The UAE is now absorbing between 600,000 and 800,000 cyberattack attempts every day, according to the UAE Cyber Security Council. That figure represents a three to four times increase from the 90,000 to 200,000 daily attempts recorded at the start of 2026. The escalation followed the outbreak of conflict between Israel, the United States and Iran earlier this year, and the Council says state-sponsored or advanced persistent threat groups now account for the bulk of tracked activity. Since the beginning of 2026, the Council has confirmed 128 cyber threat incidents against UAE entities, with government administration and financial services the most targeted sectors.
In February 2026, Dr. Mohamed Hamad Al Kuwaiti, Head of the UAE Government Cybersecurity Council, told the Emirates News Agency (WAM) that the country was facing 90,000 to 200,000 breach attempts daily, all of which were being detected and blocked without disrupting services or compromising data. He said 128 confirmed cyber threat incidents had hit UAE entities since the start of the year, spanning ransomware attacks, government breaches and data leaks.
By May 2026, that picture had changed sharply. According to Dark Reading, the breach attempt volume rose to a daily average of 600,000 to 800,000 in the weeks following the start of military operations by Israel and the United States against Iran. The composition of the attacks also shifted, moving away from denial of service campaigns publicised by hacktivists on Telegram toward more serious claims of network intrusion and compromise. The figures were restated publicly around the time the UAE hosted its third annual Government Cybersecurity Summit in Abu Dhabi on 9 June 2026, an event convened by the Cyber Security Council to address what organisers described as the country’s escalating threat environment.
What the source data shows
The February 2026 disclosure gave the clearest breakdown yet of how UAE cyber incidents are categorised. Of the 128 confirmed incidents, website defacement, the unauthorised alteration of a website’s appearance, accounted for the largest share at 38.3 percent. Data leaks followed at 25.8 percent, data breaches at 13.3 percent, initial access incidents at 10.2 percent, ransomware attacks at 7.8 percent, and distributed denial of service (DDoS) attacks, which flood systems with traffic to take them offline, at 4.7 percent.
Chart 1: Confirmed UAE cyber incidents by type, since the start of 2026

Chart 1 shows how the 128 confirmed cyber incidents reported by the UAE Cyber Security Council since the start of 2026 break down by attack type, as stated by Dr. Mohamed Hamad Al Kuwaiti to the Emirates News Agency (WAM) in February 2026.
Look at the table alongside the threat actor data the Council also released. Of 21 advanced persistent threat groups currently tracked, 15, or 71.4 percent, are classified as state-sponsored. Criminal groups motivated by financial gain and hacktivist groups each account for 14.3 percent of tracked actors. The combination matters: a threat landscape dominated by defacement and data leaks, but driven mostly by state-sponsored groups, points toward attacks aimed at signalling, disruption and intelligence gathering rather than purely financial extortion, although the Council also recorded ransomware and government breach incidents within the same period.
On targeting, government administration ranked first among affected sectors at 9.4 percent of incidents, followed by financial services and banking at 9.3 percent and real estate at 5.5 percent. Construction and engineering accounted for 4.7 percent, while professional services and transportation and logistics each represented 3.9 percent.

A separate statement from the Council in late February 2026 said that the national cyber system had thwarted organised cyberattacks described as being of a terrorist nature, targeting digital infrastructure and vital sectors. The attempts involved network infiltration, attempted ransomware deployment and coordinated phishing campaigns aimed at national platforms. The Council said its cyber defence system operates around the clock in coordination with national and international partners, though it did not name the specific entities targeted.
Why it matters
The jump from roughly 200,000 daily breach attempts at most in February to 600,000 to 800,000 by May is the most significant single data point in this update. A three to four times increase in daily breach attempts within a few months indicates that the UAE’s threat environment is now directly tied to regional conflict dynamics rather than following a steady baseline trend. Al Kuwaiti linked the surge to conflict-driven discourse, diplomatic friction and AI-enabled disinformation activity, which he said had increased rumour propagation and hacktivist mobilisation.
For organisations operating in or alongside the UAE, the practical implication is that threat models built around earlier 2026 figures are likely outdated. Government administration and financial services remain the two most targeted sectors in the UAE, according to Cybersecurity Council data covering incidents since the start of 2026. Entities in real estate, construction, transportation and professional services, while lower on the list, still represent a meaningful share of confirmed incidents and should not assume they fall outside the current threat picture.
Risks, limitations and caveats
The source material gives a clear directional picture but leaves some gaps. The Council has not published a sector by sector breakdown of the more recent 600,000 to 800,000 daily figure, so it is not possible to say from the available reporting whether the same sectors that topped the February list remain the most targeted under the higher volume. Similarly, the February attack type breakdown covers the 128 confirmed incidents up to that point and predates the conflict driven surge, so it may not reflect the current mix of defacement, data leaks, ransomware and DDoS activity.
The Council’s statements describe breach attempts that were detected and blocked, and separately describe 128 confirmed incidents. These are not the same measure, and the source material does not state what proportion of daily breach attempts, at either the earlier or later volume, escalate into confirmed incidents. Daily breach attempt volumes describe attempted intrusions that were detected and stopped, not confirmed compromises. Readers should treat the two figures as describing different stages of the threat funnel rather than directly comparable totals.
Recommended actions
For security teams, the immediate priority is to revisit detection and response priorities in light of the shift the Council has described, from opportunistic disruption toward more serious intrusion attempts. This points toward strengthening monitoring around initial access vectors, since initial access already accounted for 10.2 percent of confirmed incidents even before the May 2026 surge, and reviewing exposure in government facing systems and financial services integrations given their position at the top of the targeted sector list.
Given that 71.4 percent of tracked threat actor groups are classified as state-sponsored, organisations should prioritise threat intelligence sources that track APT activity relevant to the Gulf region and ensure incident response plans account for the possibility of intrusions aimed at disruption or data exposure rather than only ransom demands. Mapping these priorities to existing frameworks such as the NIST Cybersecurity Framework, which provides a structured approach to identifying, protecting against, detecting, responding to and recovering from cyber incidents, or relevant CIS Controls, can help translate these national level figures into specific control improvements.
For executives and boards, the key takeaway is that the threat environment facing UAE based operations has changed materially within 2026 itself, not gradually over several years. The UAE Cyber Security Council has confirmed that breach attempt volumes rose three to four times within months, tied to a regional conflict that began earlier in the year. Boards should expect security leadership to revisit risk assessments and budget allocations against this updated baseline rather than figures from earlier in the year.
Conclusion
The data the UAE Cyber Security Council has released across February and May 2026 tells a consistent story of an escalating, largely state-sponsored threat environment, where attack volumes have multiplied several times over within a single year and where government and financial sector entities remain primary targets. The figures are incomplete in places, particularly around how the post-surge attack mix and sector targeting compare with the earlier 2026 breakdown, but the direction of travel is unambiguous. Organisations operating in the UAE should treat the current 600,000 to 800,000 daily breach attempt figure, not the earlier 90,000 to 200,000 range, as the relevant baseline for planning.
FAQ
How many cyberattacks does the UAE face every day in 2026?
According to the UAE Cyber Security Council, the country was facing 90,000 to 200,000 breach attempts daily as of February 2026. By May 2026, that figure had risen to between 600,000 and 800,000 daily attempts, a three to four times increase.
Why have UAE cyberattacks increased in 2026?
The UAE Cyber Security Council attributed the increase to the conflict between Israel, the United States and Iran that began earlier in 2026, along with related diplomatic friction, conflict-driven discourse and AI-enabled disinformation that increased hacktivist mobilisation.
Which sectors are most targeted by cyberattacks in the UAE?
Based on confirmed incidents since the start of 2026, government administration was the most targeted sector at 9.4 percent, followed by financial services and banking at 9.3 percent and real estate at 5.5 percent.
Are most cyberattacks on the UAE state-sponsored?
Of the 21 advanced persistent threat groups tracked by UAE authorities, 71.4 percent, or 15 groups, are classified as state-sponsored. Criminal and hacktivist groups each account for 14.3 percent of tracked actors.
What types of cyber incidents has the UAE confirmed in 2026?
Of 128 confirmed incidents reported since the start of 2026, website defacement made up the largest share at 38.3 percent, followed by data leaks at 25.8 percent, data breaches at 13.3 percent, initial access incidents at 10.2 percent, ransomware at 7.8 percent and DDoS attacks at 4.7 percent.

Leave a Reply