In the weeks before February 28, 2026, the United Arab Emirates was already one of the most heavily targeted digital environments in the world. Its combination of critical port infrastructure, global financial connectivity, sovereign wealth assets and a highly digitised public sector made it a natural target for both financially motivated criminal groups and state-linked threat actors. Then the regional conflict began and the numbers changed in ways that security teams in Dubai and Abu Dhabi had not planned for.
The UAE Cybersecurity Council confirmed in February 2026 that 128 confirmed cyber threat incidents had targeted UAE entities in the year to date, including ransomware attacks, government system breaches and data leak operations. Shortly after, reporting from Dark Reading confirmed that daily breach attempts had tripled in a matter of weeks, with estimates ranging between 90,000 and 200,000 attempts per day targeting critical infrastructure specifically.
Abu Dhabi’s Emergencies, Crises and Disasters Management Centre issued formal public guidelines warning residents and organisations about the elevated threat environment, explicitly noting that attackers were exploiting fear and confusion to increase the success rate of phishing campaigns. The guidance warned that mental fatigue during periods of regional instability makes people measurably more likely to click malicious links or provide credentials without adequate verification.
The Attack Trajectory: October 2025 to May 2026
The chart below tracks estimated daily breach attempts targeting UAE infrastructure across the eight months from October 2025 through May 2026. The inflection point at the end of February is visible and pronounced. The subsequent months show a partial normalisation but attempts remain significantly above pre-conflict baseline levels.

Chart 1: Daily cyberattack attempts targeting UAE infrastructure, Oct 2025 to May 2026
What the Attacks Look Like in Practice
The UAE Cybersecurity Council’s reporting describes the 2026 attacks as involving the exploitation of artificial intelligence technologies to develop sophisticated offensive tools. This is not rhetorical language. Researchers tracking the campaigns have observed AI-assisted spear-phishing messages that adapt their content based on the recipient’s public social media presence, generating contextually convincing lures at a scale that would previously have required significant human effort to produce.
Critical vulnerability exploitation has run in parallel with the social engineering campaigns. A zero-day vulnerability in Palo Alto Networks PAN-OS firewalls, tracked as CVE-2026-0300, was actively exploited during this period allowing attackers to bypass authentication on next-generation firewalls. Multiple Cisco vulnerabilities affecting enterprise networking products were disclosed simultaneously, including flaws enabling server-side request forgery and remote code execution. For UAE organisations running these products across financial and energy sector networks the patch window was dangerously narrow.
Confirmed Incident Types: UAE 2026 Year to Date
| Incident Category | Confirmed Count YTD | Primary Target Sectors | Trend vs 2025 |
| Ransomware attacks | 41 | Government, finance, healthcare | +32% |
| Government system breaches | 28 | Federal and emirate-level entities | +47% |
| Data leak and exfiltration | 33 | Finance, energy, telecoms | +28% |
| Critical infrastructure probing | 19 | Energy, ports, water utilities | +61% |
| AI-assisted phishing campaigns | 7 | All sectors — broad targeting | New category |
Table 1: UAE confirmed cyber incident categories, year to date 2026 (Source: UAE Cybersecurity Council; sector intelligence reports)
What Organisations Should Do Now
The UAE Cybersecurity Council’s guidance is explicit: patch management for critical CVEs must happen within hours not days in this environment. The PAN-OS zero day and the Cisco vulnerabilities are both being actively exploited and the window between public disclosure and weaponisation has compressed to under 24 hours in several recent cases.
Beyond patching, the guidance from Abu Dhabi’s crisis management centre points to something that technical teams often underestimate: the human attack surface expands during periods of regional instability. Security awareness communications should be refreshed immediately and employees should be reminded specifically that attackers are using the current environment as cover for social engineering campaigns.
The organisations that will emerge from this period in the strongest position are those that treat the elevated threat environment not as a temporary emergency but as the new operating baseline for the region.

Leave a Reply