Kaspersky researchers have highlighted significant advertising data risks during the annual Cyber Security Weekend for the Middle East, Turkiye, and Africa region. While the digital advertising ecosystem processes billions of requests daily to deliver personalized content, experts warn this infrastructure can be exploited. Specifically, advanced threat actors use this data to identify, track, and compromise selected targets.

Understanding Advertising Data Risks

The digital advertising ecosystem relies on collecting vast amounts of user information through multiple intermediaries. Consequently, this data provides valuable intelligence for cybercriminals and advanced persistent threat groups. Kaspersky researchers noted that the same tools used for commercial targeting are now being repurposed for surveillance.

Furthermore, the abuse of real-time bidding systems and data broker networks allows attackers to monitor individual movements. In some cases, threat actors can deliver highly targeted spyware that requires no user interaction. This method bypasses traditional security awareness because users only need to open a legitimate application displaying advertisements.

How Threat Actors Exploit AdTech

AdTech platforms collect user characteristics such as browsing habits, device information, and approximate locations. Although this data serves commercial purposes, it also expands the digital attack surface. Meanwhile, certain adware variants, such as Adware.Script.Redirect, actively redirect users to malicious websites. These websites then distribute malware to compromised devices.

To address these advertising data risks, organizations must look beyond traditional email phishing defenses. Maher Yamout, Lead Security Researcher at Kaspersky, stated that commercial targeting capabilities are being transformed into intelligence gathering. As a result, sophisticated threat actors can understand high-value individual behaviors and deliver exploits through trusted applications.

Regional Impact and Redirect Statistics

The threat is particularly active in the Gulf Cooperation Council region. Specifically, Kaspersky blocked more than 1.6 million malicious redirect attempts in the GCC during the first half of 2026. These attempts aimed to steer users toward harmful content through compromised advertising scripts. Consequently, this statistic highlights the scale of ad-tech-enabled threats in the region.

Recommended Security Measures for Organizations

To mitigate these advertising data risks, Kaspersky recommends a multi-layered cybersecurity approach. Consumers should install trusted security software and keep all applications updated. Meanwhile, businesses need to deploy endpoint detection and response systems to monitor suspicious activities.

In addition, organizations should implement dedicated anti-targeted attack platforms and use threat intelligence services. Regularly reviewing application permissions and deploying ad blockers on corporate devices also helps. These combined actions minimize exposure to compromised advertising infrastructures and protect sensitive corporate networks.