible cyber actor supporting the Houthi cause by targeting Saudi interests and publicising alleged access to sensitive Saudi information. The GIP claim is particularly valuable from an information-operations perspective because intelligence services occupy a highly symbolic position within national security structures. A claim of successful penetration therefore has considerably greater psychological and political value than a conventional claim against a commercial organisation.
The alleged presence of GIP personnel names, geographical assignments and contact details increases the potential significance of the disclosure if the material is subsequently authenticated. If genuine, such information could have counterintelligence implications, facilitate social engineering or targeting, expose relationships between personnel and geographical areas of responsibility, and potentially create risks for individuals and their families. At present, however, the inability to independently establish the identity and employment of the named individuals means that these potential consequences should be treated as conditional rather than confirmed effects.
The operation may therefore generate strategic effects even if the complete database claim ultimately proves false. The publication forces Saudi security institutions to consider whether sensitive personnel information has been exposed, while simultaneously allowing Uways Qarani to portray itself as capable of penetrating one of the Kingdom’s most sensitive institutions. This creates a distinction between technical success and psychological effect: an unverified breach claim can still contribute to an adversary’s information campaign.
Three principal hypotheses should remain under consideration:
- Uways Qarani is an autonomous, genuinely pro-Houthi hacktivist group attempting to acquire legitimacy and visibility through operations against Saudi Arabia.
- The group constitutes a proxy or cut-out supported by another cyber actor or state, with the Houthi identity providing political cover and attributional ambiguity.
- Uways Qarani is an opportunistic persona created by actors without a substantive relationship with either the Houthis or Iran, exploiting the current conflict to enhance its visibility and perceived capabilities.
The possibility of a deliberately constructed cyber persona deserves particular attention. Cyber operations conducted through hacktivist identities can create strategic ambiguity by separating the apparent operator from the organisation or state that ultimately benefits from the activity. The Handala case demonstrates the relevance of this analytical model: US authorities have previously attributed Handala-linked cyber and psychological operations to Iran’s Ministry of Intelligence and Security, including activity involving fabricated hacktivist identities and the use of stolen information for psychological effects. This does not establish a connection between Handala and Uways Qarani, but it demonstrates why declared affiliations should not automatically be treated as evidence of actual command relationships.
The timing of Uways Qarani’s campaign is therefore strategically relevant. The group is attempting to establish its identity during a period in which Saudi Arabia is facing simultaneous military, political and cyber-security pressures. The Houthi-Saudi confrontation is intensifying, the regional military alignment around Saudi Arabia is expanding through Turkey and Pakistan, and the broader Iran-US confrontation continues to shape the strategic environment. The cyber domain provides an additional means of exerting pressure without necessarily triggering the same immediate attribution and escalation dynamics associated with conventional military attacks.
We might contextualise the activity as part of a wider cyber-geopolitical risk environment rather than as an isolated hacktivist incident. Even if Uways Qarani has limited technical capabilities, its targeting choices and narrative can contribute to the perception that Saudi government, intelligence and critical-infrastructure systems are vulnerable. Conversely, if subsequent technical analysis establishes that the GIP material is genuine, the incident will represent a substantially more serious counterintelligence and national-security development.
Attribution remains the principal intelligence gap. Current evidence is sufficient to establish Uways Qarani’s declared political positioning and anti-Saudi targeting narrative, but not to establish its actual organisational relationships.
Conclusion
The Uways Qarani campaign is part of the broader deterioration of the Middle Eastern security environment rather than as an isolated hacktivist episode. The alleged GIP database disclosure remains unverified, but its timing and political messaging are significant. The campaign coincides with intensified Saudi-Houthi confrontation, increasing pressure against Saudi interests and Ankara and Islamabad’s decision to implement their defence commitments and support Riyadh militarily.
Overall, the regional cyber-geopolitical risk is increasing. The convergence of kinetic confrontation, military realignment, proxy activity, cyber operations and information warfare creates an environment in which cyber incidents and data-leak campaigns can increasingly support broader geopolitical objectives. Continuous monitoring of Uways Qarani, associated cyber personas and the wider Houthi and Iranian cyber ecosystems, alongside developments in the Saudi-Houthi confrontation, is therefore fundamental for policymakers and organisations operating in or connected to the Gulf.
