Collage of various graphics and maps with Emily and Lucien Taylor in front of Google HQ in the center

MENA Regulators Forum: Examining Regional Infrastructure Abuse Trends Through GSE Data

On 21 July, Lucien and Emily took part in a fireside chat at the Middle East and North Africa Regulators Forum, hosted by Google in London.

Two themes emerged from the discussions. First was the role of the ASN league table in flagging high levels of abuse reports from several states in the region, and second was the insights provided by the GSE Compass tool.

The MENA region has almost no footprint for abuse reports in the domain registry and registrar league tables. This is consistent with research findings by the OXIL team into the MENA domain name industry marketplace and linguistic diversity online which found that the region is home to relatively few ICANN accredited registries and registrars.

World map highlighting low level of abuse reports across domain registries and registrars in the Middle East and North Africa Region.

In contrast, the region features in the bottom 10 globally for the ASN League Table:

World map showing high levels of abuse reports in Middle East and North African ASNs

While the Gulf is known to be both targeted by scammers and used as a location for scam centres, the role of North African ASNs is less obvious.

This is where the GSE Compass tool provides further insight, drawing a distinction between intentional, malicious hosting and passive compromise.

One hypothesis to explain the high level of reports in some North African ISPs is that the results reflect a large, vulnerable consumer base rather than directly linking to scam compounds or threat actors. In these regions, the primary driver of abuse reports is frequently botnet activity. Under this hypothesis, compromised residential gateways, IoT devices, and unpatched consumer hardware are often used as proxies or nodes in global attack chains. Because these devices reside within the ISP's network, the reports are attributed to the ASN, even though the ISP is itself a victim of the same infrastructure abuse as the end-users.

Another feature of ISPs in developing markets is that many lack the automated abuse-handling infrastructure to remediate compromised endpoints at scale. Consequently, they remain at the bottom of the table not because they are complicit, but because they face significant challenges in securing a massive, heterogeneous, and often legacy-hardware-heavy network footprint.

The insights from the GSE are another example of a region’s digital footprint being different from the on-the-ground experience of both victims and perpetrators. More research is needed to understand what is the role of the MENA region’s ISPs, and how their exploitation links to the global fraud attack chain.